Log inSign up
Auditware
860 posts
Auditware profile banner
@audit_wizard

Auditware

@audit_wizard
Industry leading OpSec audits, security tools, and code reviews performed by true security wizards
auditware.io
Joined August 2022
548
Following
2,752
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @audit_wizard
    Auditware
    @audit_wizard
    Aug 20
    Web3 founders, the Cloud Security Grant is open for applications 🚨 Here's what it is: A cloud review teams normally pay for, run by us, given to a handful who do real work for web3. We want to help because we keep seeing the same thing happen: A protocol ships audited
    Image
    1
  • @audit_wizard
    Auditware
    @audit_wizard
    Sep 1
    We ran Delve through a security check and it pulled an F on headers (yes, that Delve) 🫣 Missing security headers barely matter on a blog. On a dapp they decide whether an injected script can quietly rewrite the transaction in your wallet while the page still shows the domain
    Image
    00:00
  • @audit_wizard
    Auditware
    @audit_wizard
    Aug 31
    W3OS has added a whole domain for AI agent OpSec, and two of its requirements will annoy people. Allow listing domains does not satisfy session isolation. The untrusted content lives on the domains you already allowed, your agent reads GitHub issues and web pages and both are
    @thedaofund
    thedao.fund
    @thedaofund
    Aug 20
    Less than 4 hours until go time. Today we’re talking OpSec with people who work directly on Ethereum security. Joining us: @isaacpatka from @_SEAL_Org Roman from @Quantstamp @dobsec @hudsonjameson and @arda_certik from @CertiK @joe_vanloon from @audit_wizard @officer_secret
  • @audit_wizard
    Auditware
    @audit_wizard
    Aug 27
    Excluding vercel-hosted, upgrade your Next.js to 16.3.3, and ASAP.
    @forefy
    forefy
    @forefy
    Aug 27
    🚨🚨Next.js 16.3.0 vulnerable to a yet unpatched remote code exec but here's the more interesting part 👇 Agentic attacks are all about token allocations. even if the vuln technical details remain unreleased, just knowing the vulnerable version already set attackers to focus all
  • @audit_wizard
    Auditware
    @audit_wizard
    Aug 26
    This is what happens when you point an AI agent at a K8 Labs challenge (we built the labs to let it in on purpose) 🤖 In short: ✅ the agent gets real access on a temporary, scoped key ✅ it maps the box, reads the primitives, walks itself toward the answer ✅ the API hands out
    Image
@thedaofund
thedao.fund
Host
Come Join Us for TheDAO’s First Ethereum Security Space: Let’s Talk OpSec
176 tuned in
Aug 20
1:06:12
Advertisement
Advertisement