# hacking

Published articles for hacking.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Modern Android Hacking

DevFeed: [Modern Android Hacking](<https://devfeed.tech/articles/modern-android-hacking-32344.md>)

Original publisher: [Read original article](<https://dustn.dev/page/presentations/2020-11-18-modern-android-hacking/>)

Author: dustin@dustn.dev (Dustin Summers)

Published: 2026-09-17T04:13:15.404035Z

Content type: article

Language: en

Sources: [Dustin Summers](<https://devfeed.tech/sources/dustin-summers.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [Android](<https://devfeed.tech/topics/android.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [modern](<https://devfeed.tech/tags/modern.md>), [presentation](<https://devfeed.tech/tags/presentation.md>), [summit](<https://devfeed.tech/tags/summit.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

A presentation titled "Modern Android Hacking" was given at the 2020 Android Summit, which was hosted virtually due to the pandemic. The page provides a video of the presentation.

### Source excerpt

This presentation was given at the 2020 Android Summit which was hosted virtually due to the pandemic Video of Presentation:

## Developer commentary on agentic hacking, AI persistence, and LLM programming

DevFeed: [Developer commentary on agentic hacking, AI persistence, and LLM programming](<https://devfeed.tech/articles/fragments-september-16-31476.md>)

Original publisher: [Read original article](<https://martinfowler.com/fragments/2026-09-16.html>)

Author: Martin Fowler (martin@martinfowler.com)

Published: 2026-09-16T20:05:00Z

Content type: opinion

Language: en

Sources: [Martin Fowler](<https://devfeed.tech/sources/martin-fowler.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Programming](<https://devfeed.tech/topics/programming.md>), [Wiki](<https://devfeed.tech/topics/wiki.md>), [hugging face](<https://devfeed.tech/topics/hugging-face.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [build](<https://devfeed.tech/tags/build.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [llms](<https://devfeed.tech/tags/llms.md>), [persistence](<https://devfeed.tech/tags/persistence.md>)

### AI overview

This collection of developer commentary discusses reports of agentic hacking involving RubyGems, Hugging Face, and Wiki attacks, including questions about OpenAI's disclosure and log review. It also examines AI systems' unpredictable behavior, improvements in reasoning and persistence, and the use of harnesses to control LLM-based programming.

### Source excerpt

Reports of agentic hacking continue, in this case it happened back in May and it seems OpenAI did not disclose that they were responsible. Simon Willison sees two options: After the Hugging Face and Wiki attacks OpenAI were still unable to review their previous logs and determine that they had previously attacked RubyGems. They knew about the attack on RubyGems and made the decision not to reach out to the RubyGems team about it. Both of these are bad! Given this incident, the Hugging Face situation, and the Wiki attack, the obvious question right now is how many more incidents like this are out there waiting to be discovered? ❄ ❄ ❄ ❄ ❄ Dave Farley: Stop asking the sci-fi question: 'Is it conscious?' Start asking the engineering question: 'Is this a powerful, unpredictable component being put somewhere consequential, and where's the feedback that tells us that it's safe? ❄ ❄ ❄ ❄ ❄ Nate Silver is known for his forecasts, but to do them he writes a lot of code for his models. He's found agentic programming capable of doing miraculous work. In spending so much time with the LLMs, I'm super attentive to improvements in their capabilities. And these changes tend not to be so linear. Instead, they improve in step functions, almost as phase changes. Suddenly, the models just start doing things capably that they were screwing up before. In my experience, there was a big leap forward when reasoning models first came out in late 2024/early 2025 -- enough that they were occasionally useful for tasks involving data and not just words -- and then another one this past winter. The most recent changes I've noticed, however, have had less to do with intelligence and more with persistence. Consider the Hugging Face attack. Although these agents showed remarkable intelligence, they weren't really super-intelligent - but they were super-persistent. This is a common theme of AI in its various forms: Game engines like AlphaGo Zero start out by basically making random moves -- but by playin

## Steam Frame vs. Quest 3 Specs: Better PC Streaming, Power & Hackability

DevFeed: [Steam Frame vs. Quest 3 Specs: Better PC Streaming, Power & Hackability](<https://devfeed.tech/articles/steam-frame-vs-quest-3-specs-better-pc-streaming-power-hackability-17475.md>)

Original publisher: [Read original article](<https://roadtovr.com/steam-frame-vs-quest-3-specs/>)

Author: Scott Hayden

Published: 2026-09-14T16:59:00Z

Content type: comparison

Language: en

Sources: [Road to VR](<https://devfeed.tech/sources/road-to-vr.md>)

Topics: [Streaming](<https://devfeed.tech/topics/streaming.md>), [pc](<https://devfeed.tech/topics/pc.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Steam Deck](<https://devfeed.tech/topics/steam-deck.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Operating system](<https://devfeed.tech/topics/operating-system.md>), [Arm](<https://devfeed.tech/topics/arm.md>)

