
cy//ective
@cyllective
IT Security Services - ๐จ๐ญ๐ค๐จโ๐ป
ID: 791937054
https://cyllective.com 30-08-2012 16:30:51
997 Tweet
537 Followers
2,2K Following

Kudos to our own @cydave.bsky.social // for finding severe vulnerabilities in the 'Canto Extension' of TYPO3! His keen skills made the digital world a safer place by preventing potential #SSRF and #RCE. We're proud of you, Dave! <3 ๐ #TYPO3 #RCE #SSRF #Exploit โก๏ธtypo3.org/security/advisโฆ

cyllective is #hiring! We seek a skilled Security Engineer / Penetration Tester, primarily focusing on white box penetration testing of web apps. Hack the application process with the CTF challenges provided๐ป๐ชโก๏ธcyllective.com/jobs/postings/โฆ #pentest #job #cybersecurity #switzerland


During a #DLP (Data Loss Prevention) audit, we had to find a way to copy files off a computer with restricted USB functionality. Using microcontrollers, software engineering skills, and a neat browser feature called #WebSerial, we developed #COMfiltrat0r. cyllective.com/blog/post/comfโฆ




We are excited to have Cyllective as a Silver sponsor supporting the AREA41 conference - Thank you๐ฅณ See you 6-7.June in Zรผrich DC4131 - DEFCON CH cy//ective


๐จ New Blog Post! ๐จ ๐ธ๏ธ Discover our journey of identifying a critical stored XSS vulnerability in Collabora Online, CVE-2024-29182๐๐ป Our latest blog post provides an in-depth analysis of how @cydave.bsky.social // found the flaw. #web #cve #collabora โก๏ธ cyllective.com/blog/posts/cveโฆ

๐ Verstรคrkung gesucht! ๐ Wir suchen eine Person, die uns im Backoffice unterstรผtzt und eine Schlรผsselrolle im Unternehmen รผbernimmt. ๐ค Bist du interessiert dich in einem KMU im Bereich Cybersicherheit zu verwirklichen? ๐ค ๐พ cyllective.com/de/jobs ๐ #Cyber #Hiring #Job


Creating a Malicious Atlassian Plugin ๐ฆ In our latest post, we dive into the dark side of Atlassian plugins. Discover how we created a malicious plugin capable of hiding from admins, exfil. data, and even running a reverse shell. ๐ cyllective.com/blog/posts/atlโฆ #Atlassian #infosec

Huge thanks to Risky Businessยฎ Media for mentioning the #ghmlwr project! ๐ ๐ฐ news.risky.biz/risky-biz-newsโฆ ๐ ghmlwr.0dave.ch - @cydave.bsky.social // #Infosec #GitHub #ThreatIntelligence




๐ New from cyllective: ๐๐๐ฎ๐ญ๐ก ๐๐๐๐ฌ ๐ ๐ Master OAuth 2.0 with hands-on Docker-based labs: -JWT signature flaws -Open redirect risks -Claim validation issues ๐ปDevs & pentesters: sharpen your skills! ๐cyllective.com/blog/posts/oauโฆ #OAuth #Cybersecurity #Training

The first CVEs of 2025 are live! ๐จ We discovered ~10 vulnerabilities in Cordaware bestinformed, leading to 4 CVEs. They can be chained for an unauthenticated compromise of the server and all connected clients. ๐พ CVE-2025-042{2..5} cyllective.com/blog/posts/corโฆ #blogpost #CVE #infosec