Gaetan

Security research @ GitGuardian | Former pentester 🥾
I have an empty blog that I am decided to fill with personal research since 1874.

Gaetan boosted:
2025-12-22

all these stupid VPN ads act like TLS has never existed

2025-11-27

@christopherkunz @danielp choose your poison:
* Have your home dir wiped
* Have your home dir pushed to the public GitHub and a public remote control chanel deployed to your host.
I personally think it's an easy choice 😅.

Gaetan boosted:
Mike Fiedler, Code Gardenermiketheman@hachyderm.io
2025-11-27

There's a nasty #OpenSource #SupplyChain worm going around named Shai-Hulud. It's also capable of exposing some projects' long-lived PyPI API Tokens. Read more on what's happening, and what you can do to protect your projects.

TL,DR: Adopt Trusted Publishing 🔐🚀📦

blog.pypi.org/posts/2025-11-26

2025-11-27

@verbrecher @claushoumann you forgot to add: registers the host as a GitHub action runner to remote control it through a malicious workflow containing a voluntary injection vulnerability.
Yeah, that's thing really is friendly.

Gaetan boosted:

@glasspusher

The greatest research skill you can have is being a nosy bitch who wants to find out

cr: @NC_Renic

The greatest research skill you can have is being a nosy bitch who wants to find out
Gaetan boosted:
2025-11-14

The narrative about #FortiWeb (CVE-2025-64446) exploitation is going to end up being about attacker behavior and compromise, which is fair enough, except that this looks to have been entirely preventable.

How are we still letting suppliers get away with silent patches in frequently exploited products in 2025? Customers need to be voting for better supplier behavior with their wallets, or with their legal teams.

vulncheck.com/blog/fortinet-fo

2025-10-24

@zhuowei AMI Secure Boot platform key has found by binarly in the PKFail research: binarly.io/blog/pkfail-untrust

Gaetan boosted:
Exodus Privacyexodus@framapiaf.org
2025-09-29

Certain·es ont remarqué que l’association est en sommeil depuis environ un an. En effet, nous sommes très peu au sein de l’association et nos vies ces derniers temps ont été mouvementées, ne nous permettant pas de nous investir davantage.

C’est pourquoi nous faisons cet article afin de lancer un appel : si le sujet de la vie privée sur mobile (et plus particulièrement Android) vous intéresse et que vous voulez participer à faire vivre Exodus Privacy, rejoignez-nous !

exodus-privacy.eu.org/fr/post/

Gaetan boosted:
Captain, it's Wednesdayyikes@bbs.kawa-kun.com
2025-09-17
What a week, huh?
Yikes!
Gaetan boosted:
2025-09-01

> Thomas Chauchefoin has once again generously sent us a number of security bug reports, most of which had patches attached. Thanks Thomas!

This time I got 2 more RCEs on git.sr.ht and hg.sr.ht and a leak of private lists on lists.sr.ht o/

This is getting harder, can't wait for the next review to poke at a few new things! And kudos to SourceHut for writing super readable code and landing fixes in a matter of minutes.
mastodon.social/@lobsters/1151

Gaetan boosted:
mcdwaynemcdwayne
2025-08-22

Did you know that an exposed App_Key can lead to someone executing their own code in Laravel apps?

Scary stuff, but it does not need to be. Hear from GitGuardian's cybersecurity researcher on how to protect yourself!

youtu.be/Vw1i66Lftk0

2025-08-19

@swapgs the 90s called, etc.

2025-08-17

@jerry @jawnsy Alright technical limitation it is then.
Those lens are freaking expensive which is why I only own a 70-200 f/4 non stabilized (canon here) and it already cost me quite some money back then. Doesn't really allow for moon shots tho.

Anyway, your results are still pretty clean with the 600mm. I guess the doubler is not really worth it in most situations.

2025-08-16

@jerry @jawnsy I'm quite puzzled. I've never tried shooting the moon with a long tele, and actually don't own any such lens, but I find the parameters surprising.
Why did you choose to shoot at f/9 (f/14) rather than the sharpest high aperture available? Would have gained some precious 10th of shutter speed to hopefully gain some additional sharpness. Also, I would expect most lenses to start dropping in image quality at f/14 due to the diffraction.
Anything I need to learn about moon shots or are those just due to technical limitations?

Gaetan boosted:
Pass the SALT Conferencepassthesaltcon@infosec.exchange
2025-07-27

PHOTOS
While Salty has decided to take some good times on the coast 😎, the team has found time to put online photos of #pts25 taken by our own @julioloayzam ❤️

Feel the soul of the event 👉 flickr.com/photos/yobibe/album

And all files available on our archives site: archives.pass-the-salt.org/Pas

Gaetan boosted:
STPoSTPo
2025-07-23

Si vous ne deviez lire qu'une seule nécro d'Ozzy Osbourne, ce serait celle de Lelo Jimmy Batista. Évidemment.
archive.is/PWRUu

Gaetan boosted:
Ivan Ožić Bebekobivan@infosec.exchange
2025-07-11
2025-07-11

@obivan see blog.gitguardian.com/exploitin for Gitguardian's side of the same story.

Gaetan boosted:
2025-06-19
👷 After 15 years of entrepreneurship and a few months of sabbatical I'm looking for a regular old job.

My ideal role would be primarily technical, aimed to dissect software to uncover vulnerabilities. Beyond bug mining I'd love to learn to mine better and make new kinds of pickaxes.

My public works and contact info are on my homepage:

https://scrapco.de

Get in touch if you want to know more!

Boosts are appreciated! #FediHire
Gaetan boosted:
JB Lièvremontmithfindel
2025-06-19

Or donc,

Idéalement, où mes 20+ années d'expérience dans "la tech" au sens large pourraient bénéficier à l', l', la .

Il y a peu de domaines de la tech qui me font peur. J'ai fait du front, du back, de l'embarqué, du desktop, de l'intégration.

Je connais très bien l'écosystème , un peu moins et - et j'apprends vite.

Je me reconnais à 100% dans cette description des "généralistes experts" : martinfowler.com/articles/expe

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst