Carlos Holguera
grepharder.bsky.social
Carlos Holguera
@grepharder.bsky.social
Project Leader at @owasp for the OWASP Mobile App Security (MAS) flagship project.

https://mas.owasp.org


#mobilesecurity #grep #frida #radare2 #goodcoffee #reverseengineering
We've been waiting 5 years for this: objection has been updated to 1.12.x with Frida17+ support. Thank you so much @leonjza.bsky.social and everyone who contributed!

github.com/sensepost/ob...

Thanks to @ipmegladon.bsky.social for updating the MASTG accordingly (OWASP/mastg/pull/3378)
Release 1.12.0 · sensepost/objection
The, wow, finally, a release release! 😂 Honestly, there has been so much that has changed, and it's hard to thank and attribute to everyone that has contributed. To that end, thank you for your con...
github.com
November 21, 2025 at 12:30 PM
@ipmegladon.bsky.social hey, what's your name on LinkedIn? I'm thanking you in a post but couldn't find you
November 21, 2025 at 12:25 PM
Reposted by Carlos Holguera
🚨Friendly reminder: The #CFP for #r2con2025 is still OPEN! There's plenty of time before October 24th, but if you want to talk about anything related to #radare2, please submit your talk ASAP! ✨ Let’s make this edition even better! 🚀 #infosec

👉 radare.org/con/2025/
radare.org
June 28, 2025 at 8:07 AM
Reposted by Carlos Holguera
🥇 Today we welcome our second MAS Advocate, @guardsquare.bsky.social who has consistently made high-impact contributions to the project, reviewed complex PRs, and made a tremendous impact during the past OWASP Project Summit. We hope that others will follow!

mas.owasp.org/news/2025/05...
Guardsquare Achieves MAS Advocate Status - OWASP Mobile Application Security
mas.owasp.org
May 23, 2025 at 11:46 AM
Reposted by Carlos Holguera
🚨 OWASP Global AppSec EU 2025 in Barcelona May 27–31!

For builders, breakers, defenders, leaders, and all others who want to engage with the best minds in AppSec.

🔗 owasp.glueup.com/eve...

#OWASP #AppSecEU2025 #Cybersecurity #AppSec #DevSecOps #AI #LLMSecurity #Hacking #InfoSec #Barcelona
May 21, 2025 at 7:04 AM
Reposted by Carlos Holguera
Last weekend I did some improvements for Decai

- load custom decompiler pipelines from external json
- deterministic mode for ollama, openai and claude
- add mistral endpoint.
- implement a vector database for embeddings from scratch in C with 0 deps

#radare2 #r2ai
February 11, 2025 at 8:40 AM
Reposted by Carlos Holguera
Comparing Decai decompilation using @anthropic.com 's Claude 3.5 vs 3.7 with a simple strcoll wrapper function #r2ai #radare2
February 25, 2025 at 12:35 PM
Reposted by Carlos Holguera
The new asm.lines.split creates a secondary column in the disassembly view for the backward branch lines making it easier to spot loops and understand the control flow #reverseengineering #disassembly #cli #tui
March 15, 2025 at 12:04 AM
Reposted by Carlos Holguera
How to pass the OWASP MASVS verification by design?

In Admincontrol, our Android app and IOS app passed the @owasp.org MASVS verification by deciding security requirements and -controls using a game. Here is how...https://dev.to/owasp/how-to-pass-the-owasp-masvs-verification-by-design-2cf9 #appsec
February 14, 2025 at 8:35 AM