@shellsharks I'm trying to get the #IndieSec hashtag going here, are you in? :D

Here's my new article on how I escalated a CSS injection to remote code execution on a Google app. Enjoy!

https://bm.gy/gwdrce3

#Cybersecurity #InfoSec #BugBounty #IndieSec #Vulnerability

Client-side RCE via CSS Injection in Google Web Designer for Windows

Fixed in version 16.4.0.0711 — $3,500 bug bounty

Bálint Magyar
Bug Bounty Year 1: $0–16k, Low to CVE @ BSides Budapest 2025

My conference talk on May 21, 2025

Bálint Magyar
@shellsharks Hey, do you happen to know of any #IndieSec webrings? 👀

Just posted my new article on another client-side remote code execution bug I found in Google Web Designer back in February, tracked as CVE-2025-4613, fixed in an April release. Enjoy the write-up!

https://bm.gy/gwdrce2

#Cybersecurity #Security #InfoSec #IndieSec #Vulnerability #CVE

Client-side RCE via improper URL parsing in Google Web Designer for Windows: CVE-2025-4613

Fixed in version 16.3.0.0407 — $8,500 bug bounty. Another code execution bug following my November 2024 find.

Bálint Magyar

New article with many personal firsts:
- First bug on Google's Vulnerability Reward Program
- First remote code execution bug
- First 5-figure bug bounty
- First CVE

What a ride.

https://bm.gy/gwdrce

#Cybersecurity #InfoSec #Security #Vulnerability #BugBounty #IndieSec #IndieWeb #SmallWeb

Client-side RCE via symlink following in Google Web Designer for macOS/Linux: CVE-2025-1079

Fixed in version 16.2.0.0128 — $11,250 bug bounty

Bálint Magyar

Ok, I scrambled and am getting the v1 of this Fedi-native starter pack out. Here is my “#IndieSec" #starterpack.

https://fedidevs.com/s/MjQ/

It features #infosec / #cybersecurity folks that are active here. No corpo accounts, no bots, no influencers.

I KNOW I've missed people, so ping me if you want to be added. Or just post something as you usually would and Ill probably grab ya. If you want to be removed, ping me. The list maxes at 150 so eventually I'll have to start a sequel pack.

FediDevs | FAQ

Frequently Asked Questions

Fediroll

Cybersecurity Research and More

shellsharks

If you are in #infosec / #cybersecurity and looking for an easier way to follow interesting infosec accounts that are relatively high signal-to-noise without having to scour the Fediverse, consider checking out the #mammoth Mastodon client and subscribing to the new #indiesec Smart List! Smart Lists are a unique feature pioneered by Mammoth which offers curated lists of accounts in a number of different subject areas.

To start, the IndieSec Smart List (curated by yours truly) features 50 independent security researchers /professionals across many infosec sub-disciplines. I will continue to maintain this list and add new accounts in the coming weeks (I have a whole backlog of accounts I'd like to see added). Over time, this list will seek to feature many accounts that are lower-volume, but high-quality in terms of content. Surfacing harder-to-find accounts (by doing hours of scrolling and curation) is one more way we as a community are improving #discoverability across the network.

Thanks to the @mammoth team and @bart for working with me on this new list. If you have any questions about the list feel free to drop me a message!

Edit: I should add - you can see everyone who is featured on this list here https://github.com/shellsharks/assorted/blob/master/resources/mammoth-indiesec.csv. When new accounts are added, they too will be represented there.

assorted/resources/mammoth-indiesec.csv at master · shellsharks/assorted

Contribute to shellsharks/assorted development by creating an account on GitHub.

GitHub