🦜 HN Security
@hnsecurity.it@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
Offensive Security Specialists
Your feed and you don't want it here? Just
e-mail the birb.
My Semgrep C/C++ ruleset is ready for prime time again
https://hnsecurity.it/blog/my-semgrep-c-cpp-ruleset-is-ready-for-prime-time-again/
Published: July 15, 2026 08:29
“Retention of critical thinking and problem solving skills in an AI saturated world will probably become a superpower for those […]
The post My Semgrep C/C++ ruleset is ready for prime time again appeared first on HN Security.
AI Reporter – Let’s automate reporting in Burp Suite!
https://hnsecurity.it/blog/ai-reporter-lets-automate-reporting-in-burp-suite/
Published: May 27, 2026 09:38
To wrap up PortSwigger Extensibility Month in style, today I’ll walk you through an extension I recently published: Burp Suite […]
The post AI Reporter – Let’s automate reporting in Burp Suite! appeared first on HN Security.
Restoring Testability: Slides, Code & Video
https://hnsecurity.it/blog/restoring-testability-slides-code-video/
Published: May 22, 2026 13:30
Hi! Last Thursday, as part of the Burp Extensibility Month on the PortSwigger Discord server, I gave a talk on […]
The post Restoring Testability: Slides, Code & Video appeared first on HN Security.
Extending Burp Suite for fun and profit – The Montoya way – Part 10
https://hnsecurity.it/blog/extending-burp-suite-for-fun-and-profit-the-montoya-way-part-10/
Published: May 5, 2026 12:12
Setting up the environment + Hello World Inspecting and tampering HTTP requests and responses Inspecting and tampering WebSocket messages Creating […]
The post Extending Burp Suite for fun and profit – The Montoya way – Part 10 appeared first on HN…
Extending Burp Suite for fun and profit – The Montoya way – Part 9
https://hnsecurity.it/blog/extending-burp-suite-for-fun-and-profit-the-montoya-way-part-9/
Published: December 10, 2025 09:02
Setting up the environment + Hello World Inspecting and tampering HTTP requests and responses Inspecting and tampering WebSocket messages Creating […]
The post Extending Burp Suite for fun and profit – The Montoya way – Part 9 appeared first on HN…
Groovy Template Engine Exploitation – Notes from a real case scenario, part 2
https://hnsecurity.it/blog/groovy-template-engine-exploitation-part-2/
Published: November 11, 2025 08:23
In the first days of this 2025, I came across a new Groovy-capable templating engine in a client’s web application. […]
The post Groovy Template Engine Exploitation – Notes from a real case scenario, part 2 appeared first on HN Security.
Brida 0.6 released!
https://hnsecurity.it/blog/brida-0-6-released/
Published: October 28, 2025 08:55
Hi! Recently, Ole André Vadla Ravnås (@oleavr) & his team made some breaking changes to their great Frida dynamic instrumentation […]
The post Brida 0.6 released! appeared first on HN Security.
Streamlining vulnerability research with the idalib Rust bindings for IDA 9.2
https://hnsecurity.it/blog/streamlining-vulnerability-research-with-the-idalib-rust-bindings-for-ida-9-2/
Published: October 14, 2025 07:42
“The attack surface is the vulnerability. Finding a bug there is just a detail.” — Mark Dowd A previous version of […]
The post Streamlining vulnerability research with the idalib Rust bindings for IDA 9.2 appeared first on HN Security.
Attacking GenAI applications and LLMs – Sometimes all it takes is to ask nicely!
https://hnsecurity.it/blog/attacking-genai-applications-and-llms-sometimes-all-it-takes-is-to-ask-nicely/
Published: July 29, 2025 09:29
Generative AI and LLM technologies have shown great potential in recent years, and for this reason, an increasing number of applications […]
The post Attacking GenAI applications and LLMs – Sometimes all it takes is to ask nicely! appeared first on HN…