Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

HD Moore

@hdm@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange
8296 Followers
1813 Following
26 Posts
Joined November 05, 2022
Home:
https://hdm.io
Github:
https://github.com/hdm
Work:
https://www.runzero.com/
Twitter:
https://twitter.com/hdmoore
Bluesky:
https://bsky.app/profile/hdm.bsky.social
Open post
HD Moore @hdm@infosec.exchange
· 2mo ago
Hello Las Vegas (and hackers following along at home)! I'm excited to share the first batch of our Out-of-Band / Baseboard Management Controller research at Black Hat USA today and DEFCON 34 this weekend. Read an exclusive by Ars Technica at: https://arstechnica.com/security/2026/08/thousands-of-servers-can-be-backdoored-by-exploiting-buggy-motherboard-controllers/ Interested in checking your network? The pre-release of OOBscan is live on GitHub: https://github.com/runZeroInc/oobscan Thank you to our friends at Dragos.com, NetRise.io, and all of the researchers abroad who helped with review & feedback!
arstechnica.com
16
0
8
0
Open post
HD Moore @hdm@infosec.exchange
· 2mo ago

The best part of BSidesLV/BlackHat/DEFCON is getting to meet the people you admire. I got a chance to nerd out with Thai Duong of calif.io today (photo proof!). Thai and team just posted their latest work - 3 remote exploits in FreeBSD - all critical issues if you use HA with your FreeBSD-based firewalls. Noteworthy is that these bugs were found months ago with relatively old model. Vulnerability discovery continues to accelerate!

https://blog.calif.io/p/the-taking-of-freebsd-one-two-three

blog.calif.io
14
0
1
0
Open post
HD Moore @hdm@infosec.exchange
· 4mo ago

My favorite bugs are where the vendor doesn't consider it a vulnerability: How a USB-connected speaker can infect a PC without ever being touched: https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devices/

arstechnica.com
25
0
18
0
Open post
HD Moore @hdm@infosec.exchange
· 7mo ago

New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises: https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/

AirSnitch resets WiFi security back to the bad-old-days of ARP spoofing and trivial MITM.

arstechnica.com
36
0
43
0
Open post
HD Moore @hdm@infosec.exchange
· 3mo ago
Skipping Black Hat and DEFCON this year? Consider presenting at BSides Hanoi instead. Now in its second year, the conference takes place on August 5th, 2026, and a few more talk slots are still open - but the submission deadline is today. Apply here: https://www.bsideshanoi.net/en/call-for-paper Thank you to everyone who has already submitted!
bsideshanoi.net
8
0
6
0
Open post
HD Moore @hdm@infosec.exchange
· 6mo ago

Tom Ptacek posted a great writeup titled "Vulnerability Research Is Cooked", covering the state of vulndev and its rapidly accelerating future:
https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/

Vulnerability Research Is Cooked
A Final Ward

Vulnerability Research Is Cooked

Vulnerability discovery has always been gated by elite attention. Elite attention is now abundant. What happens next?

23
6
10
0
Open post
HD Moore @hdm@infosec.exchange
· 5mo ago

RE: @runZeroInc@infosec.exchange

Excited to share what we've been cooking for the last few months:

Interactive attack graphs, with hop-by-hop planning, support for over 220 protocols, and no-auth backplane enumeration to identify non-IP systems unauth over the network!

Our free trial includes a fun Demo Organization you can explore and converts into our free Community Edition at the end (with all of the same capabilities, just a lower asset limit)!

infosec.exchange
12
0
4
0
Open post
HD Moore @hdm@infosec.exchange
· 5mo ago
Replying to
@joshbressers@infosec.exchange it feels like we're back to the 90s - anyone can break into anything and there's very little public information on actively exploited capabilities (and since you find new ones as you go...) - i don't see CVE even with CNAs, keeping up
6
2
1
0
Open post
HD Moore @hdm@infosec.exchange
· 9mo ago
Replying to
@gsuberland@chaos.social @GossiTheDog@cyberplace.social the exploit was included as a unit test in the original patch, wiring that into a python script isn't slowing down attackers (but surely made the defenders take notice)
8
0
0
0
Open post
HD Moore @hdm@infosec.exchange
· 8mo ago

runZero users get a new feature today (including Community Edition) - recurring internet speed tests for all deployed Explorers! This (very optional) capability lets you identify backhaul/connectivity issues for sites that you can't physically get to, smoothing the path for tool deployment and exposure management processes: https://www.runzero.com/blog/internet-speed-tests/

Thanks to Pete C for the writeup, Jeremy B for the UX, and Iain P for the suggestion!

Handy for tracking ISP issues on your home network as well =D

runzero.com
6
0
0
0
Open post
HD Moore @hdm@infosec.exchange
· 6mo ago

Joseph Menn, renowned journalist & author of "The Cult of the Dead Cow," joins us for a special book signing event at RSAC! runZero and Mallory are thrilled to co-host a private book signing with renowned investigative journalist Joseph Menn during RSA Conference 2026! This is your chance to meet the man who writes the stories the industry talks about.

