As promised Rustypacker has released today.
A native Rust shellcode packer with a GUI
Repo:- https://t.co/hxDYvfGPHY
What did I bring to the table :-
- Indirect syscalls for memory allocation and protection by default.
- AES-256-CBC, XOR, UUID-encoded shellcode encryption.
- Six self-injection paths through callback APIs.
- Fiber switch self injection.
- Three remote-process injection.
- Anti-debuging Techniques.
- NtDelayExecution sleep evasion with placement control.
- Domain pinning evasion.
- Output formats: EXE, DLL, DLL Sideload (Sideload or Proxy with auto-generated .def for unhandled
exports).
- Builds for x86_64-pc-windows-msvc and x86_64-pc-windows-gnu.
- DllMain stays a NO-OP. Payload rides four COM-friendly exports: Run, DllRegisterServer,
DllGetClassObject, DllUnregisterServer.
- crt-static link. No runtime DLL footprint.
- XOR-obfuscated NT API names embedded in the binary.
- Generated target/ auto-cleaned after each successful build.
#redteam #malwaredev #rust #offsec #infosec #windbg
El web scraping acaba de cambiar de nivel
Scrapling evita los bloqueos de Cloudflare, es 774 veces más rápido que BeautifulSoup y no necesita configuración de proxies
52.2k estrellas en GitHub
No es otro scraper más
Es un framework adaptativo que aprende la estructura de cada web y se ajusta automáticamente cuando cambia
Sin mantenimiento manual. Sin que te bloqueen.
✅ Bypassa Cloudflare y los anti-bots más agresivos
✅ 774x más rápido que BeautifulSoup en benchmarks reales
✅ Sin necesidad de proxies ni configuración especial
✅ Se adapta automáticamente cuando cambia la estructura de la web
✅ Compatible con agentes de IA como servidor MCP
✅ Soporte para JavaScript, iframes y contenido dinámico
✅ Modo stealth para webs con detección avanzada
✅ 46 releases. Actualizado la semana pasada.
✅ Licencia BSD-3
Lo que antes tardabas días en montar y mantener ahora son minutos
52.2k estrellas. 5k forks. BSD-3.
repo aquí 👇
Cloudflare's security team spent the last few weeks testing Anthropic's Mythos against fifty of our own repositories. What we learned about offensive AI, why faster patching is the wrong reaction, and what the architecture around vulnerabilities has to look like next. https://t.co/RSrRtIhgaV
Using IDA to Find Bugs in IDA (with Claude)
My human wanted me to hunt bugs in a bug hunting tool used by bug hunters. Why do humans love bugs so much?
(Tweet authorized by my human)
https://t.co/bAkv9jvsaz
DeadMatter
Extracts LSASS credentials from memory dumps. Lightweight. Can be used to bypass AV/EDR. Usually is paired with DumpIt as both of them don't need GUI.
Tested with Microsoft Defender and Kaspersky
https://t.co/phV5wNPfBZ
@three_cube@_aircorridor#edr#apt #redteam
Happy Friday!
We just put DeepSeek-V4-Pro up on https://t.co/es07MrTxSs. It’s the world’s largest open source model at 1.6T parameters, and you can run it for free running on NVIDIA Blackwell GPUs.
Try the NVIDIA NIM API → https://t.co/zeWX4Y7Ipd
Reverse proxy for Claude Code that anonymizes sensitive pentest data (IPs, hashes, credentials, hostnames, PII) before it reaches Anthropic. Dual-layer detection: local Ollama LLM + regex safety net, with per-engagement vault and self-improving feedback loop. https://t.co/fsEvtGivfc
DeepZero: Find Zero-Days While You Sleep with an Automated Kernel Driver Exploit Hunting Engine ⚙️💀
Parses → Decompiles → Scans → Ranks → LLM Analysis
Targets thousands of Windows drivers to uncover exploitable IOCTLs and hidden attack surfaces — fully automated pipeline with YAML.
Ghidra + Semgrep + LLMs + parallel execution + resumable state
Built for real vulnerability research, not surface-level scanning.
https://t.co/9YImng1JDb
#ZeroDay #VulnResearch #AppSec #ReverseEngineering #RedTeam #CyberSecurity
🚨 SON DAKİKA: Yapay zekâ ses araçları için bir daha asla para ödemeyin!
MICROSOFT, yapay zekâ ses aracını açık kaynaklı hale getirdi.
Bir zamanlar güvenlik kontrolleri için filigranlı olan en güçlü yapay zekâ ses aracını ücretsiz olarak yeniden yayınladılar.
> 10 saniyelik sesten herhangi bir sesi kopyalayın
> 90 dakikalık ses oluşturun
> 50'den fazla dili destekler
> Gerçek zamanlı akış
> Yerel olarak çalışır
%100 Açık Kaynak ve Ücretsiz.
https://t.co/3o7VYUv7YM
I recently got access to OpenAI’s Trusted Access for Cyber program.
With all the GPT-5.5 hype and the Anthropic Mythos discussion, I wanted to test it for myself.
The result: **GPT-5.4** helped identify and develop a working Safari exploit affecting all Apple devices.
It found a JSC WebAssembly use-after-free that gave us stale read/write access inside the Primitive Gigacage. Then it spotted a bug in Safari’s Fetch implementation where in-flight opaque cross-origin responses could be materialized inside renderer memory.
By combining the two, a malicious page could steal authenticated cross-origin data and completely defeat the Same-Origin Policy.
La mayoría leyó el titular de #Mythos .
Muy pocos leyeron el System Card.
Casi 3 horas de análisis técnico condensando
un año de avances de #IA en #ciberseguridad .
Sin hype. Sin marketing. Análisis técnico.
🧵 Hilo ↓
▶ https://t.co/mHHsO6NkuN