Oh, the irony.. CISA — the agency responsible for telling everyone else how to secure their infrastructure — reportedly had internal cloud credentials, deployment files, Terraform configs, and plaintext passwords exposed in a public GitHub repository:
https://t.co/2SCkGsM4Pv
Most operators are comfortable when they have backup. Our SOLO course is about what happens when you don’t.
When you’re operating alone, every mistake belongs to you.
Next course: June 20-21, 2026 | Virtual | €1500 | 12-20 CEST
Learn more: https://t.co/Ddib2tN5Ze
Attackers are now using Microsoft Teams chats to socially engineer employees into infecting their own systems with malware.
This article breaks down:
— how the fake IT support chats work
— why Teams makes the attack feel legitimate
& more
Read here: https://t.co/BodP6uedMp
Most companies prepare for physical attacks as if someone's sneaking in a window at night.
But the most dangerous attacker is often the one everyone assumes belongs.
Let's break down why physical intrusions almost always evolve into insider threats:
https://t.co/EXQoPwd9Kb
We want people to leave our courses able to immediately apply what they learned in the real world.
One student in latest PACT course said: “I came away feeling much more confident and prepared.”
Overall, students rated it a 9.6/10!
Next course: https://t.co/K7XAFUOm13
John-André Bjørkhaug has been developing specialized physical pentesting equipment focused on real-world PACS attacks, RFID exploitation, tamper bypasses & Wiegand interception.
This article takes a look at some of John’s equipment: https://t.co/2raptyzuCV
Most physical pentest training assumes you have a team. What if you’re running solo?
Our SOLO course is built specifically for experienced black teamers who need to plan, execute, adapt & problem-solve entirely on their own in high-pressure environments: https://t.co/Ddib2tN5Ze
Federal prosecutors say a Chinese aerospace engineer spent years impersonating trusted U.S. researchers to obtain restricted NASA and military aerospace software.
Not through malware. Not through zero-days. Through trust. Learn more:
https://t.co/HpD5kfw36J | #CyberSecurity
A local sports celebrity. A believable pretext. One social engineer inside a bank.
Patrick Laverty breaks down how OSINT, authority, and human behavior mattered far more than “breaking in” on this Covert Access Team Podcast episode: https://t.co/r4l2PHINUK
🚨 Last chance to join this weekend’s Physical Audit Certification Training (PACT) course.
We won’t have another PACT course until November, so now’s your chance.
Learn professional physical security audit methodology from experienced practitioners: https://t.co/0NVB5H28KG
Ana Montes spied for Cuban intelligence for nearly two decades while working as a senior DIA analyst. She allegedly avoided many traditional data exfiltration indicators by using one of the oldest methods in espionage: Memory.
Full story: https://t.co/Q6P9vwYWSa
Toronto Police just announced the first known SMS blaster case in Canada.
According to investigators, the attackers used mobile rogue cellular infrastructure to force nearby phones onto fake networks & push phishing texts directly into victims’ devices: https://t.co/LW3RCAzWFr
Spend this weekend getting certified to perform physical security audits 💪
There’s still time to join this weekend’s PACT course covering physical security assessments, covert entry, social engineering & real-world audit methodology.
Learn more:
https://t.co/0NVB5H28KG
Another Covert Access Team course wrapped up earlier this month.
The office was warned about the engagement beforehand.
The students still got in.
Physical security work is about adaptation, not scripts.
Course recap:
https://t.co/PeXuBzxJP6
Enroll:
https://t.co/0d2cWRVS0s
Brian sits down with Alex Cole, the creator of Fitted, a new physical security tool built around a problem every physical pen tester understands: finding repeatable ways to exploit real-world access control assumptions.
Listen on Youtube: https://t.co/aLqfAiLKKr
Most new physical pentesters want to jump right into physical pentests. For beginners, that’s usually a mistake. That’s why we built the Physical Audit Certification Training. Audits help you learn the fundamentals.
Join our next PACT course May 23-24: https://t.co/0NVB5H28KG
Federal prosecutors say a crew in Michigan moved ~400 high-end vehicles worth around $40M through a coordinated theft and export pipeline.
Local theft → staging lots → shipping containers → rail/freight → overseas.
Read the full post: https://t.co/nY0uVUe13V
🚨 Covert Access Team is offering free physical security penetration tests and audits to a limited number of European companies. 🚨
Interested? Email [email protected] to learn how your company can be considered.
#CyberSecurity#PenTesting#PhysicalSecurity
Most teams waste recon time. Not because they’re lazy—but because they don’t know what “done” looks like.
Let's break down how we structure recon across OSINT, long range, short range, and embedded—and what you should accomplish before moving closer: https://t.co/ICSWOjFA97
Another idiot gets into a high-security airport.
A man breached the perimeter in broad daylight, made it onto a remote taxiway, climbed onto a parked U.S. Air Force C-130, and started striking the aircraft with a handheld tool before being stopped: https://t.co/CBoyp9kMPj