#IndieSec

Bálint Magyarbalint
2025-05-23

@shellsharks Hey, do you happen to know of any webrings? 👀

Bálint Magyarbalint
2025-05-22

Just posted my new article on another client-side remote code execution bug I found in Google Web Designer back in February, tracked as CVE-2025-4613, fixed in an April release. Enjoy the write-up!

bm.gy/gwdrce2

Bálint Magyarbalint
2025-04-02

New article with many personal firsts:
- First bug on Google's Vulnerability Reward Program
- First remote code execution bug
- First 5-figure bug bounty
- First CVE

What a ride.

bm.gy/gwdrce

2024-12-04

Ok, I scrambled and am getting the v1 of this Fedi-native starter pack out. Here is my “#IndieSec" #starterpack.

fedidevs.com/s/MjQ/

It features #infosec / #cybersecurity folks that are active here. No corpo accounts, no bots, no influencers.

I KNOW I've missed people, so ping me if you want to be added. Or just post something as you usually would and Ill probably grab ya. If you want to be removed, ping me. The list maxes at 150 so eventually I'll have to start a sequel pack.

2024-03-21

If you are in #infosec / #cybersecurity and looking for an easier way to follow interesting infosec accounts that are relatively high signal-to-noise without having to scour the Fediverse, consider checking out the #mammoth Mastodon client and subscribing to the new #indiesec Smart List! Smart Lists are a unique feature pioneered by Mammoth which offers curated lists of accounts in a number of different subject areas.

To start, the IndieSec Smart List (curated by yours truly) features 50 independent security researchers /professionals across many infosec sub-disciplines. I will continue to maintain this list and add new accounts in the coming weeks (I have a whole backlog of accounts I'd like to see added). Over time, this list will seek to feature many accounts that are lower-volume, but high-quality in terms of content. Surfacing harder-to-find accounts (by doing hours of scrolling and curation) is one more way we as a community are improving #discoverability across the network.

Thanks to the @mammoth team and @bart for working with me on this new list. If you have any questions about the list feel free to drop me a message!

Edit: I should add - you can see everyone who is featured on this list here github.com/shellsharks/assorte. When new accounts are added, they too will be represented there.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst