Najam Ul Saqib 

616 Followers
44 Following
604 Posts
I'm Najam Ul Saqib, aka CyberSoldier. I hack and code for fun, and specialize in software security and development. I also contribute to open source projects like OWASP Zaproxy.
Githubhttps://github.com/njmulsqb
LinkedInhttps://linkedin.com/in/njmulsqb
Bloghttps://njmulsqb.github.io
akaCyber Soldier
Pixelfedhttps://pixelfed.social/shiningstar
Peertubehttps://video.infosec.exchange/c/cybersoldier/videos

Back in 2021, when I was a fresh graduate at Systems Limited, my great manager Ali Bandagi asked me a simple question:

โ€œ๐˜•๐˜ข๐˜ซ๐˜ข๐˜ฎ, ๐˜ธ๐˜ฉ๐˜ฆ๐˜ณ๐˜ฆ ๐˜ฅ๐˜ฐ ๐˜บ๐˜ฐ๐˜ถ ๐˜ด๐˜ฆ๐˜ฆ ๐˜บ๐˜ฐ๐˜ถ๐˜ณ๐˜ด๐˜ฆ๐˜ญ๐˜ง ๐˜ช๐˜ฏ 5 ๐˜บ๐˜ฆ๐˜ข๐˜ณ๐˜ด?โ€

Without overthinking it, I said:
โ€œ๐˜ ๐˜ด๐˜ฆ๐˜ฆ ๐˜ฎ๐˜บ๐˜ด๐˜ฆ๐˜ญ๐˜ง ๐˜ญ๐˜ฆ๐˜ข๐˜ฅ๐˜ช๐˜ฏ๐˜จ ๐˜ฎ๐˜บ ๐˜ฐ๐˜ธ๐˜ฏ ๐˜ต๐˜ฆ๐˜ข๐˜ฎ ๐˜ฐ๐˜ง ๐˜ต๐˜ข๐˜ญ๐˜ฆ๐˜ฏ๐˜ต๐˜ฆ๐˜ฅ ๐˜ฑ๐˜ฆ๐˜ฐ๐˜ฑ๐˜ญ๐˜ฆ โ€” ๐˜ช๐˜ฏ ๐˜ฎ๐˜บ ๐˜ฐ๐˜ธ๐˜ฏ ๐˜ค๐˜ฐ๐˜ฎ๐˜ฑ๐˜ข๐˜ฏ๐˜บ.โ€

At the time, it felt like an ambitious answer from someone just starting out.

Looking back now, Iโ€™m filled with nothing but ๐—ด๐—ฟ๐—ฎ๐˜๐—ถ๐˜๐˜‚๐—ฑ๐—ฒ.

Because today, thatโ€™s exactly where I am.

2025 was the year I stepped out of my comfort zone โ€” leaving a stable role at a company many aspire to work at, and choosing to build something of my own from the ground up.

Starting Exfiltra wasnโ€™t about taking a risk for the sake of it.

๐Ÿ‘‰ It was about committing to a mission: delivering high-quality application and cloud security, built with depth, integrity, and strong fundamentals.

Iโ€™m deeply grateful to God for the opportunities, the strength, and the guidance throughout this journey.

And Iโ€™m thankful to everyone in my LinkedIn network โ€” for the encouragement, thoughtful conversations, and trust you placed in my work this year.

Sharing this photo from my office for the first time feels like a quiet milestone.
โ†ณ A reminder that setting clear targets matters โ€” and that I still have much bigger goals ahead.

๐—ช๐—ถ๐˜€๐—ต๐—ถ๐—ป๐—ด ๐—ฒ๐˜ƒ๐—ฒ๐—ฟ๐˜†๐—ผ๐—ป๐—ฒ ๐—ฎ ๐—ต๐—ฎ๐—ฝ๐—ฝ๐˜† ๐—ฎ๐—ป๐—ฑ ๐˜€๐˜‚๐—ฐ๐—ฐ๐—ฒ๐˜€๐˜€๐—ณ๐˜‚๐—น ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ.

Iโ€™m looking forward to building more meaningful connections here in the year ahead!

I have recently shifted my small business from Zoho to completely self-hosted opensource products, and been loving it so far.

Shout out to @nextcloud @openproject @vaultwarden_releases and @suitecrm

I won't stop yapping. ๐Ÿ˜ฌ

#opensource #linux

The last time I posted this I had some Zionists out themselves and get angry, so to be crystal clear I will repost it. I will always be a voice for the oppressed and for those less privileged than myself. Even if it costs me infosec clout.
Spent some time gardening after a long time. It's has always been a pretty refreshing and restorative and I should be spending more time with plants.

In these photos, you'll see attempt to grow chillis, some lemon grass plants, cuttings of holy basil and lucky bamboo and some oranges :)

Also, I have started the attempt to create compost from kitchen waste, let's see how it goes :)

#houseplants #plants #gardening #urbangarden #communitygardening #houseplant

๐Ÿšจ OWASP Top 10 (2025) is here!

With some really interesting changes that every developer and security engineer should pay attention to.

For context โ€” OWASP releases its Top 10 web vulnerability categories every 4 years, with the last version released in 2021.

Here are a few major changes this time around ๐Ÿ‘‡

1๏ธโƒฃ Injection going down the list
This trend makes sense โ€” most modern frameworks now provide strong, built-in protection. Unless a developer really tries to break something, these issues are becoming less common.

2๏ธโƒฃ SSRF merged into Access Control
This oneโ€™s a bit odd. Iโ€™m still digging into the reasoning behind it โ€” feels like a stretch, but letโ€™s see how the community interprets it.

3๏ธโƒฃ A new category: Mishandling of Exceptional Conditions
This one caught my eye. Itโ€™s an interesting addition and reflects how subtle error handling flaws can have major security impact.

๐Ÿ’ก Access Control remains the king.
Even with AI becoming incredibly capable, it still struggles to test access control properly โ€” every app has its own roles, logic, and edge cases. I donโ€™t see that changing anytime soon.

Now Iโ€™m curious โ€”
๐Ÿ‘‰ Do you think Business Logic Vulnerabilities will fall under this new โ€œExceptional Conditionsโ€ category?

Drop your thoughts in the comments โ€” would love to hear how others interpret this yearโ€™s changes.

Are people still using Mastodon?
What do you think security engineers (offensive) should do to stay relevant in the era of AI?
Here's an interesting post that interlinks deep-work and cybersecurity by @Azeria, must read: https://azeria-labs.com/the-importance-of-deep-work-the-30-hour-method-for-learning-a-new-skill/
The Importance of Deep Work & The 30-Hour Method for Learning a New Skill

Azeria-Labs

Easily track your books with this nifty open source app!

https://news.itsfoss.com/openreads/

Openreads: An Open Source Mobile App To Keep Track of Your Books

You can keep track of your book progresses using the Openreads app. Here's how.

It's FOSS News