@SynackRedTeam

The power behind the @Synack platform is an elite team of the world's top cybersecurity researchers. Our best are honored at https://nitter.cf/t.co/6bEAyp7HWJ

Redwood City, CA
Joined May 2014
SRT researcher @mcipekci on why AI will not replace humans:
1
2
12
1,577
Synack Red Team researcher Mạnh Nguyen Dinh pointed an AI coding agent at a car's CAN bus. See what it found in our latest Exploits Explained: hubs.ly/Q04y3R160
1
1
13
1,657
“I had three SQLis I submitted two days ago; they got triaged yesterday." ⚡️ - SRT researcher Austin on the advantages of hacking with @synack compared to other platforms. Interested in joining the Synack Red Team? Visit our website to learn more: synack.com/red-team
1
5
1,766
Meet our 2026 Synack Red Team Heroes! 🏆🏆🏆🏆 (Part 4 of 4) The Hero Award honors our researchers who generate significant value and impact for our customers. See all 2026 Acropolis winners: acropolis.synack.com/?utm_ca… #Acropolis2026 #CyberSecurity #EthicalHacking #Pentesting
1
4
1,852
Synack Red Team retweeted
Thanks @SynackRedTeam and The Datatech Times! Glad to be able to share some more about this research.
Nice writeup from The Datatech Times on @malcolmst and his NatJack research. Stagg first discovered that NAT table entries could be corrupted or replaced while on assignment for the Synack Red Team. In his own words: “For a lot of business and enterprise customers, I would say the TCP and HTTP session hijacking techniques are the most dangerous, since a lot of internal network traffic is still unencrypted, and untrusted/trusted workloads often share the same NAT." Worth the read if you want the story behind the NatJack research: hubs.ly/Q04x8SM70
1
3
396
Nice writeup from The Datatech Times on @malcolmst and his NatJack research. Stagg first discovered that NAT table entries could be corrupted or replaced while on assignment for the Synack Red Team. In his own words: “For a lot of business and enterprise customers, I would say the TCP and HTTP session hijacking techniques are the most dangerous, since a lot of internal network traffic is still unencrypted, and untrusted/trusted workloads often share the same NAT." Worth the read if you want the story behind the NatJack research: hubs.ly/Q04x8SM70
1
1
8
1,896
An AI chatbot flagged every injection attempt it recognized. The one that got through wasn't recognized as an attempt at all. SRT researcher @N0_M3ga_Hacks realized it was filtering by intent, not syntax. Wrapping the real payload inside a benign, expected-looking request slipped past the filter and returned database schema details in markdown. Parth broke down the discovery, the bypass, and what it means for AI guardrail design in this week's Exploits Explained: hubs.ly/Q04x4V4d0 #ExploitsExplained #AIsecurity #OffensiveSecurity #SynackRedTeam
6
49
3,216
Synack Red Team retweeted
I have not posted here in a long time. This seemed worth logging back in for. This week @NetSPI and @Synack signed a definitive agreement to merge, backed by @KKR_Co. Together we are creating the largest expert-led offensive security platform in the world. Nearly 40 years of operating history and more than 13 million hours of real-world offensive testing, with agentic AI underneath all of it. There are far too many people to name here, so: every Synacker past and present, the investors who backed two guys out of the NSA in 2013 on an idea that sounded strange at the time, and the partners, advisors and customers who took our calls and told us the things we did not want to hear. The people who moved on built the floor the rest of us are standing on. This outcome is yours as much as anyone's. To the @SynackRedTeam especially. You are the reason the thesis was right in the first place. If I believed autonomous tooling could replace expert judgment, then merging two of the largest concentrations of it in this industry would be a spectacular waste of capital. This deal is an argument for your value, not against it. And I am looking forward to working alongside @Aaron_Shilts and the NetSPI team as much as anything else about this. Respected them from across the field for years. Glad to finally be on the same side of it. Briefly on why we did it this way, because it is not the obvious bet. The industry is spending hundreds of millions of dollars to take humans out of offensive security. "No humans in the loop." "Requires no human input." We just built the opposite. Every benchmark in this argument measures what agents found. Not one measures what they walked past. A false positive costs an engineer an afternoon. A false negative is the breach, and it is invisible by construction. The best autonomous agent yet tested beat nine of ten professional pentesters on a live network, out-submitted every one of them on false positives, and reached the finding that mattered only after researchers handed it hints. It was not outmatched. It was undiscerning. Autonomy was never the goal. It is a means. The goal is knowing which of ten thousand findings gets used against you, and knowing what nobody looked at. Day one of the next chapter. Thank you for building the last one with me. Full thesis: synack.com/blog/autonomy-was…
