What started as a team of 5 high school students in 2018, is now a top 10 international team with members from all over the world.
1st place: 8 CTFs
Single-digit place: 18 CTFs
Attended on-site finals: 10
Organized CTFs: 3
Wishing you all a Happy and Blessed 2024!
@Cloudflare built Vinext ( vinext.io/ ) for $1,100. AISafe Labs audited it for $200. Cloudflare paid AISafe Labs a bounty worth $4,600.
Welcome to the new economics of AI-written code.
More details on the blog post page: aisafe.io/blog/cloudflare-vi…#bugbounty
I'll never forget the indescribable joy of capturing my first flag and will cherish for life the brotherhood, the memories and adventures that CTFs gave me. Still surreal that after 8 consecutive years of playing DefCon CTF, I sat out this time. #PwnThyBytes#WreckItRalph@WreckTheLine#Zer0RocketWrecks
🚨BREAKING: AISafe Labs discovered Remote Code Execution on @langfuse with a single OTel trace request.
The flaw in the OpenTelemetry dotted-attribute expansion allowed unauthorized access to LLM traces belonging to other projects and system compromise via prototype pollution💣
AISafe Labs found a 🔥 Stored XSS in Immich's 360° panorama viewer (CVE-2026-35455) 🔥
Any user can upload a panorama with text in it. OCR reads the text, then the viewer renders that text as raw HTML. Attacker JS runs against any victim who views the photo.
More details 👇🧵
We rebuilt Next.js in a week. No, really.
The team ported the framework to run natively on Workers to prove what’s possible with edge-first architecture. Dive into the technical hurdles we solved to eliminate Node.js dependencies.
cfl.re/4ciNc3L
As the official launch of AISafe draws near, we’re excited to select up to 4 projects for a free Code Audit 🚀
If you're interested, join the waitlist and drop us an email at contact@aisafe.io with your project.
For more information, visit aisafe.io 👈
We teamed up with @WreckTheLine & @redrocket_ctf and secured 🥇1st place at @LakeCtf! Huge thanks to @polygl0ts for putting together an awesome CTF - it was an incredible experience!🇨🇭🔥
I'm releasing fontleak: a new CSS injection technique to quickly exfiltrate text nodes (and yes, that includes inline scripts).
Works on Chrome/Firefox and Safari*. You can use it to escalate the impact of your HTML injection payloads and to solve CTF challenges.
We’re tossing an extra $10k into the prize pool if this tweet gets 100 retweets or we hit 1k teams signed up for The Remedy CTF.
This could be the biggest web3 CTF yet (Jan. 24–26). Let’s make it real—just hit that retweet button 🔁
Register your team here: ctf.r.xyz?utm_source=Twitter…
LakeCTF qualifications are now over!
🥇 @smiley_ctf
🥈 @WreckTheLine
🥉 @dicegangctf
Congratulations to the winners, see you in Lausanne for the finals! 📷
ALT Place User Score
1 .;,;. Academic 5133
2 Zer0RocketWrecks Academic 5101
3 DiceGang Non-academic 4918
4 The Flat Network Society Non-academic 4334
5 FluxFingers Academic 4279