#NahamCon2022EU: Hunting for Amazon Cognito Security Misconfigurations by@yassineaboukir

#NahamCon2022EU is a virtual offensive security. This year's event was hosted by Farah Hawa & InsidePhD! Thank you to our sponsors for making this conference happen! Halborn - halborn.com Project Circuit Breaker - projectcircuitbreaker.com Android - google.com HackTheBox - hackthebox.eu HackenProof - hackenproof.com Intigriti - intigriti.com Snyk - snyk.io Offensive Security - offensive-security.com YesWeHack - yeswehack.com Immunefi - immunefi.com NetworkChuck - networkchuck.com Bugcrowd - bugcrowd.com Project Discovery - ProjectDiscovery.io Detectify - Detectify.com HackerContent - hackercontent.com PentesterLab - Pentesterlab.com No Starch Press - nostarch.com Ethiack - ethiack.com Purchase my Bug Bounty Course here 👉🏼 bugbounty.nahamsec.training Yassine Aboukir is a proficient bug bounty hunter, MVH winner and a security consultant specialized in application security. Yassine is an aspiring athlete who enjoys running, lifting weights and trekking/hiking mountains. He has been traveling the world as a digital nomad for 5 years now and enjoys meeting and connecting with like-minded people. Free $100 DigitalOcean Credit: https://m.do.co/c/3236319b9d0b Follow me on social media:   / nahamsec     / nahamsec   https://twitch.com/nahamsec https://hackerone.com/nahamsec   / nahamsec1  

#NahamCon2022EU: I Hope This Sticks: Analyzing ClipboardEvent Listeners for XSS by spaceraccoon
▶︎

#NahamCon2022EU: I Hope This Sticks: Analyzing ClipboardEvent Listeners for XSS by spaceraccoon

#NahamCon2022 - @codingo: Recon Fundamentals by Example
▶︎

#NahamCon2022 - @codingo: Recon Fundamentals by Example

DEF CON 31 -  Smashing the State Machine the True Potential of Web Race Conditions - James Kettle
▶︎

DEF CON 31 - Smashing the State Machine the True Potential of Web Race Conditions - James Kettle

Demystifying Bug Bounties: Insights from a Decade of Experience - Yassine Aboukir
▶︎

Demystifying Bug Bounties: Insights from a Decade of Experience - Yassine Aboukir

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed
▶︎

OWASP's Top 10 Ways to Attack LLMs: AI Vulnerabilities Exposed

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

NahamCon2022 - seanyeoh & devec0: Continuous Intrusion: Hacking CI Systems
▶︎

NahamCon2022 - seanyeoh & devec0: Continuous Intrusion: Hacking CI Systems

Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)
▶︎

Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)

Building an AI Dark Factory:  A Codebase That Writes Its Own Code, Live
▶︎

Building an AI Dark Factory: A Codebase That Writes Its Own Code, Live

Practical Web Cache Poisoning: Redefining 'Unexploitable'
▶︎

Practical Web Cache Poisoning: Redefining 'Unexploitable'

#NahamCon2024: Modern WAF Bypass Techniques on Large Attack Surfaces
▶︎

#NahamCon2024: Modern WAF Bypass Techniques on Large Attack Surfaces

God Says:"TAKE THIS MESSAGE SERIOUSLY, BECAUSE ONLY YOU ARE SEEING IT"/God Message Now/God Message
▶︎

God Says:"TAKE THIS MESSAGE SERIOUSLY, BECAUSE ONLY YOU ARE SEEING IT"/God Message Now/God Message

Reverse Proxy vs Load Balancer vs API Gateway: The Real Difference ?
▶︎

Reverse Proxy vs Load Balancer vs API Gateway: The Real Difference ?

#NahamCon2022EU: Story of an RCE on Apple Through Hot Jar Swapping by Frans Rosen
▶︎

#NahamCon2022EU: Story of an RCE on Apple Through Hot Jar Swapping by Frans Rosen

Cybersecurity Architecture: Who Are You? Identity and Access Management
▶︎

Cybersecurity Architecture: Who Are You? Identity and Access Management

k20 - Attacking Secondary Contexts in Web Applications - Sam Curry
▶︎

k20 - Attacking Secondary Contexts in Web Applications - Sam Curry

researcher accidentally finds 0-day affecting his entire internet service provider
▶︎

researcher accidentally finds 0-day affecting his entire internet service provider

Passkeys Explained: Are They Actually Better Than Passwords?
▶︎

Passkeys Explained: Are They Actually Better Than Passwords?

Advanced Phishing with AI & the Last Mile Reassembly Attacks | Bypass Secure Web Gateways
▶︎

Advanced Phishing with AI & the Last Mile Reassembly Attacks | Bypass Secure Web Gateways

New methods of recon with OrwaGodfather
▶︎

New methods of recon with OrwaGodfather