Simply stated: Give us any kind of app and we'll hack it better than the rest.
Our clients include awesome tech companies in Silicon Valley, NYC, and beyond.includesecurity.com Brooklyn and the worldJoined May 2012
Do you use or exploit WebSockets? Check out our new blog post to see how modern browsers may (or may not) be protecting you from Cross-Site WebSocket Hijacking!
blog.includesecurity.com/2025/04/cross-…
Today our team at IncludeSec is releasing a site to help with key collision concerns. We've known for a while that private keys should not be shared, use this site to ensure they are not! ismyprivatekeypublic.com
New research🤩 on old tech👴! Our team's latest blog post demonstrates many ways memory vulnerabilities can occur in your legacy Delphi code despite being described as a "memory safe" language by the NSA.
blog.includesecurity.com/2025/03/memory…
It's winter, so hacking space heater IoT devices to completely control their firmware seems like the thing to do! In our latest blog post, you'll see some of the things we do for our IoT/HW clients!!
blog.includesecurity.com/2025/02/replac…
Hey folks, for those who like the HTB community we've done a collab contribution of a challenge box (free, no subscription needed), give it a spin if you like to hack the hackers! 🪓 👩💻
hackthebox.com/machines/backf…
Hint: It's a tough box, check our github and our blog for info.
We're happy to sponsor great learning resources like @OpenSecTraining, the world is awash with a lot of bad training/certs, here's some courses that are solid and open/free!😀
As the year comes to a close, we want to once again thank all of the individual and corporate donors who generously contributed to #OST2's nonprofit mission this year! You help ensure that OST2 will be around for years to come!
ost2.fyi/Partnership.ht…
Platinum Partners:
@hackaday Thanks for including some of our content @hackaday! Would you mind mentioning the Author/Company in your article? Keep that source credit going😀, thnx! We see you did it on last week's summary.
New blog! Join us as we explore seemingly safe but deceptively tricky ground in Elixir, Python, and the Golang standard library. Well-documented behavior is not always what it appears!
blog.includesecurity.com/2024/11/spelun…
Who hacks the hackers? We do!
Our new research on vulns in multiple common C2 frameworks used by netpen and red teams. If you use any of these take a look and patch up.
blog.includesecurity.com
.@OpenTechFund’s Security Lab partner @IncludeSecurity’s security audit of VPN Generator (software that lets anyone provide a VPN to a small group) revealed that the tool only had 4 “low-risk” issues, 3 of which have already been fixed.
Learn more
ow.ly/XPZI50S8P7S
@kevinriggle this particular punk bar has been the host of many summerc0n after parties and we've spent many thousands there on "networking", the staff loves summercon every year!
.@OpenTechFund’s Security Lab partner @IncludeSecurity’s security audit of VPN Generator (software that lets anyone provide a VPN to a small group) revealed that the tool only had 4 “low-risk” issues, 3 of which have already been fixed.
Learn more
ow.ly/XPZI50S8P7S
Fresh blog post for ya;
We introduce coverage-guided fuzzing as a concept to hunt down bugs faster via modification of the Fuzzilli fuzzer from Google Project Zero.
blog.includesecurity.com/2024/04/covera…
We released our new semgrep rules today. Given the recent news about executive orders from the Whitehouse, we thought it would be important to flag all of the code that doesn't meet federal standards.
Memory Safety is serious stuff today:
github.com/IncludeSecurit…
We're happy to support great open/free security training to get more folks into our industry. If you want to learn low-level RE/hacks/OS check out OST2! ost2.fyi/Home.html
We're still seeing a lot of Ruby code out there in the tech world. If we see it we hack it! Latest blog post on advanced Ruby deserialization gadget chains for exploitation of application is up
blog.includesecurity.com/2024/03/discov…
It’s here folks, here’s an actually deeper dive into the topic of LLM prompt injection; Much more complete than all the fluff you see out there on the topic today. If you like under-the-hood AI context, this one is for you.
blog.includesecurity.com/2024/02/improv…
28K Followers 628 FollowingWeb hacker and Burp Suite Pro trainer
Refer to https://t.co/D5tRH7U2hg for trainings
Follow @MasteringBurp for free tips and tricks
287 Followers 617 FollowingUnofficial Listing of Hacker Summer Camp Parties (Black Hat, BSidesLV & DEFCON). Not affiliated with ANY of them. Built by @sheffus
95 Followers 390 FollowingI am interested in crypto scams, software engineering, history, stock and bond markets and economics in general. Please don’t tell me to “follow the science”