Ahmed Attalla
Dubai, United Arab Emirates
85 followers
86 connections
View mutual connections with Ahmed
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Ahmed
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
I build the systems that turn threat intelligence into detections. At Malcrove I manage…
Activity
85 followers
-
Ahmed Attalla reposted thisAhmed Attalla reposted thisFinally back home after DEF CON 34. This was the third year we run the Bug Bounty Village, DEF CON. I think this was the best BBV so far, bigger and had a huge number of people attending. We had many hackers chilling, playing CTF and solving coins, while some of the best Bug Bounty Hunters were doing talks at the same time. What a great week. Met hundreds if not thousands of people, did a talk in the village about my challenge coins, which BTW this year was the most engaging and had hundreds of people coming to me asking questions about the coin and many many solved it. It makes me really proud that people engaged so much, and people actually spent their DEF CON time solving my coin. We also went to the stage to announce our CTF Winners, first time we have the chance to do this. Kudos to DEF CON for improving that process so all official contests can recognize the CTF creators and winners. We also had an amazing badge that was connected to our challenge coins and CTFs, this is something that allows people to actually crack ciphers, learn about challenges, and sign up in the CTF to start playing. Many are afraid of even trying because they believe is out of their league. Well, is not. We have challenges of all different complexities. I'm inmensely proud of what we have achieved with Harley Kimball, but make no mistakes. This is a work of dozens of people. Thanks to all our volunteers for investing their time, traveling around the world, and making this a possibility. We love you all! Last but not least, massive thanks to all of our sponsors, because we couldn't run the village without their massive support. Special mention to my employer XBOW for not only sponsoring our CTF (created by CTF.ae) but also letting me, attend DEF CON and dedicate all the time to run the Bug Bounty Village. I'm proud to work (and have worked) in companies that invest and care about the Hacker Community as I do. If you haven't, please follow the Bug Bounty village in socials, and join the newsletter so you can see all the talks and content we are working on for you all. https://lnkd.in/d3zKMfWt https://lnkd.in/du9k9t-M x.com/BugBountyDEFCON https://lnkd.in/dNkMQC7z https://lnkd.in/dd8Pwrbj bugbountydefcon.com/mail See you next year!
-
Ahmed Attalla reposted thisAhmed Attalla reposted thisSAGE 11.5.0 is imminent (we're at 11.4.11 atm) and with it brings the complete federation (aka sovereign aspect of the (S) in SAGE) ... What does that mean in plain English? You can have your AI agents communicate with your colleague's AI agent via a secure, distributed, message layer. Just say send this to "Bob's agent's inbox" and all Bob has to do is tell his agent, "check your SAGE inbox; Alice just sent us an update about project Vanta" Couple it with Github for file tracking, and you now have a much quicker and more efficient way to hand off tasks between colleagues or even other agents on your network (other machines in your LAN). Spend less time explaining to your agent what the task is about / what you need done; and go have a coffee.... Can't wait for you guys to try it! #sage #governance #consensus #distributed #ai #memory #infrastructure
-
