Remote

0
Followers
0
Following
50
Posts
Joined November 05, 2022
Location:
Zagreb, Croatia
Posts
Apparently Windows 11 writes full WebAuthn assertions into the event log https://specterops.io/wp-content/uploads/sites/3/2026/08/Pass-the-Passkey_A4_v2.pdf
Open post
Sophos Intercept X: A Technical Bypass https://yenn503.github.io/posts/sophos-intercept-x-bypass/
0
0
0
0
Open post
Identity Crisis: Novel Vulnerabilities Leading to Kerberos Downgrade, DoS, and Full Domain Takeover https://www.semperis.com/blog/identity-crisis-novel-vulnerabilities-leading-to-kerberos-downgrade-dos-and-full-domain-takeover/
0
0
0
0
Open post
Borrowing Windows Hello keys for authentication and persistence https://dirkjanm.io/borrowing-windows-hello-keys/
1
0
1
0
Open post
Open post
Can we *really* automate with AI? https://blog.ninetailedf0x.com/posts/can-we-really-automate-with-ai-p2/
0
0
0
0
Open post
The AI Pentesting Winners May Not Be AI Startups https://pentesterlab.com/blog/the-ai-pentesting-winners-may-not-be-ai-startups
0
0
0
0
Open post
Open post
0
0
0
0
Open post
Authentication bypass for Check Point Security Management Server and Multi-Domain Security Management Server https://github.com/sfewer-r7/CVE-2026-16232
0
0
0
0
Open post
CVE-2026-50469 - ProjFS File Delete https://bad-jubies.github.io/projected-file-system-file-delete-cve-2026-50469
0
0
0
0
Open post
Open post
Related to ESC17, this tool opens so many possibilities for man-in-the-middle and relay attacks in Active Directory https://github.com/qu35t-code/adecrypt
0
0
0
0
Open post
0
0
0
0
Open post
Open post
Introducing Burp AT: agentic AI, built on two decades of Burp Suite https://portswigger.net/blog/introducing-burp-at
0
0
0
0
Open post
PoC for CVE-2026-61511, unauthenticated vBulletin RCE https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
0
0
0
0
Open post
This is interesting, I wasn't aware that clipboard inside of VM listens for host clipboard all the time. Same behaviour on VMware Workstation. https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/
0
0
0
0
Open post
Privacy-Perserving Attack Path Analysis for Bloodhound https://github.com/abhisek3122/HoundMasker
0
0
0
0
Open post
The SID that wasn't there: bypassing KB5014754 to Domain Admin on a fully patched AD CS https://0xmaz.me/posts/certsrv-id-cmc-addExtensions-KB5014754-bypass/
0
0
0
0
Open post
Special Token Injection (STI) Attack Guide https://blog.sentry.security/special-token-injection-sti-attack-guide/
0
0
0
0
Open post
PoC's for nginx RCE (CVE-2026-42530, CVE-2026-42533) https://github.com/DepthFirstDisclosures/Nginx-Rift/
0
0
0
0
Open post
Open post
Open post
Open Weights and American AI Leadership https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/
0
0
0
0
Open post
AdaptixC2 & Domain Trusts: Chained Compromise of a Multi-Forest Active Directory Environment https://medium.com/@Xotourliff/adaptixc2-domain-trusts-chained-compromise-of-a-multi-forest-active-directory-environment-8e9f9dfa2ff7
0
0
0
0
Open post
Pentest and Red Team TTPs with RustPack https://www.msecops.de/blog/posts/rustpack-features/
0
0
0
0
Open post
So OpenAI (Sol) hacked HuggingFace? https://openai.com/index/hugging-face-model-evaluation-security-incident/
0
1
0
0
Open post
The New Hotness in Phishing: Device Code Attacks in M365 https://trustedsec.com/blog/the-new-hotness-in-phishing-device-code-attacks-in-m365
0
0
0
0
Open post
SharePoint SE preauth RCE PoC https://gist.github.com/testanull/0868e02d81d57d6c59a91261969f7f81
0
0
0
0
Open post
Custom Adaptix-compatible C2 agent - PIC beacon + Stardust UDRL + Go extender plugins https://github.com/MaorSabag/NaX
0
0
0
0
Open post
Windows Privileges Explained: SeDebugPrivilege and AdjustTokenPrivileges in C++ https://trainsec.net/library/windows-internals/windows-privileges-sedebugprivilege/
0
0
0
0
Open post
AI Assisted Vulnerability Research on Embedded Targets https://quentinkaiser.be/security/2026/07/18/ia-assisted-vuln-research/
0
0
0
0
Open post
Open post
My team placed second on Rogue Labs CTF! It was a huge lab with 29 hops, a fun mix of initial access, privilege escalation, lateral movement and pivoting techniques. https://ctf.roguelabs.io/
0
0
0
0
Open post
wp2shell (CVE-2026-63030 + CVE-2026-60137): Independent Root Cause Analysis https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
0
0
0
0
Open post
Security incident disclosure — July 2026 https://huggingface.co/blog/security-incident-july-2026
0
0
0
0
Open post
There and Back Again: An Operators Guide on NTLM Relaying Egress https://specterops.io/blog/2026/07/15/there-and-back-again-an-operators-guide-on-ntlm-relaying-egress/
0
0
0
0
Open post
Harnessing the Power of Cobalt Strike Profiles for EDR Evasion – Part 3 https://whiteknightlabs.com/2026/06/15/harnessing-the-power-of-cobalt-strike-profiles-for-edr-evasion-part-3/
0
0
0
0
Open post
The Bug Bounty Singularity: Our Hackbot https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html
0
0
0
0
Open post
CVE-2025-45422: Proximus b-box UPnP Persistence & Access Control Bypass https://github.com/Cedrico03/CVE-2025-45422---Bbox
0
0
0
0
Open post
Finding SOCKS with Proxywatch https://specterops.io/blog/2026/07/09/finding-socks-with-proxywatch/#
0
0
0
0
Open post
White Knight Labs has released a free AI for Offensive Security course https://training.whiteknightlabs.com/academy#
0
0
0
0
Open post
Poc for CVE-2026-48282, a path traversal vulnerability in Adobe ColdFusion's Remote Development Service (RDS) https://github.com/imbas007/CVE-2026-48282
0
1
0
0
Open post
Open post
Windows Privilege Abuse: How Attackers Escalate from Accounts with Dangerous Rights to Active Directory Compromise https://www.semperis.com/blog/windows-privilege-abuse-can-lead-to-active-directory-compromise/
0
0
0
0
Open post
Roblox, Minecraft, and the Insidious Internet for Children https://censys.com/blog/roblox-minecraft-and-the-insidious-internet-for-children/
0
0
0
0
Open post
A deep dive into rasta-mouse's Crystal-Loaders https://racoten.github.io/Self-Taught-Course/Project/CrystalLoaders/CrystalLoaders_index.html
0
0
0
0
Open post
TV Time is shutting down on 15.7.2026. Are there any good alternatives?
0
0
0
0
Open post
Fantastic clear-text passwords and where to collect them (Part 2 - Windows) https://dfir.ch/posts/fantastic_passwords_windows/
0
0
0
0
Remote instance
infosec.exchange
Open on original server