Join us to grab a signed copy:

https://www.runzero.com/joseph-menn-book-signing/

runzero.com
4
0
1
0
Open post
HD Moore @hdm@infosec.exchange
· 6mo ago

runZero Hour 0x1C is live NOW: https://www.youtube.com/live/EF633eUIquI

4
0
0
0
Open post
HD Moore @hdm@infosec.exchange
· 16mo ago

A PSA for why you should probably not use Postman (it can leak secrets to them): https://anonymousdata.medium.com/postman-is-logging-all-your-secrets-and-environment-variables-9c316e92d424

anonymousdata.medium.com
17
2
8
0
Open post
HD Moore @hdm@infosec.exchange
· 3mo ago

@thegibson@masto.hackers.town thanks!

1
0
0
0
Open post
HD Moore @hdm@infosec.exchange
· 30mo ago

The #golang `gorilla/sessions` directory traversal and file (over)write is now being tracked as GO-2024-2730: https://go-review.googlesource.com/c/vulndb/+/579655

This issue was (co)-discovered as part of watchTowr's analysis of the Palo Alto Networks RCE (#CVE_2024_3400), but is entirely separate, and affects a wide range of Go-based web services.

https://github.com/golang/vulndb/issues/2730

If you use gorilla/sessions with the FilesystemStore, please switch to the CookieStore instead until a patch is available.

infosec.exchange

Infosec Exchange

30
0
26
0
Open post
HD Moore @hdm@infosec.exchange
· 7mo ago

Hello Austin Go hackers! Tonight (2026-02-11) is our next ATX Golang meetup, located in Station Austin (aka Capital Factory ). We will have pizza, drinks, and various short talks and discussions related to the Go ecosystem. If you're looking for a Go job, this is a great place to meet potential employers and get a sense for what the interview process looks like in a world of AI noise: https://www.meetup.com/atxgolang/events/312781558/?eventOrigin=group_upcoming_events

meetup.com
2
0
1
0
Open post
HD Moore @hdm@infosec.exchange
· 8mo ago

It's time for our first ATX Gopher meetup of the year! If you are in Austin and write Go code (or would like to start), please join us at 6:30pm at Station Austin (co-located with Capital Factory). Charles and I will be providing pizza and drinks as usual, we have a guest speaker lined up for the main session, and a few smaller talks available as time permit (
I plan to cover two new projects: 1. & 2).

https://www.meetup.com/atxgolang/events/312781553/?_xtd=gqFyqDc2Njk0NTQyoXCjYXBp&from=ref

1. https://github.com/runZeroInc/go-rod
2. https://github.com/runZeroInc/conniver/

meetup.com
2
0
1
0
Open post
HD Moore @hdm@infosec.exchange
· 6mo ago
LinkedIn

Running on Empty with runZero | Kyle Goode

Network asset inventory is basically Frogger. 🐸 You

1
0
0
0
Open post
HD Moore @hdm@infosec.exchange
· 6mo ago

Join author Caroline Wong for the release of "The AI Cybersecurity Handbook" at RSAC! runZero and Mallory are thrilled to co-host a private book signing with the AI cybersecurity strategist Caroline Wong during RSA Conference 2026! This is your chance to meet the woman Fortune 500 organizations are turning to for AI guidance on governance, risk, and resilience.

Space is limited. Register to request access to this event:

https://www.runzero.com/caroline-wong-book-signing/

runzero.com
1
0
1
0
Open post
HD Moore @hdm@infosec.exchange
· 8mo ago

@jeroen@secluded.ch thanks for the feedback - its a little tricky today since the multi-protocol traceroute code is part of the scanner where the speedtest bit is standalone and not part of a scan, i'll take a look though!

0
0
0
0
Open post
HD Moore @hdm@infosec.exchange
· 8mo ago

@jeroen@secluded.ch IPv6 is fully supported for everything (link-local scans are on by default, DNS AAAA records, etc)

0
0
0
0
Open post
HD Moore @hdm@infosec.exchange
· 8mo ago

@jeroen@secluded.ch we don't for the speedtest, but do full traceroutes as part of normal scans; we haven't added a visualizer/map/asn lookup there, but not reason we couldn't

0
0
0
0
Open post
HD Moore @hdm@infosec.exchange
· 5mo ago

ATX Go is TONIGHT (a week early this month):

Hey gophers! Join us Wednesday (May 6th, today), 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: 🍕 pizza, 🍻 beer, and a few short talks on Go. Bring a talk, a friend, or an idea!

https://www.meetup.com/atxgolang/events/312781570/

meetup.com
0
0
0
0
Open post
HD Moore @hdm@infosec.exchange
· 5mo ago

ATX Go is a week early this month, tomorrow night!

Hey gophers! Join us Wednesday, 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: 🍕 pizza, 🍻 beer, a few short talks on Go, and general discussion. Whether you write Go all day or just dabble on the weekends, come hang out and meet other folks in the Austin Go community.

https://www.meetup.com/atxgolang/events/312781570/

meetup.com
0
0
0
0
Open post
HD Moore @hdm@infosec.exchange
· 6mo ago
Replying to
@gsuberland@chaos.social fair!
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:06:43 UTC