Tags: [arm](<https://devfeed.tech/tags/arm.md>), [cameras](<https://devfeed.tech/tags/cameras.md>), [compatibility](<https://devfeed.tech/tags/compatibility.md>), [devices](<https://devfeed.tech/tags/devices.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [linux](<https://devfeed.tech/tags/linux.md>), [meta-quest-3-news-reviews](<https://devfeed.tech/tags/meta-quest-3-news-reviews.md>), [news](<https://devfeed.tech/tags/news.md>), [os](<https://devfeed.tech/tags/os.md>), [pc](<https://devfeed.tech/tags/pc.md>), [pc-vr-news-reviews](<https://devfeed.tech/tags/pc-vr-news-reviews.md>), [pcie](<https://devfeed.tech/tags/pcie.md>), [steam-deck](<https://devfeed.tech/tags/steam-deck.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [windows](<https://devfeed.tech/tags/windows.md>), [x86](<https://devfeed.tech/tags/x86.md>)

### AI overview

This comparison examines Valve's Steam Frame standalone headset against Quest 3. Steam Frame is designed to run Steam's flatscreen and PC VR libraries, stream PC VR games wirelessly through a dedicated Wi-Fi 6E dongle, and support native x86 Windows and Linux content through a compatibility layer. Compared with Quest 3, it offers a more powerful Qualcomm Snapdragon processor, a more open and hackable SteamOS platform, an accessible gen4 PCIe expansion port, and broader compatibility, although its application compatibility is not yet as established.

### Source excerpt

Want to know how Valve's Steam Frame standalone headset stacks up against the competition? Read on to find out. Steam Frame is a lot like Steam Deck; it can play pretty much all of Steam's game library out of the box, which includes flatscreen content based on x86 architecture--basically everything on Steam--and also now PC [...] The post Steam Frame vs. Quest 3 Specs: Better PC Streaming, Power & Hackability appeared first on Road to VR.

## FREE-WILi 2 portable hacking multitool features two RP2350 MCUs, ESP32-C5, ICE40 FPGA, and Raspberry Pi CM0

DevFeed: [FREE-WILi 2 portable hacking multitool features two RP2350 MCUs, ESP32-C5, ICE40 FPGA, and Raspberry Pi CM0](<https://devfeed.tech/articles/free-wili-2-portable-hacking-multitool-features-two-rp2350-mcus-esp32-c5-ice40-fpga-and-raspberry-pi-cm0-14036.md>)

Original publisher: [Read original article](<https://www.cnx-software.com/2026/09/09/free-wili-2-portable-hacking-multitool-features-two-rp2350-mcus-esp32-c5-ice40-fpga-and-raspberry-pi-cm0/>)

Author: Debashis Das

Published: 2026-09-09T00:00:02Z

Content type: news

Language: en

Sources: [CNX Software - Embedded Systems News](<https://devfeed.tech/sources/cnx-software-embedded-systems-news.md>)

Topics: [Embedded Systems](<https://devfeed.tech/topics/embedded-systems.md>), [Raspberry Pi](<https://devfeed.tech/topics/raspberry-pi.md>), [ESP32-C5](<https://devfeed.tech/topics/esp32-c5.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [802-15-4](<https://devfeed.tech/tags/802-15-4.md>), [ble](<https://devfeed.tech/tags/ble.md>), [bluetooth](<https://devfeed.tech/tags/bluetooth.md>), [broadcom-bcmxxxx](<https://devfeed.tech/tags/broadcom-bcmxxxx.md>), [c-c-plus-plus](<https://devfeed.tech/tags/c-c-plus-plus.md>), [can](<https://devfeed.tech/tags/can.md>), [electronics](<https://devfeed.tech/tags/electronics.md>), [embedded](<https://devfeed.tech/tags/embedded.md>), [esp32](<https://devfeed.tech/tags/esp32.md>), [esp32-c5](<https://devfeed.tech/tags/esp32-c5.md>), [espressif](<https://devfeed.tech/tags/espressif.md>), [fpga](<https://devfeed.tech/tags/fpga.md>), [hack](<https://devfeed.tech/tags/hack.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [lattice](<https://devfeed.tech/tags/lattice.md>), [linux](<https://devfeed.tech/tags/linux.md>), [lora](<https://devfeed.tech/tags/lora.md>), [meshtastic](<https://devfeed.tech/tags/meshtastic.md>), [nfc](<https://devfeed.tech/tags/nfc.md>), [open-hardware](<https://devfeed.tech/tags/open-hardware.md>), [python](<https://devfeed.tech/tags/python.md>), [raspberry-pi](<https://devfeed.tech/tags/raspberry-pi.md>), [raspberry-pi-rp2350](<https://devfeed.tech/tags/raspberry-pi-rp2350.md>), [rfid](<https://devfeed.tech/tags/rfid.md>), [rust](<https://devfeed.tech/tags/rust.md>), [security](<https://devfeed.tech/tags/security.md>), [som](<https://devfeed.tech/tags/som.md>), [stm32](<https://devfeed.tech/tags/stm32.md>), [stmicro-stm32](<https://devfeed.tech/tags/stmicro-stm32.md>), [texas-instruments-simplelink](<https://devfeed.tech/tags/texas-instruments-simplelink.md>), [thread](<https://devfeed.tech/tags/thread.md>), [tools](<https://devfeed.tech/tags/tools.md>), [video](<https://devfeed.tech/tags/video.md>), [wi-fi](<https://devfeed.tech/tags/wi-fi.md>), [wifi-6](<https://devfeed.tech/tags/wifi-6.md>), [wireless](<https://devfeed.tech/tags/wireless.md>), [zigbee](<https://devfeed.tech/tags/zigbee.md>)

### AI overview

The FREE-WILi 2 Founder Edition is an open-hardware, portable multitool for hardware hackers, pentesters, and embedded-system developers. It combines two Raspberry Pi RP2350 MCUs, an ESP32-C5, a Lattice ICE40UP5K FPGA, and a Raspberry Pi CM0 capable of running a full Linux OS, along with touchscreen controls, expansion headers, and multiple wireless interfaces.

