Credential Guard was supposed to end credential dumping. It didn't.
@bytewreck just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled.
Read for more ⤵️ https://t.co/mYPHg1mTKj
Found an XSS but got blocked by the CSP?
https://t.co/0aA3GyIOVz has a compiled list of ways to bypass the Content-Security Policy. Check out the video below 👇
The security vulnerability we found in Perplexity’s Comet browser this summer is not an isolated issue.
Indirect prompt injections are a systemic problem facing Comet and other AI-powered browsers.
Today we’re publishing details on more security vulnerabilities we uncovered.
Goexec is a new take on some of the methods used to gain remote execution on Windows devices. Goexec implements a number of largely unrealized execution methods and provides significant OPSEC improvements overall
https://t.co/djN3yL4FfY
Github repo:
https://t.co/me3WItpsIm
Attacks against AD CS are de rigueur these days, but sometimes a working attack doesn’t work somewhere else, and the inscrutable error messages are no help. Jacques replicated the most infuriating and explains what’s happening under the hood in this post https://t.co/eF5nhHfPuS
Great video with @xssdoctor and @ctbbpodcast on modern XSS chains.
Bounty programs should start rating XSS in classes by how many gadgets the hunter had to use. Higher payouts for more gadgets.
https://t.co/gnavPtFOWK
Are you interested in incorporating Large Language Models (LLMs) into app tests yet lack the tooling to get you there? In our new #blog, App Security Practice Lead Geoff Walton walks through how to start using effective #LLM attacks today. Read it now! https://t.co/7j1mODob8w
The LLMNR response name spoofing pioneered by @tiraniddo and @Synacktiv does not seem to work with mDNS & NetBIOS 😢
But guess what! It works with DNS😯
🥳 Here's the new pretender release supporting Kerberos relaying via DHCPv6-DNS-Takeover: 🎉
https://t.co/2zhJlpBRvn
#infosec