AppSec Guy
150 subscribers
79 photos
9 videos
13 files
30 links
Download Telegram
First image is taken at previous Cyberkent 2.0 (2024). Second one is from the last Cyberkent 3.0

This time, my team showed TuranSec's capability to work on multiple complex processes (blue team, red team, etc) at once and make it in perfect quality at the same time.

This is not some PR words, just recap of how team did it.

So, here we are, expanded, learned a lot.
6๐Ÿ‘5๐Ÿ”ฅ4โค1๐Ÿฅฑ1
photo_2025-11-17_20-57-02.jpg
104.6 KB
bof - explorer.exe
๐ŸŒš4๐Ÿ”ฅ1
Forwarded from Turan Security
๐Ÿ† BlackHat MEA 2025 Final CTF musobaqasida 12-o'rin!

Turan Security va O'zbekiston sharafini himoya qilgan xalqaro jamoa dunyoning eng nufuzli kiberxavfsizlik musobaqalaridan birida 125 jamoa orasidan TOP-12 talikdan joy oldi!

Saudiya Arabistoning Ar-Riyod shahrida oโ€˜tkazilgan BlackHat MEA 2025 tadbiri - global miqyosdagi eng kuchli mutaxassislar, ekspertlar va jahonning yetakchi kiberxavfsizlik jamoalari uchrashadigan maydon.

TOP jamoalar orasida Team leadโ€™imiz 3 ta topshiriqda:
๐ŸšฉFirstblood - web, birinchi;
๐ŸšฉFirstblood - forensics, birinchi;
๐ŸšฉSecondblood - web, ikkinchi bo'lib topshiriqni barajarishga erishdi.


Birinchi marta uchun eng kuchli jamoalar o'rtasida topshiriqlarni birinchi bo'lib ishlash juda qiyin va kamdan-kam uchratiladigan natija! Ushbu yutuq uchun Team lead'imiz tashkilotchilar tomonidan maxsus "Firstblood coin"lar bilan taqdirlandi, bunday natija O'zbekiston uchun birinchisi hisoblanadi๐Ÿ”ฅ

Bizning maqsadimiz xalqaro maydonda Oโ€˜zbekistonni nufuzini oshirish, yoshlarga ilhom berish va kiberxavfsizlik sohasini rivojlantirish.
๐Ÿ†’5๐Ÿ‘3๐Ÿ”ฅ2
i was able to get 2 firstblood, 1 secondblood

it was impossible to solve tasks earlier than R3kapig, FMC, bios, Odin, etc who are the most elite teams but i did it๐Ÿ”ฅ
1๐Ÿ”ฅ15๐Ÿ‘2
Forwarded from JavaSec
Why mid-January๐Ÿค”
Please open Telegram to view this post
VIEW IN TELEGRAM
1๐Ÿ‘4
JavaSec
Why mid-January๐Ÿค”
Pr0xxxy is the goat๐Ÿ”ฅ
๐Ÿ”ฅ4๐Ÿ‘1
Forwarded from JavaSec
3 ta zero-day va uchunchi 0day zaifligi accepted va ๐Ÿ‘€000๐Ÿ’ฒ bounty!

1-zero-day zaifligi uchun reject olganimda menimcha Zero Day Initiativedan
accepted olishni iloji yoq deb oylagan edim

Zero Day Initiative (ZDI) โ€” Trend Micro tomonidan yuritiladigan, dunyodagi eng yirik va nufuzli vulnerability research dasturlaridan biri. Ushbu dastur mustaqil xavfsizlik tadqiqotchilari (researcherlar) tomonidan topilgan zero-day va kritik zaifliklarni sotib oladi, ularni ishlab chiqaruvchi (vendor) bilan hamkorlikda yopilishini taโ€™minlaydi va foydalanuvchilar xavfsizligini oshiradi.

Shu dastur orqali topgan zaifligim ZDI laboratoriyasida toโ€˜liq tekshirilib, tasdiqlandi va rasmiy ravishda qabul qilindi. Natijada bounty oldim va ZDI researcher sifatida tan olindim.


Demak iloji borโ€ฆ
๐Ÿ”ฅ6
image_2026-01-01_00-23-48.png
56.5 KB
Let's start this year with insane challenge

It's just a joke, let me try guys.

Btw, im late for 20 minutes, but yes, happy new year, i mean hope we can make some good things this year.
๐Ÿ”ฅ2๐Ÿค1
AppSec Guy
https://youtu.be/TmWM51mTY_c?si=H9oeSxnZcnhBy_ar
AI helps to reduce our need for world's elites, it enables them to lay off as much as possible employees while saving the budget.

There is no meaning to pay for loose, they have been doing this for decades. So, they don't need population who they really don't need on running this world, so they start small wars to erase mass population while keeping most part still to run what AI cannot make it done.

They are waiting for the evolution of AI, so they have no dependency on us.

They don't care about us, they don't care if AI goes rogue (it's sht from movies), peace.

some conspiracy theory same as flat earth
image_2026-01-03_17-22-48.png
286 KB
its cool
1๐Ÿ”ฅ2๐Ÿ†’1
This media is not supported in your browser
VIEW IN TELEGRAM
RCE on Google Chrome up to 141.0.7390.65 version through Use after free in Storage (CVE-2025-11460) - ASLR, CFG bypass

PoC exploit: https://issues.chromium.org/issues/446722008

Bounty: $100,000
๐Ÿ”ฅ6