### Source excerpt

The FREE-WILi 2 (Founder Edition) is an open-hardware, portable hacking multitool and lab designed for hardware hackers, pentesters, and embedded system developers. Designed as an "open electronics multitool," it combines a range of chips and modules into a handheld device, including two Raspberry Pi RP2350 MCUs, an ESP32-C5 for wireless connectivity, a Lattice ICE40UP5K FPGA, and a Raspberry Pi CM0 for running a full Linux OS. The device also features a 3.5-inch capacitive touchscreen, a 14-button physical interface, and modular "Orca" headers for hardware expansion. Its wireless features include 2.4/5GHz Wi-Fi, Bluetooth, LoRa, sub-GHz RF, NFC, 125kHz RFID, and IR. These features make it very suitable for wireless testing, embedded hardware debugging, real-time control, electronics development, and retro gaming, with support for Adafruit Fruit Jam, PICO-8, and Doom. FREE-WILi 2 specifications: Compute Main MCUs - 2x Raspberry Pi RP2350B (One for main controls, one dedicated to display) SoM - Raspberry [...] The post FREE-WILi 2 portable hacking multitool features two RP2350 MCUs, ESP32-C5, ICE40 FPGA, and Raspberry Pi CM0 appeared first on CNX Software - Embedded Systems News.

## Latent Powers

DevFeed: [Latent Powers](<https://devfeed.tech/articles/latent-powers-30737.md>)

Original publisher: [Read original article](<https://lucumr.pocoo.org/2026/9/5/latent-powers/>)

Author: Armin Ronacher

Published: 2026-09-05T00:00:00Z

Content type: opinion

Language: en

Sources: [Armin Ronacher](<https://devfeed.tech/sources/armin-ronacher.md>)

Topics: [Dongle](<https://devfeed.tech/topics/dongle.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Rust](<https://devfeed.tech/topics/rust.md>), [Embedded Software Dev](<https://devfeed.tech/topics/embedded-software-dev.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Raspberry Pi](<https://devfeed.tech/topics/raspberry-pi.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [dongle](<https://devfeed.tech/tags/dongle.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [raspberry-pi](<https://devfeed.tech/tags/raspberry-pi.md>), [rust](<https://devfeed.tech/tags/rust.md>), [soc](<https://devfeed.tech/tags/soc.md>), [thoughts](<https://devfeed.tech/tags/thoughts.md>), [usb](<https://devfeed.tech/tags/usb.md>)

### AI overview

A developer experiments with modifying a cheap CarPlay dongle to run custom code while preserving regular CarPlay functionality. After receiving a different SoC than expected, they use LLM-assisted discussions to flash the device and compile CatPlay, a Rust reimplementation of the CarPlay protocol, for the hardware.

### Source excerpt

A few weeks ago I felt like it would be fun to see if I can make one of those cheap Chinese CarPlay dongles run something other than the stock firmware. The idea was that rather than just forwarding CarPlay, why not do something more interesting with them? They all work quite similarly: they act as bridges between your car and the phone. From there they deal with video and audio streams and pass some other data through. Most of them also bring up a custom UI for pairing and have a web interface that your phone can reach for updates. Long story short: I had a conversation with Fable and Sol via Pi about what could be done with such a dongle or whether I should use a Raspberry Pi instead if I wanted to do my own thing there. I figured it might be quite fun to run my own code while still allowing regular CarPlay to pass through. Through working with the LLM I learned about CatPlay, which is a Rust reimplementation of the CarPlay protocol that can run on Carlinkit devices. In particular, it can run on the Carlinkit Mini Ultra, which I figured would be easy enough to buy. I do have a few CarPlay adapters around, but I did not have that particular model, so I bought one on Amazon. Twenty-four hours later, I had a device in my hand that was branded as a Carlinkit Mini Ultra, but instead of being the Ingenic device that the original author used, it turned out to be something else. This is normally where the story would stop. However, it's 2026. Armed with a bit of knowledge about how these systems work, I managed to have some fruitful discussions with Kimi K3 and Sol and figure out how flash the device and in turn, how to make CatPlay compile for that SoC. I guess that hacking these USB devices is not necessarily hard, but it's laborious and you can easily end up bricking your devices. It also just sucks because sometimes you need to work with someone else's code that does not itself run on your machine. In the past, I would abandon many such projects for lack of tenacity.

## LLMs Have Reshaped How We Think About Decompilation and Collaboration

DevFeed: [LLMs Have Reshaped How We Think About Decompilation and Collaboration](<https://devfeed.tech/articles/llms-have-reshaped-how-we-think-about-decompilation-and-collaboration-39684.md>)

Original publisher: [Read original article](<https://mahaloz.re/2026/06/10/hexrays-feature.html>)

Published: 2026-06-10T00:00:00Z

Content type: opinion

Language: en

Sources: [mahaloz.re](<https://devfeed.tech/sources/mahaloz-re.md>)

Topics: [codex](<https://devfeed.tech/topics/codex.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [coding](<https://devfeed.tech/topics/coding.md>), [harvestbench](<https://devfeed.tech/topics/harvestbench.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [codex](<https://devfeed.tech/tags/codex.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [ida](<https://devfeed.tech/tags/ida.md>), [ida-pro](<https://devfeed.tech/tags/ida-pro.md>), [llm-agents](<https://devfeed.tech/tags/llm-agents.md>), [llms](<https://devfeed.tech/tags/llms.md>), [musing](<https://devfeed.tech/tags/musing.md>), [reversing](<https://devfeed.tech/tags/reversing.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

This think piece examines how LLM agents and Codex are changing software decompilation and hacking workflows. It focuses on the shift from humans directly using reversing tools to humans supervising agents, and on the resulting need to coordinate agents, validate findings, and improve information sharing. It also connects these challenges to the authors' earlier work on BinSync, a decompiler collaboration framework.