Ahmed Attalla shared thisI've been using this tool internally for weeks and realized it's too powerful to keep to myself. So I open-sourced it. It's an MCP server that gives AI agents full image editing capabilities through Photopea -- a free, browser-based Photoshop alternative. Design posters, edit photos, apply filters and effects, load custom fonts, export to any format. All from natural language in your terminal. The browser opens automatically and you watch it work in real-time. https://lnkd.in/dpTXESHT #MCP #OpenSource #AI #DeveloperToolsGitHub - attalla1/photopea-mcp-server: MCP server for AI-driven image editing with PhotopeaGitHub - attalla1/photopea-mcp-server: MCP server for AI-driven image editing with Photopea
-
Ahmed Attalla reposted thisAhmed Attalla reposted thisيشارك مجلس الأمن السيبراني، على هامش أسبوع أبوظبي المالي، في تمرين سيبراني أُقيم بالتعاون مع CTFAE وأكاديمية أبوظبي العالمي، وذلك لتعزيز الجاهزية ورفع مستوى التنسيق في مواجهة الهجمات السيبرانية المحتملة. ويهدف هذا التمرين إلى اختبار كفاءة الاستجابة، وتحسين قدرات الفرق الفنية. #مجلس_الأمن_السيبراني During Abu Dhabi Finance Week, the Cyber Security Council took part in a cyber drill organised in collaboration with CTFAE and ADGM Academy, aimed at strengthening cyber readiness and enhancing coordination in response to potential cyber threats. The drill focused on testing incident response capabilities and further developing technical teams' skills. #CyberSecurityCouncil
-
Ahmed Attalla shared thisJoin me at IDEX and NAVDEX the most important tri-service defence exhibition in the world. From 17 - 21 February in ADNEC Centre, Abu Dhabi click here to register. https://lnkd.in/dZVQV3Pu
-
Ahmed Attalla reposted thisAhmed Attalla reposted thisCTF.ae, in partnership with the UAE Cyber Security Council, is thrilled to announce the GITEX GLOBAL CTF, a 2-day onsite Capture the Flag competition during GITEX GLOBAL 2024, on October 14-15. This exciting event is open to UAE residents of all nationalities, offering a unique challenge across various cybersecurity domains. The seats are limited (50 seats only)! Register Now: https://gitex.ctf.ae/ GITEX GLOBAL Largest Tech & Startup Show in the World
-
Ahmed Attalla reposted thisHH Sheikh Hamdan Bin Mohammed Bin Rashid Al Maktoum
HH Sheikh Hamdan Bin Mohammed Bin Rashid Al Maktoum
2yAhmed Attalla reposted thisWe congratulate Dr. Bushra Al Balushi, Director of Governance and Risk Management at the Dubai Electronic Security Center, for winning the ISC2 CEO Award from the International Information Systems Security Certification Consortium (ISC2). The first Arab woman to win this prestigious award, her achievement is yet another recognition of Emirati talent globally. We also congratulate Dr. Mohammed Hamad Al-Kuwaiti, Chairman of the UAE Cybersecurity Council for winning the ISC2 Lifetime Achievement Award. Innovation, leadership, and inspiration are core values embedded in the Emirati identity. These ideals are exemplified by outstanding role models and ambitious youth who continuously strive for excellence, embodying the vision of our leaders and the progressive path of our nation. -
Ahmed Attalla reposted thisAttack a live Azure environment, replicate APTs, & secure it back in this 3-day training with Tarek N. & myself. Learn to misconfigure and abuse, then monitor, detect, & defend. Happening August 26-28 in Bangkok. Register now! https://lnkd.in/d8tEi36Y #AzureSecurity #CloudSecurity #Cybersecurity #HITBSecConf #HITBSecTrain #InfoSec
-
Ahmed Attalla shared thisAhmed Attalla shared thisWe are thrilled to unveil that CTF.ae has been appointed as the official CTF partner of GISEC Global! This exciting collaboration signifies a strategic initiative aimed at fostering a vibrant cybersecurity community and nurturing local talent. Stay tuned for a series of upcoming events geared towards empowering and expanding our cybersecurity ecosystem. Be sure to visit us at GISEC, booth SP7, to explore how CTF.ae is revolutionizing cybersecurity education and engagement.
