Après-climb: the Security + Privacy Weekend Magazine for May 30-31, 2026.
Your weekend magazine for #InformationSecurity & #DataPrivacy! https://sherpaintelligence.substack.com/p/apres-climb-the-security-privacy-8c3
Bypassing SSL Pinning on Play Store AVDs without Frida

📲 🔓 Bypassing SSL Pinning on Play Store Android Device Emulators without Frida

Mateo Fumis (hackermater)
Bypassing SSL Pinning on Play Store AVDs without Frida

📲 🔓 Bypassing SSL Pinning on Play Store Android Device Emulators without Frida

Mateo Fumis (hackermater)
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)

Rapid7 researchers found that Gogs allows authenticated users to achieve RCE on the server by creating a pull request with a specially crafted branch name. More in our latest analysis blog.

Rapid7
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)

Rapid7 researchers found that Gogs allows authenticated users to achieve RCE on the server by creating a pull request with a specially crafted branch name. More in our latest analysis blog.

Rapid7

Red Team Tactics: Utilizing Syscalls in C# - Prerequisite Knowledge:

https://jhalon.github.io/utilizing-syscalls-in-csharp-1/

Red Team Tactics: Utilizing Syscalls in C# - Writing The Code:

https://jhalon.github.io/utilizing-syscalls-in-csharp-2/

#cybersecurity #programming #csharp #informationsecurity #redteam

Red Team Tactics: Utilizing Syscalls in C# - Prerequisite Knowledge

Over the past year, the security community - specifically Red Team Operators and Blue Team Defenders - have seen a massive rise in both public and private utilization of System Calls in windows malware for post-exploitation activities, as well as for the bypassing of EDR or Endpoint Detection and Response.

Jack Hacks

#Arrogance, #hubris

The downfall of many

#MicheleSpagnuolo, aka "AlphaRaccoon" (lol! 🤪) on #Polymarket, made a number of successful bets on #Google search terms

Well, that's because he worked at Google

🤦

Thing is, his winnings were substantial, but still paled in comparison to his high level of remuneration from his job as an #informationSecurity engineer in #Zurich

Well, now Google has placed him on leave

He believed he was so smart

He was. But not smart enough

https://www.theguardian.com/technology/2026/may/28/doj-charges-google-employee-insider-trading-polymarket

Phish Stories is an official pre-convention DEF CON contest that combines the art of creative writing with the strategic challenge of social engineering, inviting participants to craft phishing emails that are both convincing and hilariously entertaining. It gives people at any level the chance to show off their skills in writing, social engineering, and humor to create a unique contest that allows for multiple ways to win. Writers, comedians, and Red-Teamers can all find a path to victory!

https://www.phishstories.org/

What do you win? a Human DEF CON badge

#DEFCON34 #phishing #informationsecurity #cybersecurity