Tanto Security is a leading provider of advanced offensive cyber security services to leading organisations across Australia, New Zealand and North America.
We are beyond giddy to be releasing tturl, the HTTP/2 CLI for finding tiny timing differences and winning request races. Our Director of Research @justinsteven can't wait to tell you all about it at @BSidesCbr today, 3:15PM on the main stage 😎
github.com/tantosec/tturl
The entire Tanto Security team will be at @BSidesCbr this wk. We look forward to catching up with friends and supporting our colleagues who are getting up on stage... and we'll have lots of them! With SEVEN talks. Plus we got swaggggg to give away.
Four years running!
@TantoSecurity has sponsored BSides Canberra every year since 2023 and they contribute some pretty amazing talks along the way.
Thanks for continuing to support BSides both on and off the stage! ❤️
tantosec.com/
🚨 A public Telerik UI PoC chains a padding oracle into unauthenticated RCE.
TantoSec’s exploit for RadAsyncUpload forges encrypted state and loads a DLL, but only on specific non-default configurations.
Inside the chain → thehackernews.com/2026/09/te…
🚨🚨🚨🚨🚨🚨
From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP[.]NET AJAX
tantosec.com/blog/2026/09/te…
The vulnerabilities described in this post were discovered, analysed, and exploited with some AI assistance, and a lot of old-fashioned human persistence.
Our brilliant and talented Sam picked up a 4G industrial router from a second hand store, and as they say in the biz, what he found will shock you.
Check out the blow-by-blow as he wound up logged in to a "fake" root account. Full dets over on the blog: tantosec.com/blog/2026/04/ro…
🔥ℝ𝕖𝕒𝕕𝕪 𝕥𝕠 𝕓𝕣𝕖𝕒𝕜 𝕥𝕙𝕖 𝕤𝕥𝕒𝕔𝕜 𝕒𝕟𝕕 𝕡𝕨𝕟 𝕥𝕙𝕖 𝕙𝕖𝕒𝕡?
Corelan Stack (Feb 3-6) + Heap (Feb 9-12) in Melbourne 🇦🇺 — the ultimate exploit dev combo, back to back 💥
Do both = earn your shot at CCED 😈
Seats 👉 bit.ly/corelan-training
💛 Sharing = caring
Are you going to be in or around Wellington on the 7th-8th November? Are you a student or currently unwaged? TantoSec wants to get you to Kawaiicon❤️
We have tickets to give away. They cover entry to the con only. Travel & accom aren't included. Send us a DM if you can make it😎
Tanto Security ❤️ @DownUnderCTF - and when they asked us if we could do a pentest of their new brand new CTF scoreboard we knew we had to say yes.
With their permission we are proud to release the full pentest report today! 👇
@DownUnderCTF have published their annual infra writeup at downunderctf.com/blog/2025/i… and today's an extra special day, because they're open sourcing their scoreboard, noCTF! 🎉 we think it's pretty dang good (and probably pretty secure)
We think @DownUnderCTF does incredible work, and Tanto Security is proud to have been a sponsor since 2023. Thank you friends for letting us pentest your new scoreboard, and we'll see you for DownUnderCTF 7 in 2026 🫡
🚆🚄🚅🚉🛤️🚃🚂
Training Alert!
We are partnering with @corelanc0d3r to bring his amazing exploit dev workshop to Melbourne for the first time. Want to take your exploit dev to the next level? Check out events.humanitix.com/corelan… Early Bird Discounts if you get in before October 1
A big thank you to Silver sponsor & long-time friend, @TantoSecurity.
They’re back for their third year supporting BSides Canberra and the community, and have also contributed accepted talks to this year’s conference.
More at: tantosec.com
Our Technical Director and co-founder @marcioalm will be at the Melbourne AppSec & DevSecOps Summit next week! He'll be pondering the changing nature of software assurance alongside @jksdua and friends of TantoSec @volvent and @pamoshea
It's blog post day! 🎉 Our email whisperer Ben Wilson has distilled his Outlook email spoofing journey from @BSidesCbr 2024 into a terrific post, walking you through the process of exploring niche email tricks that bypass anti-spoofing controls 👇
He ends up delivering a perfectly spoofed email, indistinguishable from one that would have been sent from within the victim organisation. Some of the tricks have been patched 🥳 some tricks haven't 👀 so grab a cup of tea and get busy reading 😁
tantosec.com/blog/2025/08/mo…