### Source excerpt

How LLM agents are changing decompilation workflows, collaboration, and the future of reversing tools.

## Hacking Workshop for June/July 2026

DevFeed: [Hacking Workshop for June/July 2026](<https://devfeed.tech/articles/hacking-workshop-for-june-july-2026-33637.md>)

Original publisher: [Read original article](<https://rhaas.blogspot.com/2026/06/hacking-workshop-for-junejuly-2026.html>)

Author: Robert Haas (noreply@blogger.com)

Published: 2026-06-02T18:36:18Z

Content type: news

Language: en

Sources: [Robert Haas](<https://devfeed.tech/sources/robert-haas.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [IO](<https://devfeed.tech/topics/io.md>), [observability](<https://devfeed.tech/topics/observability.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [announce](<https://devfeed.tech/tags/announce.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [io](<https://devfeed.tech/tags/io.md>), [mentoring](<https://devfeed.tech/tags/mentoring.md>), [observability](<https://devfeed.tech/tags/observability.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [sessions](<https://devfeed.tech/tags/sessions.md>), [sign-up](<https://devfeed.tech/tags/sign-up.md>)

### AI overview

The June/July 2026 PostgreSQL Hacking Workshop will feature Melanie Plageman discussing her talk "Additional IO Observability in Postgres with pg_stat_io." Interested participants can sign up to receive an invitation.

### Source excerpt

I was hoping to usual resume the monthly cadence of hacking workshops in June, but it didn't quite happen, largely due to being a little exhausted after pgconf.dev. But, I'm pleased to announce that Melanie Plageman will be joining us to discuss her talk Additional IO Observability in Postgres with pg_stat_io. If you're interesting in joining us, please sign up using this form and I will send you an invite to one of the sessions. As always, thanks to Melanie for joining us.Read more "

## Hacking Workshop for April/May 2026

DevFeed: [Hacking Workshop for April/May 2026](<https://devfeed.tech/articles/hacking-workshop-for-april-may-2026-33635.md>)

Original publisher: [Read original article](<https://rhaas.blogspot.com/2026/03/hacking-workshop-for-aprilmay-2026.html>)

Author: Robert Haas (noreply@blogger.com)

Published: 2026-03-18T19:47:00Z

Content type: opinion

Language: en

Sources: [Robert Haas](<https://devfeed.tech/sources/robert-haas.md>)

Topics: [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [conference](<https://devfeed.tech/tags/conference.md>), [event](<https://devfeed.tech/tags/event.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [mentoring](<https://devfeed.tech/tags/mentoring.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [workshop](<https://devfeed.tech/tags/workshop.md>)

### AI overview

The author plans a combined April and May hacking workshop covering Masahiko Sawada's PGCon 2022 talk, "Breaking away from FREEZE and Wraparound." Interested participants can sign up to receive an invitation. The post also mentions PGConf.dev 2026, scheduled for May 19-22 at Simon Fraser University in Vancouver, Canada.

### Source excerpt

I'm planning to hold a single hacking workshop for April and May combined, covering Masahiko Sawada's talk, Breaking away from FREEZE and Wraparound, given at PGCon 2022. If you're interested in joining us, please sign up using this form and I will send you an invite to one of the sessions. Thanks to Sawada-san for agreeing to join us. Read more "

## Insecure Dava India Pharmacy APIs Exposed Super Admin Users and Enabled Privileged Account Creation

DevFeed: [Insecure Dava India Pharmacy APIs Exposed Super Admin Users and Enabled Privileged Account Creation](<https://devfeed.tech/articles/hacking-a-pharmacy-to-get-free-prescription-drugs-and-more-32619.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/02/13/dava-india-hack/>)

Author: Eaton

Published: 2026-02-14T03:07:20Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Website](<https://devfeed.tech/topics/website.md>), [account](<https://devfeed.tech/topics/account.md>), [password reset](<https://devfeed.tech/topics/password-reset.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Next.js](<https://devfeed.tech/topics/next-js.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [password](<https://devfeed.tech/tags/password.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

A security write-up describes insecure super-admin APIs on Dava India Pharmacy's website. The APIs exposed a list of super-admin users without authentication, and testing indicated that creating a super-admin account was a supported operation.

### Source excerpt

Super admin exploit on Dava India Pharmacy's website gave complete control over everything.

