With @OSTIFofficial and @sovtechagency we audited @symfony YAML, the library bundled in that PHP framework that all your friends probably run somewhere in their stack. If that's true, please update and read the attached blogpost to find out if you're affected!
Links β¬
InfoSec boutique.
Owning things since 2014.
We love to go for the extra mile, where we usually find the best π¦ππͺ²πͺ³πππ· the others miss.
- Can a hostile container sneak past your eBPF tracing? Sometimes, yes. With @OSTIFofficial & @CloudNativeFdn we audited Inspektor Gadget - 3 vulns (fixed), 6 hardenings, 6 bypasses (io_uring, openat2, jumbo framesβ¦). Work by @ndaprela & @suidpitπ π
- #KubeCon EU starts today and guess what? Our very own @suidpit will be on stage with a panel about the @kubernetesio Security Audit we performed during 2025 with the support of @OSTIFofficial! ποΈ March 25 - 16:45 CET π Hall 8 | Room F
- Attending @1ns0mn1h4ck? Meet @not4nhacker @Luk3ros and @Sev1rus from our AppSec and Red teams! They are eager to discuss about breaking complex authentication implementations and relaying all the things to DA!