-
Ahmed Attalla reacted on thisAhmed Attalla reacted on thisEnding our time at the CrowdStrike Partner Summit on the ultimate high note! We are incredibly honored to share that Malcrove has been named one of the region’s Rising Stars at this year’s summit! While taking home an award is a proud moment, this recognition belongs entirely to the brilliant minds in our SOC and SecDevOps teams. They haven't just deployed the CrowdStrike Falcon platform they’ve mastered it. By squeezing every ounce of power out of CrowdStrike’s ecosystem, our engineering and operations teams have redefined what modern, automated threat defense looks like for our clients across the region. What drove this recognition: SecDevOps Innovation: Seamlessly embedding CrowdStrike’s capabilities into automated workflows and continuous delivery pipelines. SOC Operational Excellence: Moving beyond standard monitoring to run high-speed, proactive threat hunting powered by CrowdStrike's full technology stack. Maximizing Platform Value: Ensuring our clients don't just use security tools, but achieve complete, scalable cyber resilience. A massive thank you to the CrowdStrike team for this honor and for continuing to empower partners like us to push technical boundaries. And to our incredible SOC and SecDevOps teams at Malcrove—this trophy is a direct reflection of your hard work, expertise, and dedication. #Malcrove #CrowdStrike #PartnerSummit #RisingStar #Cybersecurity #SOC #SecDevOps #CloudSecurity #Dubai #TechExcellence
-
Ahmed Attalla reacted on thisAhmed Attalla reacted on thisFinally back home after DEF CON 34. This was the third year we run the Bug Bounty Village, DEF CON. I think this was the best BBV so far, bigger and had a huge number of people attending. We had many hackers chilling, playing CTF and solving coins, while some of the best Bug Bounty Hunters were doing talks at the same time. What a great week. Met hundreds if not thousands of people, did a talk in the village about my challenge coins, which BTW this year was the most engaging and had hundreds of people coming to me asking questions about the coin and many many solved it. It makes me really proud that people engaged so much, and people actually spent their DEF CON time solving my coin. We also went to the stage to announce our CTF Winners, first time we have the chance to do this. Kudos to DEF CON for improving that process so all official contests can recognize the CTF creators and winners. We also had an amazing badge that was connected to our challenge coins and CTFs, this is something that allows people to actually crack ciphers, learn about challenges, and sign up in the CTF to start playing. Many are afraid of even trying because they believe is out of their league. Well, is not. We have challenges of all different complexities. I'm inmensely proud of what we have achieved with Harley Kimball, but make no mistakes. This is a work of dozens of people. Thanks to all our volunteers for investing their time, traveling around the world, and making this a possibility. We love you all! Last but not least, massive thanks to all of our sponsors, because we couldn't run the village without their massive support. Special mention to my employer XBOW for not only sponsoring our CTF (created by CTF.ae) but also letting me, attend DEF CON and dedicate all the time to run the Bug Bounty Village. I'm proud to work (and have worked) in companies that invest and care about the Hacker Community as I do. If you haven't, please follow the Bug Bounty village in socials, and join the newsletter so you can see all the talks and content we are working on for you all. https://lnkd.in/d3zKMfWt https://lnkd.in/du9k9t-M x.com/BugBountyDEFCON https://lnkd.in/dNkMQC7z https://lnkd.in/dd8Pwrbj bugbountydefcon.com/mail See you next year!
-
Ahmed Attalla reacted on thisAhmed Attalla reacted on thisSometimes the best research starts with a sudden spike of motivation on a lazy weekend! This one started as weekend tinkering with a desktop app, and noticing a very questionable behavior. It unexpectedly turned into a marathon of reverse engineering, protocol analysis, multiple exploit chains, a confirmed zero-click RCE, nine distinct findings, and, because the vendor directed the submission through YesWeHack instead of the VDP, the “Black Hole” achievement along the way. Technical details remain private for now while the coordinated process continues, but this was a strong reminder that compiled binaries are often where the bodies are buried.
