Thomas Stacey (@t0xodile) 's Twitter Profile
Thomas Stacey

@t0xodile

Penetration tester trying to perform novel research. You can find all of my write-ups and research at thomas.stacey.se.

ID: 2634803080

linkhttps://thomas.stacey.se calendar_today23-06-2014 15:42:55

208 Tweet

351 Followers

197 Following

Adam Langley (@buildhacksecure) 's Twitter Profile Photo

Had great fun making this huge lab. ProjectDiscovery create amazing CLI tools, and in this lab weโ€™ll teach you how to use shuffledns, alterx, dnsx, naabu, httpx, katana and tlsx to supercharge your recon game!

BSides Exeter (@bsidesexeter) 's Twitter Profile Photo

Another successful meeting last night. Details for BSides Exeter 2026 will start to trickle out from Monday 3rd November 2025. Time to recharge that #oooarrcyber.

Another successful meeting last night. Details for BSides Exeter 2026 will start to trickle out from Monday 3rd November 2025.

Time to recharge that #oooarrcyber.
Security Fest (@securityfest) 's Twitter Profile Photo

SecurityFest WWWinter Pub is approaching fast and on Friday the 7th of November we'll be at Rollin Bistros in Gamlestaden, Gรถteborg! Come join us! Some tickets are still available! securityfest.com/wwwinterpub/

Thomas Stacey (@t0xodile) 's Twitter Profile Photo

Even more smuggling techniques from the awesome Jeppe Weikop with yet another "oh yeah http1 does that" moment. w4ke.info/2025/10/29/funโ€ฆ

BSides Exeter (@bsidesexeter) 's Twitter Profile Photo

๐Ÿš€ BSides Exeter 2026 is coming! ๐Ÿ’ก Curiosity Built the Cyber Pro ๐Ÿ“… 24โ€“25 April | ๐Ÿ“ University of Exeter Weโ€™re celebrating the spark that drives every cyber mind โ€” from retro roots to future innovation. ๐Ÿค Sponsorships now open: bsidesexeter.co.uk #oooarrcyber

๐Ÿš€ BSides Exeter 2026 is coming!
๐Ÿ’ก Curiosity Built the Cyber Pro
๐Ÿ“… 24โ€“25 April | ๐Ÿ“ University of Exeter

Weโ€™re celebrating the spark that drives every cyber mind โ€” from retro roots to future innovation.

๐Ÿค Sponsorships now open: bsidesexeter.co.uk

#oooarrcyber
Thomas Stacey (@t0xodile) 's Twitter Profile Photo

We're back! This year we're focusing on all those weird and wonderful moments that led you to your cyber careers. Sponsorships are open so feel free to reach out ๐Ÿ”ฅ

Gareth Heyes \u2028 (@garethheyes) 's Twitter Profile Photo

Firefox nightly introduces the setHTML() method. Which is like a native DOMPurify. You can easily test it here: portswigger-labs.net/mxss/ Set HTMLSanitizer โœ… Auto update โœ… I'm trying to break it, I encourage you to break it too

OWASP Gรถteborg (@owaspgbg) 's Twitter Profile Photo

Join OWASP Gรถteborg for an Evening of Cybersecurity Stories from the Field! Where: Zacco Digital Trust, 5th floor โ€“ Theres Svenssons gata 13, 417 55 Gรถteborg When: Wednesday, November 20, 2025, 17:00 โ€“ 21:00 meetup.com/owasp-gothenbuโ€ฆ

BSides Exeter (@bsidesexeter) 's Twitter Profile Photo

We have just seen the first shirt design draft - this might be the best yet! We just need sponsors for it now. sponsorship.bsidesexeter.co.uk Time for more #oooarrcyber

We have just seen the first shirt design draft - this might be the best yet! We just need sponsors for it now. sponsorship.bsidesexeter.co.uk

Time for more #oooarrcyber
Praetorian (@praetorianlabs) 's Twitter Profile Photo

Praetorian engineer Siddhant Kalgutkar uncovered CVE-2025-55315, a critical hubs.ly/Q03SbmTF0 vulnerability that earned a $10K bounty and prompted a major security fix from Microsoft. A powerful example of the skill, curiosity, and depth that define offensive engineering at

Praetorian engineer Siddhant Kalgutkar uncovered CVE-2025-55315, a critical hubs.ly/Q03SbmTF0 vulnerability that earned a $10K bounty and prompted a major security fix from Microsoft.
A powerful example of the skill, curiosity, and depth that define offensive engineering at
Clint Gibler (@clintgibler) 's Twitter Profile Photo

๐Ÿ› ๏ธ ๐Œ๐ž๐ญ๐ข๐ฌ -- an open-source ๐€๐ˆ-๐ฉ๐จ๐ฐ๐ž๐ซ๐ž๐ ๐ฌ๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐œ๐จ๐๐ž ๐ซ๐ž๐ฏ๐ข๐ž๐ฐ ๐ญ๐จ๐จ๐ฅ by Arm's Product Security team to detect subtle vulnerabilities, improve secure coding practices, and reduce review fatigue.

Thomas Stacey (@t0xodile) 's Twitter Profile Photo

Already had some success with this completely accidentally (as always). I would highly recommend building yourself a quick reusable turbo intruder script to perform your normal recon and fuzzing at the start of your testing. I can imagine you'll find far more leads this way!

Web Security Academy (@websecacademy) 's Twitter Profile Photo

If you're hacking web apps in 2025 - you absolutely need to know about CORS. CORS is a browser security mechanism that allows a web page from one domain to safely request and receive resources from another domain, which is normally forbidden by default by the same-origin policy.

If you're hacking web apps in 2025 - you absolutely need to know about CORS.

CORS is a browser security mechanism that allows a web page from one domain to safely request and receive resources from another domain, which is normally forbidden by default by the same-origin policy.
James Kettle (@albinowax) 's Twitter Profile Photo

Want to experiment with Anomaly Rank on arbitrary requests anywhere inside Burp Suite? Nick Coblentz made an extension for that! Try it out here: github.com/ncoblentz/Burpโ€ฆ

Gareth Heyes \u2028 (@garethheyes) 's Twitter Profile Photo

๐Ÿš€ Shadow Repeater just got a big upgrade! It now detects response timing differences. thespanner.co.uk/shadow-repeateโ€ฆ

Burp Suite (@burp_suite) 's Twitter Profile Photo

"Burp AI can bring up a new generation of hackers faster and more effectively.โ€‹โ€‹โ€‹โ€‹โ€‹โ€‹" In his new article, hAPI_hacker explores how Burp AI: ๐Ÿ”ฌ Analyzes requests and adapts when attacks fail. ๐Ÿ’ฌ Explains findings in clear language. ๐Ÿ’ช Enhances human decision-making. ๐Ÿ‘‰

Gareth Heyes \u2028 (@garethheyes) 's Twitter Profile Photo

HackFriday starts now JavaScript for Hackers is on sale for $13.37 and the deal runs past Hack Friday Boost your payload skills and sharpen your hacking game Grab it while it lasts ๐Ÿ”ฅ amazon.com/JavaScript-hacโ€ฆ