I'm the author of Cairn.
Recent reports say ARTEX was used in attacks on South Korean banks, and some people have started linking us.
ARTEX officially listed Cairn as an Architecture Reference in its README:
https://t.co/uPMoIhsYBE
Cairn was never a “hacking tool.”
#Cairn#ARTEX
@rogesterone Great article!
I have one question.
Can you guess why the agent uses amap?
I think of it as just a map service, so I find it quite puzzling.
(I thought it might be less likely for the server to go down if we cached traffic with Cloudflare rather than upgrading the server.)
I've never worked on WhatsApp before, so I thought it'd be interesting to poke it with a stick!
I wrote an article about my attempt to uncover WhatsApp's CVE-2026-23866:
https://t.co/56bQA9fuHZ
This is my first article on mobile VR, let me know what you think!
Module stomping is a popular choice for modern C2 implants and stagers, but why?
In our latest blog post we break down how the technique works, why commercial C2 frameworks use it and how defenders can detect it!
https://t.co/KVhntNjwWn
Many folks don't know how to get their hands on firmware for various firewall vendors or what not.
I use this for various automated workflows - though I'm sure folks will lively have many of their own (e.g automating patch diffing).
I put together and share a small toolkit you can point your agent at that will dump the image to S3.
For example, say I wanted to dump PANOS:
1. Accept the BYOL agreement on AWS Marketplace
2. You now have the AWS AMI ID
3. Use this and dump it to S3
4. ???
https://t.co/zRVdvhFYHA
The day P2O contestants stop flexing details of their upcoming entries before they've even stepped on stage will be a great day.
not only you poke the vendor to start panicking and hammer down on the product attack surface but you also provoke other contestants to start burning bugs
If you're interested in SDR / RF security and looking to attend @BlackHatEvents EU, make sure to get your early bird tickets with discount pricing before September 25th!
👉 Black Hat EU (London), December 7-8 2026: https://t.co/cdgjqjktAV
#SIGINT#RFsecurity#SDR
If you're interested in SDR / RF security and looking to attend @BlackHatEvents EU, make sure to get your early bird tickets with discount pricing before September 25th!
👉 Black Hat EU (London), December 7-8 2026: https://t.co/cdgjqjktAV
#SIGINT#RFsecurity#SDR
I'm hiring an exceptional Offensive Security Researcher for my team at NVIDIA (Offensive Security Research - OSR).
Firmware, microcode, RISC-V, hypervisors, and shipping mitigations like HW CFI, Memory Tagging, and Pointer Masking from the ground up.
https://t.co/vvPTRnwSKE