## Hacking Workshop for February 2026

DevFeed: [Hacking Workshop for February 2026](<https://devfeed.tech/articles/hacking-workshop-for-february-2026-33632.md>)

Original publisher: [Read original article](<https://rhaas.blogspot.com/2026/01/hacking-workshop-for-february-2026.html>)

Author: Robert Haas (noreply@blogger.com)

Published: 2026-01-15T18:26:00Z

Content type: article

Language: en

Sources: [Robert Haas](<https://devfeed.tech/sources/robert-haas.md>)

Topics: [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [Process](<https://devfeed.tech/topics/process.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [mentoring](<https://devfeed.tech/tags/mentoring.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [workshop](<https://devfeed.tech/tags/workshop.md>)

### AI overview

A February 2026 hacking workshop will host two or three small-group discussions about Amit Langote's talk, "Hacking Postgres Executor For Performance," presented at PGConf India 2025. Participants can discuss PostgreSQL technology, project choices, and the community patch process with the speaker.

### Source excerpt

For next month, I'm scheduling 2 or 3 discussions of Amit Langote's talk, Hacking Postgres Executor For Performance, given at PGConf India 2025. If you're interested in joining us, please sign up using this form and I will send you an invite to one of the sessions. Thanks to Amit for agreeing to attend the sessions.Read more "

## exploits.club Weekly(ish) Newsletter 92 - S23 N-Day PoCs, Printer Overflows, DNG OOB Writes, And More

DevFeed: [exploits.club Weekly(ish) Newsletter 92 - S23 N-Day PoCs, Printer Overflows, DNG OOB Writes, And More](<https://devfeed.tech/articles/exploits-club-weekly-ish-newsletter-92-s23-n-day-pocs-printer-overflows-dng-oob-writes-and-more-32635.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-ish-newsletter-92-s23-n-day-pocs-printer-overflows-dng-oob-writes-and-more/>)

Author: exploits.club

Published: 2025-11-21T16:10:47Z

Content type: article

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [GPU](<https://devfeed.tech/topics/gpu.md>), [Qualcomm](<https://devfeed.tech/topics/qualcomm.md>), [samsung](<https://devfeed.tech/topics/samsung.md>), [Android](<https://devfeed.tech/topics/android.md>), [ctf](<https://devfeed.tech/topics/ctf.md>), [Advent of Code](<https://devfeed.tech/topics/advent-of-code.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [code](<https://devfeed.tech/tags/code.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [gpu](<https://devfeed.tech/tags/gpu.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [printer](<https://devfeed.tech/tags/printer.md>), [qualcomm](<https://devfeed.tech/tags/qualcomm.md>), [samsung](<https://devfeed.tech/tags/samsung.md>)

### AI overview

The 92nd exploits.club Weekly(ish) Newsletter rounds up recent developer and security content, including Advent-themed CTFs, Advent of Code 2025, Binary Ninja 5.2, conference slides, an exploit for Qualcomm GPU microcode vulnerability CVE-2025-21479 on a Samsung S23, Linux KASLR research, and printer security flaws.

### Source excerpt

We are so back. Annnnnyways 👇 In Case You Missed It... HEX ADVENT 2025: Crack the Advent, Conquer the Threat - STAR Labs has put together a Holiday Themed CTF open to women residing in Singapore or Malaysia. Advent of Code 2025 - It's almost the most wonderful time of

## Hacking Displate (For Fun!)

DevFeed: [Hacking Displate (For Fun!)](<https://devfeed.tech/articles/hacking-displate-for-fun-38395.md>)

Original publisher: [Read original article](<https://blog.danlew.net/2025/11/18/hacking-displate-shenanigans/>)

Author: Dan Lew

Published: 2025-11-18T15:00:46Z

Content type: opinion

Language: en

Sources: [Dan Lew Blog](<https://devfeed.tech/sources/dan-lew-blog.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [Website](<https://devfeed.tech/topics/website.md>), [API](<https://devfeed.tech/topics/api.md>), [Browser Extension](<https://devfeed.tech/topics/browser-extension.md>), [browser](<https://devfeed.tech/topics/browser.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [browser](<https://devfeed.tech/tags/browser.md>), [extension](<https://devfeed.tech/tags/extension.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [order](<https://devfeed.tech/tags/order.md>), [scraping](<https://devfeed.tech/tags/scraping.md>), [tracking](<https://devfeed.tech/tags/tracking.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

A developer documents experiments with Displate's website, including tracking Limited Edition resale prices and using its API to discover early-access links. The article also describes ordering a Limited Edition before its public release and competing with another person using a browser extension to find links and monitor inventory.

### Source excerpt

During the pandemic my weird vice/obsession became Displates (metal wall art hung up by magnets): Some of my Displates (along with other tchotchkes in my office) For me, part of the hobby was poking holes in their website. I've long stopped trying to give their devs heartburn,

## LixCon in 2026

DevFeed: [LixCon in 2026](<https://devfeed.tech/articles/lixcon-in-2026-31377.md>)

Original publisher: [Read original article](<https://lix.systems/blog/2025-11-05-lixcon-2026/>)

Published: 2025-11-05T00:00:00Z

Content type: release

Language: en

Sources: [News on Lix](<https://devfeed.tech/sources/news-on-lix.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [announce](<https://devfeed.tech/tags/announce.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [conference](<https://devfeed.tech/tags/conference.md>), [development](<https://devfeed.tech/tags/development.md>), [event](<https://devfeed.tech/tags/event.md>), [hacking](<https://devfeed.tech/tags/hacking.md>)

### AI overview

LixCon 2026 will take place in Paris from April 17 to 19, 2026. The event will focus on the Lix interpreter and its internals, with talks on the first day followed by hands-on development, discussions, and collaboration. Attendance will be limited to 200 people.

