JS sourcemaps are a goldmine for bug bounty hunters! 🤠
1. Grab any target's source map files
2. Unpack them using sourcemapper
3. Run metis on the TypeScript source files
Example! 👇
ALGUIEN CREÓ UN REPO EN GITHUB QUE TE PERMITE EJECUTAR CLAUDE CODE COMPLETAMENTE GRATIS, PARA SIEMPRE.
Redirige tu tráfico de Claude Code a 10 proveedores gratuitos como DeepSeek y Kimi, toma 5 minutos configurarlo, y ya tiene a más de 20,000 desarrolladores ejecutándolo.
Google ha acabado con la mafia de las GPU 💀
VS Code ahora se conecta directamente a Google Colab.
→ Obtienes una GPU T4 gratuita dentro de tu editor.
→ Tus archivos locales. Su potencia de cómputo.
Intercepting Unencrypted Satellite Communications
Passive GEO interception station is no longer something limited to intelligence agencies. It is now accessible to technically curious RF people with moderate budgets.
Because this has been known for decades, you'd naturally expect strong encryption to be the norm.
Yet for many non-broadcast data channels, especially internal IP backhaul links, encryption has historically been neglected.
We showed how widespread that neglect really is
Part 1: https://t.co/jZL2cX8ym4
Part 2: https://t.co/NuErE3AacF
@three_cube
卧槽,微信和支付宝正在秘密进行一场足以掀翻国内所有 App 活路的顶层改版。
据《金融时报》和彭博社等多方内幕流出,微信已经完成了内嵌 AI 智能体的原型测试,最快本月就要跑合规审批。
用户以后在微信主界面右滑一下,直接唤出最高战略级的 AI Agent,它能自己识别你的大白话,然后自动调用几百万个小程序帮你比价、下单、买咖啡。
另一边蚂蚁也不装了,直接灰度测试支付宝超级程序,引入全功能 AI 助手“阿宝”,不仅能帮你打车、订外卖,经过授权甚至能直接帮你买基金理财。
🚨 𝗡𝗲𝘁𝗹𝗼𝗴𝗼𝗻 𝗥𝗖𝗘 𝗗𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻 🚨
𝗖𝗩𝗘‑𝟮𝟬𝟮𝟲‑𝟰𝟭𝟬𝟴𝟵 (𝗖𝗩𝗦𝗦 𝟵.𝟴) — flagged by 𝗖𝗘𝗥𝗧‑𝗘𝗨 as 𝘢𝘤𝘵𝘪𝘷𝘦𝘭𝘺 𝘦𝘹𝘱𝘭𝘰𝘪𝘵𝘦𝘥. Unauthenticated attackers can escalate to 𝗦𝗬𝗦𝗧𝗘𝗠 𝗽𝗿𝗶𝘃𝗶𝗹𝗲𝗴𝗲𝘀 on domain controllers, with 𝗜𝗻𝘁𝗲𝗿𝗻𝗲𝘁‑𝗲𝘅𝗽𝗼𝘀𝗲𝗱 𝗡𝗲𝘁𝗹𝗼𝗴𝗼𝗻 𝗲𝗻𝗱𝗽𝗼𝗶𝗻𝘁𝘀 facing the greatest risk.
To help defenders, I’m sharing a 𝗵𝗶𝗴𝗵‑𝗳𝗶𝗱𝗲𝗹𝗶𝘁𝘆 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿𝗫𝗗𝗥 𝗱𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻 tailored to CVE‑2026‑41089, focused on monitoring the 𝗵𝗶𝗴𝗵𝗲𝘀𝘁‑𝗿𝗶𝘀𝗸 𝗲𝗻𝗱𝗽𝗼𝗶𝗻𝘁 𝗲𝘅𝗽𝗼𝘀𝘂𝗿𝗲.
CERT-EU Alert
https://t.co/l7qxXpaTUA
KQL Detection:
https://t.co/nu58sxA4Yo
#Cybersecurity #NetLogonRCE #DefenderXDR
🤖 We're excited to release qwen36-secura, ThreatMon's first public Cyber Threat Intelligence model on Hugging Face.
Built on Qwen3.6 and fine-tuned for cybersecurity workflows, qwen36-secura is designed to support CTI analysis, ATT&CK mapping, CVSS scoring, threat hunting, DFIR, and vulnerability research.
🔓 Open Source (Apache 2.0)
🏢 Fully Self-Hostable
🛡️ Built for Security Teams
Explore our Hugging Face repository:
https://t.co/MMiu5aIMDp
#CyberSecurity #ThreatIntelligence #CTI #AI #ThreatHunting #DFIR
微软最近开源一个 AI 终端:Intelligent Terminal,基于 Windows Terminal 开发,在终端里内置 AI 助手。
可以自动感知命令行的输出,报错时一键把上下文丢给 AI 分析,不用手动复制粘贴,还能直接帮执行修复命令。
GitHub:https://t.co/pBv4suyGFM
支持 GitHub Copilot、Claude Code、Codex、Gemini 等 AI Agent,会自动检测本地已安装的工具,开箱即用。
侧边栏的 AI 面板可以停靠在任意方向,复杂任务会自动开新标签页在后台跑,不打断当前工作。
所有对话数据只保存在本地,关掉会话就清除。可通过微软商店安装,和现有的 Windows Terminal 互不影响。
EDRUnChoker😀registers a permanent WMI subscription with a 5-second timer runs embedded VBScript (fileless) that deletes malicious MSFT_NetQosPolicySettingData policies targeting known security products or aggressive app-path throttles.
https://t.co/A1hcrpav2X
Brutespray — Open-Source Credential Attack & Password Spraying Framework 💀💥
Brutespray is a modern multi-protocol credential testing and password spraying tool designed for Red Team, Pentesting, and Security Assessment workflows.
Key features:
• Supports 40+ protocols (SSH, FTP, SMB, RDP, WinRM, LDAP, MySQL, PostgreSQL, Redis, and more)
• Imports Nmap, Nessus, Nexpose, JSON, and target lists
• Password spraying mode with lockout-aware controls
• Interactive terminal UI (TUI) with live monitoring
• Resume and checkpoint support for long engagements
• SOCKS5 proxy support
• JSON, CSV, Metasploit, and NetExec reporting outputs
• Single static Go binary with embedded wordlists
Useful for Red Team operators, penetration testers, adversary emulation exercises, credential auditing, and security validation in authorized environments.
🔗 https://t.co/XLkYsfBj8o
#RedTeam #Pentesting #CyberSecurity #GoLang #Nmap #PurpleTeam