Exploit Explained Using an LLM to Exploit a Novel HTTP Interface
A Synack Red Team member discovered a cross-site scripting vulnerability in SAP Concur Open.
Synack unites the power of human expertise and AI technology to deliver continuous, trusted security testing at scale.
Synack combines agentic AI and human expertise to deliver pentesting solutions at scale.
Synack unites the power of human expertise and AI-driven technology to deliver continuous, trusted security testing at scale.
Synack unites the power of human expertise and AI-driven technology to deliver continuous, trusted security testing at scale.
Meet the experts who power Synack’s strategic security testing platform. Our Synack Red Team unites over 1,500 of the world’s most skilled and trusted security researchers, who work with patented technology to deliver best-in-class offensive security testing on a continuous basis.
Synack combines agentic AI and human expertise to deliver pentesting solutions at scale.
Explore educational guides and practical answers about penetration testing, AI security and vulnerability validation.
Browse all of our resources including videos, case studies, articles, podcasts and more.
Stay up to date on the latest industry trends, company news and research.
Hear from newsmakers, hackers, and big thinkers around the world share their cybersecurity insights.
A video series with candid perspectives on cybersecurity topics that matter.
Cut to the Chase. A live demo series that gets the point without wasting your time.
A series featuring technical vulnerability insights from the elite security researchers on the Synack Red Team (SRT).
Learn about cybersecurity industry terms and security testing solutions—what they do, why they’re important, and how they work.
Compare Synack side by side with other security testing platforms and vendors.
Join us for any in-person event, upcoming conference, or an online webinar.
Home > Archives by Nicolas Krassas
Nicolas Krassas is a security researcher on the Synack Red Team and a Guardian of Trust inductee on the Synack Acropolis. Known online as dinosn, he specializes in remote code execution research, including work exploiting Java RMI via MBeans and breaking down Java JMX exploitation paths for Synack's Exploits Explained series. He has also documented the risks of open internet-facing proxy servers and has spoken on SRT panels at RSA Conference. Learn more: https://acropolis.synack.com/inductees/nicolas