Category: Mix

Hacking misconfigured Firebase targets: A complete guide
12
Aug
2025

Hacking misconfigured Firebase targets: A complete guide

Google Firebase is a popular back-end application development platform that provides several built-in components and services, allowing developers to seamlessly…

12
Aug
2025

I’m Worried It Might Get Really Bad

I’m starting to worry things might get very bad, very soon. Not like in a year or two, but maybe…

08
Aug
2025

Why Dwarkesh Is Wrong About AGI

Dwarkesh Patel is one of my favorite thinkers right now. I just love the intensity of his curiosity. I love…

08
Aug
2025

The Worst AI Metric

The “how many r’s in strawberry” test for AI intelligence is dumb. As a writer to write a quality sentence…

[tl;dr sec] #291 - Build a GuardDuty Triage Agent, Scaling Netflix's Threat Detection Pipelines, Claude for Security Review
07
Aug
2025

[tl;dr sec] #291 – Build a GuardDuty Triage Agent, Scaling Netflix’s Threat Detection Pipelines, Claude for Security Review

Hacker Summer Camp Once more, hackers have descended onto Vegas for our annual Hacker Summer Camp pilgrimage. I hope you…

The Desync Delusion: Are You Really Protected Against HTTP Request Smuggling?
07
Aug
2025

The Desync Delusion: Are You Really Protected Against HTTP Request Smuggling?

Andrzej Matykiewicz | 06 August 2025 at 22:22 UTC The Hidden Threat That’s Slipping Past Your Security HTTP request smuggling…

HTTP/1.1 Must Die: What This Means for Contract Pentesters and MSSPs
07
Aug
2025

HTTP/1.1 Must Die: What This Means for Contract Pentesters and MSSPs

Andrzej Matykiewicz | 06 August 2025 at 22:23 UTC At Black Hat USA and DEFCON 2025, PortSwigger’s Director of Research,…

HTTP/1.1 Must Die: What This Means for Bug Bounty Hunters
07
Aug
2025

HTTP/1.1 Must Die: What This Means for Bug Bounty Hunters

Andrzej Matykiewicz | 06 August 2025 at 22:23 UTC At Black Hat USA and DEFCON 2025, PortSwigger’s Director of Research,…

HTTP/1.1 Must Die: What This Means for In-House Pentesters
07
Aug
2025

HTTP/1.1 Must Die: What This Means for In-House Pentesters

Andrzej Matykiewicz | 06 August 2025 at 22:23 UTC At Black Hat USA and DEFCON 2025, PortSwigger’s Director of Research,…

HTTP/1.1 Must Die: What This Means for AppSec Leadership
07
Aug
2025

HTTP/1.1 Must Die: What This Means for AppSec Leadership

Andrzej Matykiewicz | 06 August 2025 at 22:23 UTC At Black Hat USA and DEFCON 2025, PortSwigger’s Director of Research,…

06
Aug
2025

Why Marcus Is Wrong About AI

My friend Marcus Hutchins put out a long, well-written, and entertaining piece about all the reasons he thinks AI is…

HTTP Request Smuggling Explained: with seasoned bug bounty hunter NahamSec and world-class researcher James Kettle
05
Aug
2025

HTTP Request Smuggling Explained: with seasoned bug bounty hunter NahamSec and world-class researcher James Kettle

Amelia Coen | 05 August 2025 at 11:08 UTC Ever wondered how attackers can compromise modern websites by exploiting invisible…