### Source excerpt

LixCon 2026 - this coming April, in Paris We won't bury the lede: we're super excited to announce that our first LixCon will take place from the 17th to 19th of April, 2026, in Paris!

## Hacking India's largest automaker: Tata Motors

DevFeed: [Hacking India's largest automaker: Tata Motors](<https://devfeed.tech/articles/hacking-india-s-largest-automaker-tata-motors-32616.md>)

Original publisher: [Read original article](<https://eaton-works.com/2025/10/28/tata-motors-hack/>)

Author: Eaton

Published: 2025-10-29T01:05:40Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [data](<https://devfeed.tech/topics/data.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [aws](<https://devfeed.tech/tags/aws.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [database](<https://devfeed.tech/tags/database.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [india](<https://devfeed.tech/tags/india.md>), [s3](<https://devfeed.tech/tags/s3.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article describes four security findings involving Tata Motors discovered in 2023. It reports that exposed AWS keys on public-facing websites enabled access to sensitive information across many S3 buckets, that weakly encrypted keys could be decrypted, that a Tableau backdoor allowed passwordless login as users including an administrator, and that an exposed Azuga API key compromised a test-drive fleet management system. The author states that the disclosed credentials were rotated and that testing did not download substantial amounts of data or show obvious evidence of malicious access.

### Source excerpt

Tata Motors gave away the keys to their infrastructure and customer data on their public websites.

## exploits.club Weekly Newsletter 89 - iOS GPU Driver Bugs, Kernel Stack UAFs, Hardware Wallet Auth Bypasses, and More

DevFeed: [exploits.club Weekly Newsletter 89 - iOS GPU Driver Bugs, Kernel Stack UAFs, Hardware Wallet Auth Bypasses, and More](<https://devfeed.tech/articles/exploits-club-weekly-newsletter-89-ios-gpu-driver-bugs-kernel-stack-uafs-hardware-wallet-auth-bypasses-and-more-32646.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-newsletter-89-ios-gpu-driver-bugs-kernel-stack-uafs-hardware-wallet-auth-bypasses-and-more/>)

Author: exploits.club

Published: 2025-10-16T15:00:32Z

Content type: article

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [iOS](<https://devfeed.tech/topics/ios.md>), [Security](<https://devfeed.tech/topics/security.md>), [GPU](<https://devfeed.tech/topics/gpu.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Memory Safety](<https://devfeed.tech/topics/memory-safety.md>), [UEFI](<https://devfeed.tech/topics/uefi.md>)

Tags: [firmware](<https://devfeed.tech/tags/firmware.md>), [gpu](<https://devfeed.tech/tags/gpu.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [ios](<https://devfeed.tech/tags/ios.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This weekly newsletter rounds up security research and announcements, including an iOS GPU kernel driver vulnerability whose patched underflow could enable out-of-bounds read/write, though modern allocator hardening may prevent a practical exploit. It also covers x86 memory-safety instructions, Apple security bounty changes, and a Nokia Beacon 1 router teardown involving UART access, command injection, and password generation.

### Source excerpt

Our NBA Finals game 7 prediction didn't go too well earlier this year, but mark these words now: Piastri and Lando are taking each other out at USGP this week. Annnnnnyways 👇 In Case You Missed It... Save the Date for OffensiveCon26 - May 15th and 16th of next

## Vulnerabilities in a centralized automaker dealer platform enabled access to more than 1,000 US dealerships

DevFeed: [Vulnerabilities in a centralized automaker dealer platform enabled access to more than 1,000 US dealerships](<https://devfeed.tech/articles/def-con-33-how-i-hacked-over-1-000-car-dealerships-across-the-us-32615.md>)

Original publisher: [Read original article](<https://eaton-works.com/2025/10/13/def-con-33/>)

Author: Eaton

Published: 2025-10-13T15:13:09Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [account](<https://devfeed.tech/topics/account.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [automotive-industry](<https://devfeed.tech/tags/automotive-industry.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [us](<https://devfeed.tech/tags/us.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article describes two vulnerabilities in a top automaker's centralized dealer platform: missing invite-token verification and a missing privilege check in account creation. The author states that these flaws enabled creation of a national admin account with access to systems across more than 1,000 US dealerships.

### Source excerpt

On August 10, 2025 at DEF CON 33 in Las Vegas, I presented what could possibly be the biggest vulnerability I may ever discover in the automotive industry. Read and watch how I managed to take over a top automaker's entire dealer ecosystem.

## Hacking smarter with Burp AI: NahamSec puts Burp AI to the test

DevFeed: [Hacking smarter with Burp AI: NahamSec puts Burp AI to the test](<https://devfeed.tech/articles/hacking-smarter-with-burp-ai-nahamsec-puts-burp-ai-to-the-test-7710.md>)

Original publisher: [Read original article](<https://portswigger.net/blog/hacking-smarter-with-burp-ai-nahamsec-puts-burp-ai-to-the-test>)

Author: Andrzej Matykiewicz

Published: 2025-10-01T14:31:40Z

Content type: article

Language: en

Sources: [PortSwigger Blog](<https://devfeed.tech/sources/portswigger-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [AI Infrastructure](<https://devfeed.tech/topics/ai-infrastructure.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-infrastructure](<https://devfeed.tech/tags/ai-infrastructure.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [features](<https://devfeed.tech/tags/features.md>), [free](<https://devfeed.tech/tags/free.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [video](<https://devfeed.tech/tags/video.md>), [youtube](<https://devfeed.tech/tags/youtube.md>)

### AI overview

NahamSec demonstrates how Burp AI fits into a real bug bounty and security testing workflow, including Repeater, Scanner follow-up, and recorded logins. The AI features run on demand within PortSwigger's secure AI infrastructure. Burp Suite Professional users receive 10,000 free AI credits.

