Category: Mix

[tl;dr sec] #291 - Build a GuardDuty Triage Agent, Scaling Netflix's Threat Detection Pipelines, Claude for Security Review
07
Aug
2025

[tl;dr sec] #291 – Build a GuardDuty Triage Agent, Scaling Netflix’s Threat Detection Pipelines, Claude for Security Review

Hacker Summer Camp Once more, hackers have descended onto Vegas for our annual Hacker Summer Camp pilgrimage. I hope you…

The Desync Delusion: Are You Really Protected Against HTTP Request Smuggling?
07
Aug
2025

The Desync Delusion: Are You Really Protected Against HTTP Request Smuggling?

Andrzej Matykiewicz | 06 August 2025 at 22:22 UTC The Hidden Threat That’s Slipping Past Your Security HTTP request smuggling…

HTTP/1.1 Must Die: What This Means for Contract Pentesters and MSSPs
07
Aug
2025

HTTP/1.1 Must Die: What This Means for Contract Pentesters and MSSPs

Andrzej Matykiewicz | 06 August 2025 at 22:23 UTC At Black Hat USA and DEFCON 2025, PortSwigger’s Director of Research,…

HTTP/1.1 Must Die: What This Means for Bug Bounty Hunters
07
Aug
2025

HTTP/1.1 Must Die: What This Means for Bug Bounty Hunters

Andrzej Matykiewicz | 06 August 2025 at 22:23 UTC At Black Hat USA and DEFCON 2025, PortSwigger’s Director of Research,…

HTTP/1.1 Must Die: What This Means for In-House Pentesters
07
Aug
2025

HTTP/1.1 Must Die: What This Means for In-House Pentesters

Andrzej Matykiewicz | 06 August 2025 at 22:23 UTC At Black Hat USA and DEFCON 2025, PortSwigger’s Director of Research,…

HTTP/1.1 Must Die: What This Means for AppSec Leadership
07
Aug
2025

HTTP/1.1 Must Die: What This Means for AppSec Leadership

Andrzej Matykiewicz | 06 August 2025 at 22:23 UTC At Black Hat USA and DEFCON 2025, PortSwigger’s Director of Research,…

06
Aug
2025

Why Marcus Is Wrong About AI

My friend Marcus Hutchins put out a long, well-written, and entertaining piece about all the reasons he thinks AI is…

HTTP Request Smuggling Explained: with seasoned bug bounty hunter NahamSec and world-class researcher James Kettle
05
Aug
2025

HTTP Request Smuggling Explained: with seasoned bug bounty hunter NahamSec and world-class researcher James Kettle

Amelia Coen | 05 August 2025 at 11:08 UTC Ever wondered how attackers can compromise modern websites by exploiting invisible…

05
Aug
2025

Why Platforms Like Substack Won’t Make Sense for Much Longer

I think the future of Substack is self-hosting. Or—more directly—I don’t think they have much of a future. I’m sure…

Why We Built a Museum Instead of a Booth — API Security
04
Aug
2025

Why We Built a Museum Instead of a Booth — API Security

Think you know what to expect from a conference booth? Think again.  Forget the cliches: the swag destined for the…

01
Aug
2025

Launching Daemon: My Personal API

Super hyped to be launching the first version of Daemon today! My daemon is my personal API that anyone—or any…

01
Aug
2025

Increased Worker Pressure from AI

My latest depressing thought about AI is that with all the pressure to adopt AI and replace employees with automation,…