Dumping LSASS is old school. If an admin is connected on a server you are local admin on, just create a scheduled task asking for a certificate on his behalf, get the cert, get its privs. All automatized in the schtask_as module for NetExec 🥳🥳🥳
Are you (like me) constantly running into your own Responder? The days are finally over!🚀
@Defte_ and I finally finished up a PR by bdrogja that let's you define exclusions such as "yourself". You can also exclude entire ranges or IPv6 addresses (if anyone uses those lol).
Be aware that your photos can be accessed without unlocking your phone when you receive a WhatsApp video call on Android.
This is in plain sight. It's not hidden, not a secret feature. Not a hack.
This has already been reported to Meta and Google.
#Privacy#Security#Android17
Cet episode des "rires du Medef" est un tournant.
Il vient adouber JLM en tant que seul défenseur des travailleurs/classe populaire
Il vient le déclarer comme seul opposant au système eco/politique actuel
Et il vient de souder toute une classe sociale derrière lui
Game changer!
I've published UniBLEed, a fully wormable proximity Bluetooth RCE affecting Unitree's G1 humanoids. Blog spans cloud, mobile, firmware, Bluetooth & hardware. Two multi-bug RCE chains. 3 months into ~80 minutes, $6,700 in bounties. Go jailbreak your G1s!!
https://t.co/GYopBgDtTO
He copied a value out of the Windows Event Log.
Pasted it into his special browser.
And he was signed into Microsoft Entra as the user who had just authenticated.
No password. No phishing link. No stolen private key.
@MGrafnetter's Black Hat USA 2026 research...
@mrzshyey2@seblatombe Mon point est juste de dire que c'est une tâche complexe et que tous les services de l'état où je suis passé, bah c'était calamiteux. Y'a juste pas assez de moyen pour recruter les profils et lancer les bons projets
@mrzshyey2@seblatombe Ouais je confirme, tu pèses pas tes mots et te rend pas compte de la charge de travail que c'est de gérer un SI qui plus est quand chaque ministère a le sien. Quant aux admins expérimentés, ça paie pas assez le public :)
This past week I’ve been asked several times by people of different ages “how do you research and publish so much?”. It’s awesome to be asked. I love sharing tips and I try to give my techniques for maintaining a research pipeline. But I also want to be honest about my reality. At times, it’s an unhealthy coping technique. I’m getting much better at it, but in the past I’ve not been so good. I’ve skirted psych wards on multiple occasions, been given a “multiple weeks off work with several therapy sessions” order, been on various psych meds, torpedoed family events and holidays etc... Social media highlights the wins, but I try and be honest about the lows too where I can.
This industry is awesome, for many of us it gives us the chance to pursue our hobbies and passions. But it does encourage unhealthy routines. There is a reason that alcohol, drugs and mental health issues are embedded in infosec culture. And while sharing a new blog post or cool vuln can inspire people to want to be doing more, it shouldn’t come at the expense of a healthy mind.
An old boss once said “we want you doing this for a long time, not doing a lot in a short time”.. I still think about this now. Stay healthy h4xx0rz!
@grauchkGPT@FemboyNep@cipamwakesta@ninetalesangel Ça tombe bien, Benito revendiquait effectivement l'ancienne Rome, la grande Rome impérial pour justifier sa dictature, tu mérites ton étiquette de compte parodique toi
@FemboyNep@cipamwakesta@ninetalesangel Je rajouterai que le fascisme c'est aussi le culte de la tradition, le refus du modernisme (coucou les trade wife), le culte de l'héroisme, le machisme. C'est pas dur à définir la fascisme loin de là et c'est spécifiquement d'extrême droite
Found a heap overflow vulnerability in Windows SMB that leads to RCE and reported it to MSRC in June.
The vulnerability has now been addressed with CVE-2026-62800 in the August Patch Tuesday updates.
https://t.co/MVDbXNccfw
Exploit ResetNightmare with NetExec 🔥
CVE-2026-27912: a logical flaw in the Kerberos Change Password protocol lets an attacker with Generic Write on one account reset the password of ANY user/computer, including Domain Admins.
Built a module to automate the full chain 🚀
Because of that mechanism, failed authentication resulted in the NETBIOS timeout (more than 2 seconds which was our default value so far). But thanks to @Xed_sama , it's now patched on main branch. Time to update :)!
@RemotelyFreely Yeah! You could go from ntlm relay to smb, to connecting to the mssql pipe and triggering a coerce with the account running the mssql database! Niche scenario but could be useful!
Did you know MSSQL databases can be exposed via Named pipes ? Welp using Impacket we can now connect to these https://t.co/E1Dy3Nz5qD
Working on the integration on NXC 👀