Time to level up your K8s security. I won't oversell the class - I'll just let 4 people I respect tell you what they got out of it.
Hack some #Kubernetes with me this August at @BlackHatEvents in Las Vegas!
Agentic AI-Aided Kubernetes Attack and Defense
https://t.co/G9PeJeRs68
Testing CVE-2026-32161 and successfully triggered a remote BSOD against my laptop over WiFi without requiring access to the same local network.
Still surreal seeing a wireless bug crash a machine from proximity alone.
Excited to teach #Kubernetes Attack & Defense @#BHUSA in Aug (@bhevents)! The class is >50% hands-on, w/ step-by-step labs. Students get computers to keep w/ CTF VMs & K8S cluster to #hack, win flags & break attacks. Come join me & the @InGuardians crew! https://t.co/blnnXrF0wH
Red Team collaboration has evolved over time. I remember using SILC for encrypted chats and TRAC wiki and source code tracking. Here are the more modern services I think Red Teams can benefit from and a super easy way to stand them up: https://t.co/airPbOCLRn
What do you use?
As promised... this is Loki Command & Control! 🧙♂️🔮🪄
Thanks to @d_tranman for his work done on the project and everyone else on the team for making this release happen!
https://t.co/fR44ukK1Y2
KrbRelayEx-RPC tool is out! 🎉
Intercepts ISystemActivator requests, extracts Kerberos AP-REQ & dynamic port bindings and relays the AP-REQ to access SMB shares or HTTP ADCS, all fully transparent to the victim ;)
https://t.co/Aebt5iFIjC
Loki C2 is coming..
Cross-platform Stage 1 C2, battle-tested in ops for 8 months against the world’s leading EDRs and MSSPs, undetectable, bypasses Application Control/WDAC..
Shoutouts to @d_tranman for helping build the project, and @chompie1337 & @knavesec for inspiration!
So excited to be presenting at the last #ShmooCon with @antitree this morning @10am - "A Commencement into Real #Kubernetes Security!"
https://t.co/etb43Dnvqa
Fun little Use After Free found in PHP cli. Might be writing up a blog on my latest findings in the near future.
https://t.co/85mSEHZ2BM
#bugbounty#cybersecurity
My Okta for Red Teamers post is up! We look at how Kerberos SSO works, how to intercept credentials via a fake AD Agent, decrypting AD Agent tokens, adding skeleton key's, and even how to deploy a janky SAML IdP server to auth as any user for good measure. https://t.co/Hs0wN5397s
Less than two months until my #Kubernetes Attack & Defense class at Black Hat Las Vegas! Content updates include using Falco! Students get a laptop to keep w/ CTF VMs & K8S cluster to #hack, gathering flags, breaking their attacks. https://t.co/M1nORshqZh… #BHUSA@BlackHatEvents
@NSACyber, along with our partners @NIST and @CISAGov, will play a major role in ensuring our nation’s most sensitive systems are protected from the #quantum computing threat. https://t.co/X8sTWtFSSE
The third post in my adversarial ML series "Learning Machine Learning Part 3: Attacking Black Box Models" is now up at https://t.co/7OMjR7cUL8 and the Invoke-Evasion repo has been updated with the associated Jupyter notebooks/samples https://t.co/twaGgLkCcy
ASR rule to harden LSASS is being turned on by default, but remember that this isn't a silver bullet, plenty of ways around this... this has to be one of my favourites 😂