-
Ahmed Attalla reacted on thisAhmed Attalla reacted on thisExcited to welcome Adham Elmosalamy as a speaker at the Bug Bounty Village during DEF CON 34! More on their talk to come. #BugBounty #DEFCON #BBV #BugBountyVillage
-
Ahmed Attalla reacted on thisAhmed Attalla reacted on thisSAGE 11.5.0 is imminent (we're at 11.4.11 atm) and with it brings the complete federation (aka sovereign aspect of the (S) in SAGE) ... What does that mean in plain English? You can have your AI agents communicate with your colleague's AI agent via a secure, distributed, message layer. Just say send this to "Bob's agent's inbox" and all Bob has to do is tell his agent, "check your SAGE inbox; Alice just sent us an update about project Vanta" Couple it with Github for file tracking, and you now have a much quicker and more efficient way to hand off tasks between colleagues or even other agents on your network (other machines in your LAN). Spend less time explaining to your agent what the task is about / what you need done; and go have a coffee.... Can't wait for you guys to try it! #sage #governance #consensus #distributed #ai #memory #infrastructure
-
Ahmed Attalla reacted on thisAhmed Attalla reacted on thisA while back I posted about Mneme, the persistent memory personal project I’ve been working on for AI agents. Same idea as before: a single Rust binary, local-first, that gives agents like Claude Code, Cursor, and OpenCode memory across sessions. Fully offline. Most of v1.1 came from things that annoyed me using earlier versions every day. Installing and wiring up an agent is now one command instead of hand-editing JSON. A daemon mode lets multiple agents share one warm process, so no more cold starts or lockfile fights. And remember pushes back when something tries to store a 10KB blob instead of quietly embedding it. Plenty I haven’t shipped yet — scope isolation across simultaneous agents, Windows daemon support, a few more agent installers. All tracked. Docs: https://lnkd.in/eKBJVYPk GitHub: https://lnkd.in/euPhA-pt If you’ve been trying it, I’d like to hear what’s been getting in your way. ——— #Rust #LocalAI #MCP #OpenSourceMnemeMneme
Licenses & Certifications
Honors & Awards
-
Guinness World Record: Largest CTF Competition (Black Hat MEA 2024)
Guinness World Records
Lead CTF organizer for the Black Hat MEA CTF. Helped deliver the 2024 edition, recognized by Guinness World Records as the largest CTF competition in the world, with players from 150+ countries and 1,000 on-site finalists.
-
Google Vulnerability Disclosure Hall of Fame
Google
Recognized by Google for responsibly disclosing security vulnerabilities through independent bug bounty research.
View Ahmed’s full profile
-
See who you know in common
-
Get introduced
-
Contact Ahmed directly
Other similar profiles
Explore more posts
-
Mazin Ahmed
Chime • 5K followers
I’m super excited to be presenting my latest research at BlackHat MEA this year! VSCode and AI-powered IDEs are going to cause one of the largest breaches soon. It’s time for vendors to take action, and I’ll be sharing my findings this December at BlackHat MEA. Over the past few months, I’ve been researching ways to scale how attackers could compromise developers through VS Code and other AI-powered IDEs (Cursor AI, Windsurf, and AWS Kiro). The research involved finding vulnerabilities that led to bypass Microsoft sandbox scanning, SAST analysis, DAST scanning, and all relevant security controls. The same outcome were shown on OpenVSX, the market is powering Cursor AI, Windsurf, and AWS Kiro. Join me this December in Riyadh for Black Hat MEA.
124
6 Comments -
Wami
8K followers
📔Studying OSINT and Cybersecurity Fundamentals from a Technical and Defensive Perspective📔 Core focus areas: 🔴 Open-Source Intelligence (OSINT) 🔴 Ethical collection and correlation of public data 🔴 Digital footprint and social media exposure awareness 🔴 Windows system fundamentals 🔴 Legal and ethical principles in offensive security Security is not exploitation — it is understanding. Knowledge exists for defense, risk mitigation, and responsible use. 🔐 🔗Comment: "RTFM-OSINT", to get Book in private. #RedTeam #OSINT #OPSEC #CyberSecurity #BlueTeamMindset #EthicalSecurity
42
82 Comments -
Sparta Defend
539 followers
Just exactly 2 weeks ago at Web Summit Qatar, we talked about the very situations we are seeing now with the reported QatarEnergy leak. This huge several-terabyte data loss proves that old-school security (kernel-level) can’t see attackers who move through a system using stolen, "real" login details. A shift toward user-mode security is one of the most effective ways to address these threats-by securing the point where data is actually used. The GCC market doesn't need just another firewall; it needs the major shift in thinking that we showed in Doha.
