Code Security for Conversational AI: Uncovering a Zip Slip in EDDI

Learn how SonarQube identified a Zip Slip vulnerability (CVE-2025-32779) in EDDI, an open-source conversational AI middleware.

Made a writeup for a nice #Nix challenge we solved at #KalmarCTF

Check it out!

https://msanft.foo/blog/kalmarctf-2025-nix-build-as-a-service/

KalmarCTF 2025: nix-build as a service (Misc) | Moritz Sanft

With under 48 hours till we kick off with #KalmarCTF 2025, we are happy to announce that @zellic_io is joining as a sponsor this year, as well as an updated prize pool!
Come compete with the best competitive hackers from around the world!

After securing the #1 spot on CTFtime last year, we've spent the winter cooking up a nice set of challenges to share what we've learned with the community! From approachable curiosities to the fiendishly difficult! There should be something for everyone!

Do you have what it takes to find 0-days and novel techniques? Will you solve all of our challenges? Join us from Friday!

Updated Prize Pool
๐Ÿฅ‡ First Place: $2000 and 3x IDA Pro Named Licenses (each with 2 Decompilers)
๐Ÿฅˆ Second Place: $1000 and 2x IDA Pro Named Licenses (each with 2 Decompilers)
๐Ÿฅ‰ Third Place: $750 and 1x IDA Pro Named License (with 2 Decompilers)
4๏ธโƒฃ Fourth Place: $500
5๏ธโƒฃ Fifth Place: $400
6๏ธโƒฃ Sixth Place: $350

Thanks again to @zellic_io as they join our long time sponsor @HexRaysSA in helping us put on a great CTF for the community!

Registrations are now open at https://kalmarc.tf !

KalmarCTF 2025

๐—ž๐—ฎ๐—น๐—บ๐—ฎ๐—ฟ๐—–๐—ง๐—™ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฑ ๐—ถ๐˜€ ๐—ท๐˜‚๐˜€๐˜ ๐—ฎ๐—ฟ๐—ผ๐˜‚๐—ป๐—ฑ ๐˜๐—ต๐—ฒ ๐—ฐ๐—ผ๐—ฟ๐—ป๐—ฒ๐—ฟ - ๐—ฐ๐—ผ๐—บ๐—ฒ ๐—ฐ๐—ผ๐—บ๐—ฝ๐—ฒ๐˜๐—ฒ ๐˜„๐—ถ๐˜๐—ต ๐˜๐—ต๐—ฒ ๐—ฏ๐—ฒ๐˜€๐˜ ๐—ฐ๐—ผ๐—บ๐—ฝ๐—ฒ๐˜๐—ถ๐˜๐—ถ๐˜ƒ๐—ฒ ๐—ต๐—ฎ๐—ฐ๐—ธ๐—ฒ๐—ฟ๐˜€ ๐—ณ๐—ฟ๐—ผ๐—บ ๐—ฎ๐—ฟ๐—ผ๐˜‚๐—ป๐—ฑ ๐˜๐—ต๐—ฒ ๐˜„๐—ผ๐—ฟ๐—น๐—ฑ ๐—ฎ๐—ป๐—ฑ ๐˜„๐—ถ๐—ป ๐—ด๐—ฟ๐—ฒ๐—ฎ๐˜ ๐—ฝ๐—ฟ๐—ถ๐˜‡๐—ฒ๐˜€!

The #KalmarCTF 2025 is on the horizon, and Kalmarunionen is ready to raise the bar once again. Mark your calendars for March 7th - 9th, 2025, and gear up for a 48-hour showdown of skill, and pure CTF grit.

๐‡๐ž๐ซ๐žโ€™s ๐ฐ๐ก๐š๐ญโ€™s ๐ข๐ง ๐ฌ๐ญ๐จ๐ซ๐ž:
With a generous nod to @HexRaysSA for making the coveted #IDAPro licenses possible, we promise an unforgettable event brimming with complex challenges in binary exploitation, reverse engineering, and other classic #CTF categories.

๐Ÿฅ‡ First Place: 3x IDA Pro Named Licenses* with 2 Decompilers each
๐Ÿฅˆ Second Place: 2x IDA Pro Licenses* with 2 Decompilers each
๐Ÿฅ‰ Third Place: 1x IDA Pro License* with 2 Decompilers

Why join hashtag #KalmarCTF 2025?
- Test yourself against top global teams and except some fun and original challenges
- Immerse yourself in a thriving community of passionate CTF players and hackers.

If youโ€™re ready to push your limits, claim your glory, and maybe take home some serious #HexRays loot, head over to KalmarC.TF for all the details.
REassemble your dream team, and lets see who takes all home the licenses this year.

#hacking #cybersecurity #CTF

KalmarCTF: Reproducible Pwning writeup

computers i guess

hey #nixos ppl there is a #CTF #kalmarctf with a nixos challenge on now! come get second blood on it, I had fun solving it :D

https://kalmarc.tf/challenges#Reproducible%20Pwning-20

KalmarCTF

The countdown to #KalmarCTF 2023 has started! We proudly support this event, organized by Kalmarunionen, and wish all teams and players luck! May the best winโ€ฆ

๐ŸŽŸ๏ธโ€‹ Register here: https://kalmarc.tf

๐ŸŒ More about IDA Pro: https://hex-rays.com/ida-pro/?utm_source=Social-Media-Post&utm_medium=Twitter&utm_campaign=kalmarctf-3โ€ฆ

#HexRays

KalmarCTF 2025

Are you good enough to be on the podium? In #KalmarCTF, the stakes are high - #IDAPro licenses! We are thrilled to support this fantastic event.

๐ŸŽŸ๏ธ Register here: https://kalmarc.tf/

๐ŸŒ More about IDA Pro: https://hex-rays.com/ida-pro/?utm_source=Social-Media-Post&utm_medium=Mastodon&utm_campaign=kalmarctf-2

#HexRays

KalmarCTF 2025

We (#KalmarUnionen CTF Team) are hosting our first CTF competition, #KalmarCTF, on 03-05 Mar 2023.
Top 3 teams will win #IDAPro Licenses, courtesy of our sponsor #HexRaysSA. Visit https://KalmarC.TF for more information, rules, and to register your team now!
#infosec #ctf #competution
KalmarCTF 2025