1
4
17
1,320
SRT researcher @ozgur_bbh hit four dead ends on an Oracle backend. Then he found the exploit hiding inside a reporting function. Standard boolean tests, time-based payloads, UNION injection and out-of-band callbacks all failed. The lever that worked: Oracle's DECODE function converts its return value to match the data type of its first result, and a mismatched default branch turns that into a type-conversion error researchers can read as a true/false signal. This is part four of Ozgur's series on blind SQL injection, following posts on MSSQL, MySQL and PostgreSQL, each with a completely different exploitation gadget. hubs.ly/Q04whTLy0 #ExploitsExplained #SQLi #SQLinjection #EthicalHacking
8
36
2,805
Meet our 2026 SRT Heroes! 🏆🏆🏆 (Part 3 of 4) See all Acropolis inductees here: acropolis.synack.com/?utm_ca… #Acropolis2026 #CyberSecurity #EthicalHacking #Pentesting #SynackRedTeam
18
2,097
Everyone tests the email field for formatting. Almost no one tests it for XSS. That blind spot let Synack Red Team researcher Salman Khan turn a routine account settings field into a full attack chain. The email spec allows a "+" for subaddress tagging, and Salman used that trick to slip an XSS payload past validation and store it, unencoded, in his own profile. Then he sent a clean, normal looking invitation to a test account, no payload in the email itself, no login required to open it. The page rendered his poisoned profile the moment it loaded, and the exploit fired on mouseover. Three separate layers of validation missed it. Read how: hubs.ly/Q04vywJb0 #ExploitsExplained #PenTesting #XSS #SynackRedTeam
3
8
1
76
4,903
Congrats to our 2026 SRT Heroes! 🏆🏆 (Part 2 of 4) The Hero designation is awarded annually to SRT members who generate significant value through exceptional production and customer impact. See all Acropolis winners: acropolis.synack.com/?utm_ca… #Acropolis2026 #cybersecurity #ethicalhacking #pentesting #SynackRedTeam
1
17
2,070
Synack Red Team retweeted
Grateful doesn't even cover it. 🙌 Recognition from @SynackRedTeam and @Synack means a lot, this community keeps pushing me to level up every single mission. Onward to the next target 🎯 #SynackRedTeam #CyberSecurity #BugBounty #InfoSec #EthicalHacking #SecurityResearch #SRT
Congrats to our 2026 Acropolis Heroes! 🏆 (Part 1 of 4) Check out the full list of winners here: hubs.ly/Q04skD5V0 #SynackRedTeam #Acropolis2026 #EthicalHacking
2
4
972
Congrats to our 2026 Acropolis Heroes! 🏆 (Part 1 of 4) Check out the full list of winners here: hubs.ly/Q04skD5V0 #SynackRedTeam #Acropolis2026 #EthicalHacking
1
1
19
2,973
A Domain Admin didn't click a phishing link. They just opened a meeting invite, and that was enough to hand over their domain account. SRT researcher Metin Yunus Kandemir found how a stored HTML injection on an internal web app, paired with a DNS trick that lands an attacker's server in Windows' "Local Intranet" zone, triggers automatic NTLM authentication with zero user input. Metin Yunus breaks down the full attack path, proof of concept and fixes in his Exploits Explained Blog: hubs.ly/Q04tF1sB0 #ExploitsExplained #ActiveDirectory #NTLMRelay #OffensiveSecurity #SynackRedTeam
6
38
2,644
Unauthenticated root, from the network, on an appliance that terminates an organization's voice and conferencing traffic. Synack Red Teamer @mcipekci found that Mitel MiCollab was extracting the Common Name from an attacker-supplied TLS certificate and running it as a shell command, even though the certificate itself was ultimately rejected as invalid. CVSS 10.0, off two SOAP requests with nothing malicious-looking in either one. The takeaway: anything that exists to establish trust, a certificate, a JWT, a SAML assertion, is not itself trusted input until it's been verified. Full technical breakdown in Exploits Explained: hubs.ly/Q04tt3DV0
11
1
59
10,454
Synack Red Team retweeted
Won this badass Lego set at the @SynackRedTeam (@synack ) DEFCON SRT event. Thank you for putting this on and all the fun as always
1
8
599
🏅🏅🏅🏅🏅 Congratulations to our 2026 Synack Red Team Olympians: @phyr3wall, SwoleTeamSix, x11, thatchersgold (@carbonmanx), and Yetric! View all Acropolis 2026 winners here: hubs.ly/Q04skD5V0 #Acropolis2026 #SynackRedTeam #Cybersecurity #SRT #EthicalHacking
1
8
2,141
🏅🏅🏅🏅 Congratulations to our Synack Red Team 2026 Olympians: huseyince, moey (@_MohammadJassim), niden, Stev0r, and phurtim! The Olympian designation is awarded each year to recognize SRT members who generate impressive value through outstanding overall production and customer impact.  Check out the full list of Acropolis winners here: hubs.ly/Q04s26h20 #SynackRedTeam #Cybersecurity #SRT #EthicalHacking #Acropolis2026
1
1
15
2,103
Malcolm Stagg, SRT member and independent researcher at SODIUM-24, LLC, will give a talk at Black Hat USA titled "Breaking Trust Boundaries," where he will examine how attackers exploit assumptions embedded in commonly used network designs. Catch the full lineup of Synackers speaking in Las Vegas this week: hubs.ly/Q04rLWZ90
1
1,751