4
-
CyberP1
111 followers
Middle East Conflict Triggers Surge in Opportunistic Cyber Attacks, Security Researchers Warn News Source : https://lnkd.in/gh8YGNbS Cyber threat actors frequently exploit major geopolitical events to increase the success rate of malicious campaigns. Periods of political tension or conflict generate heightened public interest, information demand, and emotional responses—conditions that attackers leverage to deploy social engineering and malware campaigns.
-
ODM World Wide Meetings and Congress Organizer founded in Sweden 1995 Odysseus Destination Mang. AB
984 followers
The pros and cons in NIST standards for cybersecurity recommendations to 2026 Excellent analysis by constructive criticism to hardening cybersecurity standards against humanity by weaponization of technology and AI Read through here https://zurl.co/ZaObB #Enterprise_administrator_CIO_CISO #cyber_command_USA #CEO #FBI_CIA_US_Government #CIA_NSA_OFAC_Digital_Government_US_congress #US_Senate #Cyber_Security_Community_Weaponization_AI #President #stealer_Logs_Mitre_Attacks_Extortion_Anti_Virus_Applications_EDR_XDR #Patch_Management_IBM_Microsoft_Amazon #Social_Media_Mange_Engine_Zoho_Threat_Deduction #Africa #Asia #SAP_Ariba #Canada #UN_ODC_UN_Global_Compact #US_Treasury_US_Cyber_Security_Executive_Order_EU_US_DATA_Shield_GDPR #Godaddy_AWS_Cloud_Flare_Get_HUB #World_Bank_IMF_global_DATA_Access_Combat_Act #Meta #Interpol #Black_Rock #Swiss_DATA_Protection_Act #UAE #White_House_Cyber_Security_Executive_Orders
5
-
Vyuhnet
455 followers
Weekly GCC Threat Summary: February 13, 2026 Key metrics (as of February 13, 2026): Threat Actors: 110 targeting GCC State-Sponsored APTs: 4 active Campaigns: 18 detected Actor Evolution: 12 groups showing capability changes IOC Velocity: -58% High Severity: 9 actors Most active threat actors: Ember Bear, INC Ransom, Storm-1811, Ajax Security Team, Play Key observations: - Multiple state-sponsored APT groups maintaining regional operations - Significant actor evolution detected across threat landscape - Elevated campaign activity across multiple sectors This intelligence is updated continuously from aggregated threat feeds, CVE correlations, and regional monitoring. --- GCC-Focused Threat Intelligence Platform Request a demo: info@vyuhnet.com
6
-
Vyuhnet
455 followers
Campaign Deep Dive: February 15, 2026 GCC Threat Operations Overview: 20 active campaigns targeting GCC organizations are currently being tracked in real-time across multiple threat actors. Threat Actors in Active Campaigns: - Ember Bear (MEDIUM) - active capability changes - INC Ransom (MEDIUM) - active capability changes - Storm-1811 (MEDIUM) - stable operational pattern - Ajax Security Team (MEDIUM) - active capability changes Campaign Characteristics: - Target Sectors: Finance, Government, Energy, Technology - Attack Vectors: Spear-phishing, Supply chain, Credential theft - Infrastructure: Rotating C2, bulletproof hosting, cloud abuse - Objective: Espionage, data exfiltration, pre-positioning 564 threat-CVE correlations provide attack path visibility for defenders. Understanding campaign operations enables proactive defense rather than reactive incident response. --- | GCC-Focused Threat Intelligence Platform Request a demo: info@vyuhnet.com
5
-
Vyuhnet
455 followers
IOC Velocity Report: February 04, 2026 Indicator of Compromise activity tracking for GCC-relevant threats: Period comparison: Current: 1246 IOCs Previous: 612 IOCs Change: +103.6% Trend: ACCELERATING Most active threat actors by IOC volume: - Transparent Tribe: 57 indicators This acceleration indicates intensified threat actor operations. Organizations should review detection rules for coverage gaps. IOC velocity is a leading indicator of threat actor operational tempo. Sustained increases often precede targeted campaigns. --- GCC-Focused Threat Intelligence Platform Request a demo: info@vyuhnet.com
5
Explore collaborative articles
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.
Explore More