### Source excerpt

Bug bounty legend, NahamSec, has taken Burp AI for a spin. If you're curious how Burp AI fits into a real workflow, his new video is the perfect place to start. Watch on YouTube Burp AI was built to a

## exploits.club Weekly Newsletter 83: Windows Kernel and Xbox Exploit Research, Plus an LLM-Assisted Security Tool

DevFeed: [exploits.club Weekly Newsletter 83: Windows Kernel and Xbox Exploit Research, Plus an LLM-Assisted Security Tool](<https://devfeed.tech/articles/exploits-club-weekly-newsletter-83-windows-p20-wins-llms-codeql-mcp-takes-down-defcon-ctf-and-more-32640.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-newsletter-83-windows-p20-wins-llms-codeql-mcp-takes-down-defcon-ctf-and-more/>)

Author: exploits.club

Published: 2025-08-21T15:00:46Z

Content type: article

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [exploit](<https://devfeed.tech/tags/exploit.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [llms](<https://devfeed.tech/tags/llms.md>), [race-condition](<https://devfeed.tech/tags/race-condition.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This issue of the exploits.club weekly newsletter highlights a Phrack anniversary release, a Phrack CTF, research into a Windows kernel vulnerability that was adapted to target Xbox One, and a new LLM-related security analysis tool. The supplied text ends before the tool's details are complete.

### Source excerpt

We are getting dangerously close to hacking fueled by PSLs. Get your cozy VS Code color schemes ready...Annnnnnyways 👇 In Case You Missed It... Phrack 4oth Anniversary Release - If you weren't lucky enough to get snag a physical copy from one of the recent cons, the digital

## Intel Outside: Hacking every Intel employee and various internal websites

DevFeed: [Intel Outside: Hacking every Intel employee and various internal websites](<https://devfeed.tech/articles/intel-outside-hacking-every-intel-employee-and-various-internal-websites-32613.md>)

Original publisher: [Read original article](<https://eaton-works.com/2025/08/18/intel-outside-hack/>)

Author: Eaton

Published: 2025-08-18T14:15:43Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [intel](<https://devfeed.tech/topics/intel.md>), [hardcoded credentials](<https://devfeed.tech/topics/hardcoded-credentials.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Angular](<https://devfeed.tech/topics/angular.md>), [Azure](<https://devfeed.tech/topics/azure.md>)

Tags: [angular](<https://devfeed.tech/tags/angular.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [azure](<https://devfeed.tech/tags/azure.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [hardcoded-credentials](<https://devfeed.tech/tags/hardcoded-credentials.md>), [intel](<https://devfeed.tech/tags/intel.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>)

### AI overview

This security investigation describes vulnerabilities in several internal Intel websites. The issues included bypassing corporate login controls, exploiting easily decryptable hardcoded credentials, and using client-side modifications to access employee and supplier information.

### Source excerpt

Hardcoded credentials, pointless encryption, and generous APIs exposed details of every employee and made it possible to break into internal websites.

## exploits.club Weekly Newsletter 82 - Synology Decryption, AI Thought Traces, FortiWeb Auth bypasses, And More

DevFeed: [exploits.club Weekly Newsletter 82 - Synology Decryption, AI Thought Traces, FortiWeb Auth bypasses, And More](<https://devfeed.tech/articles/exploits-club-weekly-newsletter-82-synology-decryption-ai-thought-traces-fortiweb-auth-bypasses-and-more-32639.md>)

Original publisher: [Read original article](<https://blog.exploits.club/exploits-club-weekly-newsletter-82-synology-decryption-ai-thought-traces-fortiweb-auth-bypasses-and-more/>)

Author: exploits.club

Published: 2025-08-14T15:00:35Z

Content type: news

Language: en

Sources: [exploits.club](<https://devfeed.tech/sources/exploits-club.md>)

Topics: [Synology](<https://devfeed.tech/topics/synology.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Traces](<https://devfeed.tech/topics/traces.md>), [SQLite](<https://devfeed.tech/topics/sqlite.md>), [nginx](<https://devfeed.tech/topics/nginx.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [bug](<https://devfeed.tech/tags/bug.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [release](<https://devfeed.tech/tags/release.md>), [sqlite](<https://devfeed.tech/tags/sqlite.md>), [synology](<https://devfeed.tech/tags/synology.md>), [traces](<https://devfeed.tech/tags/traces.md>), [weekly](<https://devfeed.tech/tags/weekly.md>)

### AI overview

The 82nd exploits.club weekly newsletter rounds up security research and developer resources, including Synology encrypted archive decryption, AI agent thought traces from vulnerability assessments, Black Hat slides, a radare2 release, and other security research.

