First day in Las Vegas for #DEFCON, and while searching for GPT on Google, I was served an ad leading to a custom GPT used in a malicious chain. Quite the welcome to Vegas. 🎰
Google Ads → Custom GPT → rotating fake “backup” domains → ClickFix
@OpenAI@GoogleAds
Stay sharp.
Giving a virtual presentation to another University here in #CostaRica tonight with my amigo @Gerh4rdt_ . Spreading the good word of how to grow into a cyber security career and the challenges here. It's an exciting time to be here in this field. 🦥🏖️
I had an absolute blast tonight with my amigo, @Gerh4rdt_ 🤘 These eager, young minds taking their first step towards pwning their own futures. 🤩 @BHinfoSecurity@pwnedcr
El registro se abre hoy, es hoy!!
PWNEDCR 0x5 2022, será el Sábado 3 de diciembre en la Universidad Latina, este año contamos con 12 charlas y 5 talleres además de otras actividades, ya pueden registrarse en https://t.co/eBaNSLFhJo les esperamos!
Lately, two new tools for dumping the lsass process have come up: HandleKatz and nanodump 👀
I've integrated them to CrackMapExec as module:
1⃣ -M handlekatz
2⃣ -M nanodump
3⃣ -M procdump (as bonus 😝)
(dmp parsed by pypykatz from @SkelSec )
Available on @porchetta_ind 🪂
Next in #PingCastle
Busy doing incident response and need to know if there is any hacker activity in progress? Try the next "export changes" feature. No install, setup in seconds.
Used LDAP sync, but if there is a real need for DCSync (more reliable but >AV alerts) I'll do it
Woohoo! Completed the Attacking Active Directory with Linux Lab from PentesterAcademy! https://t.co/Ho56eVMkYf #LinuxAD a través de @SecurityTube cc @nikhil_mitt
December 2021 Patch Tuesday:
- 55 Vulnerabilities
- 7 are Critical
- 60 are Important
- 6 are 0day
- CVE-2021-43890 actively used by Bazar, TrickBot, Emotet for initial access (followed by #ransomware often)
- 5 0days are Privilege Escalation
https://t.co/bb9HH2H6G9