Thomas Stacey (@t0xodile) 's Twitter Profile
Thomas Stacey

@t0xodile

Penetration tester trying to perform novel research. You can find all of my write-ups and research at thomas.stacey.se.

ID: 2634803080

linkhttps://thomas.stacey.se calendar_today23-06-2014 15:42:55

208 Tweet

351 Takipçi

197 Takip Edilen

Adam Langley (@buildhacksecure) 's Twitter Profile Photo

Had great fun making this huge lab. ProjectDiscovery create amazing CLI tools, and in this lab we’ll teach you how to use shuffledns, alterx, dnsx, naabu, httpx, katana and tlsx to supercharge your recon game!

BSides Exeter (@bsidesexeter) 's Twitter Profile Photo

Another successful meeting last night. Details for BSides Exeter 2026 will start to trickle out from Monday 3rd November 2025. Time to recharge that #oooarrcyber.

Another successful meeting last night. Details for BSides Exeter 2026 will start to trickle out from Monday 3rd November 2025.

Time to recharge that #oooarrcyber.
Security Fest (@securityfest) 's Twitter Profile Photo

SecurityFest WWWinter Pub is approaching fast and on Friday the 7th of November we'll be at Rollin Bistros in Gamlestaden, Göteborg! Come join us! Some tickets are still available! securityfest.com/wwwinterpub/

BSides Exeter (@bsidesexeter) 's Twitter Profile Photo

🚀 BSides Exeter 2026 is coming! 💡 Curiosity Built the Cyber Pro 📅 24–25 April | 📍 University of Exeter We’re celebrating the spark that drives every cyber mind — from retro roots to future innovation. 🤝 Sponsorships now open: bsidesexeter.co.uk #oooarrcyber

🚀 BSides Exeter 2026 is coming!
💡 Curiosity Built the Cyber Pro
📅 24–25 April | 📍 University of Exeter

We’re celebrating the spark that drives every cyber mind — from retro roots to future innovation.

🤝 Sponsorships now open: bsidesexeter.co.uk

#oooarrcyber
Thomas Stacey (@t0xodile) 's Twitter Profile Photo

We're back! This year we're focusing on all those weird and wonderful moments that led you to your cyber careers. Sponsorships are open so feel free to reach out 🔥

Gareth Heyes \u2028 (@garethheyes) 's Twitter Profile Photo

Firefox nightly introduces the setHTML() method. Which is like a native DOMPurify. You can easily test it here: portswigger-labs.net/mxss/ Set HTMLSanitizer ✅ Auto update ✅ I'm trying to break it, I encourage you to break it too

OWASP Göteborg (@owaspgbg) 's Twitter Profile Photo

Join OWASP Göteborg for an Evening of Cybersecurity Stories from the Field! Where: Zacco Digital Trust, 5th floor – Theres Svenssons gata 13, 417 55 Göteborg When: Wednesday, November 20, 2025, 17:00 – 21:00 meetup.com/owasp-gothenbu…

BSides Exeter (@bsidesexeter) 's Twitter Profile Photo

We have just seen the first shirt design draft - this might be the best yet! We just need sponsors for it now. sponsorship.bsidesexeter.co.uk Time for more #oooarrcyber

We have just seen the first shirt design draft - this might be the best yet! We just need sponsors for it now. sponsorship.bsidesexeter.co.uk

Time for more #oooarrcyber
Praetorian (@praetorianlabs) 's Twitter Profile Photo

Praetorian engineer Siddhant Kalgutkar uncovered CVE-2025-55315, a critical hubs.ly/Q03SbmTF0 vulnerability that earned a $10K bounty and prompted a major security fix from Microsoft. A powerful example of the skill, curiosity, and depth that define offensive engineering at

Praetorian engineer Siddhant Kalgutkar uncovered CVE-2025-55315, a critical hubs.ly/Q03SbmTF0 vulnerability that earned a $10K bounty and prompted a major security fix from Microsoft.
A powerful example of the skill, curiosity, and depth that define offensive engineering at
Clint Gibler (@clintgibler) 's Twitter Profile Photo

🛠️ 𝐌𝐞𝐭𝐢𝐬 -- an open-source 𝐀𝐈-𝐩𝐨𝐰𝐞𝐫𝐞𝐝 𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐜𝐨𝐝𝐞 𝐫𝐞𝐯𝐢𝐞𝐰 𝐭𝐨𝐨𝐥 by Arm's Product Security team to detect subtle vulnerabilities, improve secure coding practices, and reduce review fatigue.

Thomas Stacey (@t0xodile) 's Twitter Profile Photo

Already had some success with this completely accidentally (as always). I would highly recommend building yourself a quick reusable turbo intruder script to perform your normal recon and fuzzing at the start of your testing. I can imagine you'll find far more leads this way!

Web Security Academy (@websecacademy) 's Twitter Profile Photo

If you're hacking web apps in 2025 - you absolutely need to know about CORS. CORS is a browser security mechanism that allows a web page from one domain to safely request and receive resources from another domain, which is normally forbidden by default by the same-origin policy.

If you're hacking web apps in 2025 - you absolutely need to know about CORS.

CORS is a browser security mechanism that allows a web page from one domain to safely request and receive resources from another domain, which is normally forbidden by default by the same-origin policy.
James Kettle (@albinowax) 's Twitter Profile Photo

Want to experiment with Anomaly Rank on arbitrary requests anywhere inside Burp Suite? Nick Coblentz made an extension for that! Try it out here: github.com/ncoblentz/Burp…

Burp Suite (@burp_suite) 's Twitter Profile Photo

"Burp AI can bring up a new generation of hackers faster and more effectively.​​​​​​" In his new article, hAPI_hacker explores how Burp AI: 🔬 Analyzes requests and adapts when attacks fail. 💬 Explains findings in clear language. 💪 Enhances human decision-making. 👉

Gareth Heyes \u2028 (@garethheyes) 's Twitter Profile Photo

HackFriday starts now JavaScript for Hackers is on sale for $13.37 and the deal runs past Hack Friday Boost your payload skills and sharpen your hacking game Grab it while it lasts 🔥 amazon.com/JavaScript-hac…