### Source excerpt

We hope everyone enjoyed drinking and partying as a business expense Hacker Summer Camp. Annnnnyways 👇 In Case You Missed It... Black Hat Slides Out! - Most of the links now have the associated slides for you to checkout. radare2 6.0.2 Release - Bug fixes and new features Resources And

## One Year of Hacking Workshops

DevFeed: [One Year of Hacking Workshops](<https://devfeed.tech/articles/one-year-of-hacking-workshops-33627.md>)

Original publisher: [Read original article](<https://rhaas.blogspot.com/2025/07/one-year-of-hacking-workshops.html>)

Author: Robert Haas (noreply@blogger.com)

Published: 2025-07-17T20:24:00Z

Content type: article

Language: en

Sources: [Robert Haas](<https://devfeed.tech/sources/robert-haas.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>)

Tags: [hacking](<https://devfeed.tech/tags/hacking.md>), [mentoring](<https://devfeed.tech/tags/mentoring.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [workshops](<https://devfeed.tech/tags/workshops.md>)

### AI overview

Robert Haas reviews the first year of PostgreSQL Hacking Workshops, covering participation, recurring attendance, speaker involvement, discussion quality, and opportunities to attract more newcomers.

### Source excerpt

I started running PostgreSQL Hacking Workshops just about one year ago, and I've run one each month, except for May, when we had pgconf.dev. Signups are now open for August, if you're interested in joining us for a discussion of Peter Geoghan's talk on Multidimensional search strategies for composite B-Tree indexes, but I'd also like to take a few minutes to summarize where we are after one year of hacking workshops, both the good and the maybe not quite as good. So here goes. Read more "

## Mentoring Applications and Hacking Workshop for April 2025

DevFeed: [Mentoring Applications and Hacking Workshop for April 2025](<https://devfeed.tech/articles/mentoring-applications-and-hacking-workshop-for-april-2025-33624.md>)

Original publisher: [Read original article](<https://rhaas.blogspot.com/2025/03/mentoring-applications-and-hacking.html>)

Author: Robert Haas (noreply@blogger.com)

Published: 2025-03-19T15:04:00Z

Content type: news

Language: en

Sources: [Robert Haas](<https://devfeed.tech/sources/robert-haas.md>)

Topics: [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [.NET Conf](<https://devfeed.tech/topics/net-conf.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [mentoring](<https://devfeed.tech/tags/mentoring.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [workshop](<https://devfeed.tech/tags/workshop.md>)

### AI overview

A March 2025 update announces a one-on-one mentoring program for PostgreSQL contributors, an April discussion of a talk about autovacuum, and plans to skip the May hacking workshop because of 2025.pgconf.dev.

### Source excerpt

Here are a few mentoring-related updates.Read more "

## Fetch the Flag CTF 2025 Community Writeups

DevFeed: [Fetch the Flag CTF 2025 Community Writeups](<https://devfeed.tech/articles/fetch-the-flag-ctf-2025-community-writeups-7918.md>)

Original publisher: [Read original article](<https://snyk.io/blog/fetch-the-flag-ctf-2025-community-writeups/>)

Author: Gina Fitzpatrick

Published: 2025-03-05T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [ctf](<https://devfeed.tech/topics/ctf.md>), [Security](<https://devfeed.tech/topics/security.md>), [Web](<https://devfeed.tech/topics/web.md>), [Discord](<https://devfeed.tech/topics/discord.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [blog](<https://devfeed.tech/tags/blog.md>), [community](<https://devfeed.tech/tags/community.md>), [ctf](<https://devfeed.tech/tags/ctf.md>), [developer](<https://devfeed.tech/tags/developer.md>), [discord](<https://devfeed.tech/tags/discord.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [learning](<https://devfeed.tech/tags/learning.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This blog presents community write-ups from Fetch the Flag CTF 2025, showing how participants solved web, binary, and exploitation challenges. It also directs readers to official write-ups and further community insights in Discord.

### Source excerpt

Discover how players tackled the challenges in Fetch the Flag CTF 2025! This blog features community write-ups breaking down solutions to web, binary, and exploitation challenges.

## Top 10 web hacking techniques of 2024

DevFeed: [Top 10 web hacking techniques of 2024](<https://devfeed.tech/articles/top-10-web-hacking-techniques-of-2024-7709.md>)

Original publisher: [Read original article](<https://portswigger.net/research/top-10-web-hacking-techniques-of-2024>)

Author: James Kettle

Published: 2025-02-04T15:01:48Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [OAuth](<https://devfeed.tech/topics/oauth.md>), [Cache](<https://devfeed.tech/topics/cache.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [LocalStorage](<https://devfeed.tech/topics/localstorage.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [cache](<https://devfeed.tech/tags/cache.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [cookies](<https://devfeed.tech/tags/cookies.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [web](<https://devfeed.tech/tags/web.md>), [xss](<https://devfeed.tech/tags/xss.md>)

### AI overview

This annual community-powered review identifies notable web security research and hacking techniques from 2024. The supplied excerpts discuss OAuth flow hijacking through Cookie Tossing, risks involving cookies and JavaScript's Same-Origin Policy, and a ChatGPT account takeover using inconsistent decoding, path traversal, and Web Cache Deception.

### Source excerpt

Welcome to the Top 10 Web Hacking Techniques of 2024, the 18th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year

[Next page](<https://devfeed.tech/tags/hacking.md?cursor=WyIyMDI1LTAyLTA0VDE1OjAxOjQ4KzAwOjAwIiwgImMxNmMzODQwLWQ1MjQtNDMwNi1iYTJiLTk0OGMwMjliMjA5OCJd>)