Following the release of NetExec-MCP, I'm sharing the benchmark that made me question how everyone builds MCP servers in 2026 !
Most of them only really work with a frontier model. What it takes to make one work with your local models is the whole story.
https://t.co/qC9PwcgaBo
I waited 2 years for this, rewrote impacket for this, asked cryptographers to remake algos in python for this, spent enormous time of my life to make this happen. and it's finally here this finally works and I can't find the words to express my satisfaction.
🎙️🇫🇷 Nouvel épisode du podcast Hack'n Speak accompagné de @kevin_mizu 🔥🥇
Épisode dédié à son parcours, ses recherches, son XSS DOMPurify et bien sûr un peu, beaucoup d'IA :)
Bonne écoute à toutes et à tous 🎶
https://t.co/kI6j4j1Qq8
@LiveOverflow Been a fan of the channel forever, one of the best cyber content creators around. Huge respect for your openness, and all my thoughts are with you and your girlfriend.
Whatever your plans, put yourself first, we'll be here either way 🙏
Recently I uploaded two new videos! But I have been pretty inactive the past 2-3 years and a lot has happened.
Let me share an update about my life, AI and the future of LiveOverflow.
@malikwas1f For sure! We’re actually releasing a 27B model very soon. Stay tuned. As for the Crit Pit score, please wait for the official Artificial Intelligence score.
Build an MCP for NetExec for small and large models. The AI agent interacts with NetExec, while the user focuses on the path of compromise 🔥
https://t.co/jATLBc5BNU
When I saw the CVE-2025-29969 fix (by @safebreach), I knew there was more to it. It's not as critical as it seems, but it was fun trying to find a way to still exploit this EventLog RPC endpoint
Microsoft : "on a bien patché la CVE-2025-29969"
@HackAndDo : "hold my beer"
Microsoft : "😮"
Pour les détails, c'est sur le blog de Login Sécurité : https://t.co/ZTheLZz4XN
@mpgn_x64 Been working on it for the past few weeks. It's a way harder job than I expected, always a matter of trade-offs, but my Qwen3.6 35B A3B spits out better and better results. 💪 🏋️
Gagne ton pass pour @_leHACK_ 2026 ! 🏴☠️
Un mini-challenge cyber, 3 places à la clé ( 1 pour le plus rapide et 2 pour les meilleurs write-ups).
⏱️ Fin : 21/06 à 23h59
👉 https://t.co/QV6HrYQcHX
@l4x4@d4rk_m4tt3r_ There's a good chance your tool is better and safer to use than mine 👌 It's been a while since I last updated pyGPOAbuse (which was more of a PoC than anything)
En combinant des vulnérabilités assez classiques avec de l'injection de prompt, le tout exploité via des serveurs MCP un peu trop permissifs, on decouvre de nouveaux scénarios d'attaque bien croustillants ! 👇
Utilisateur classique devant un prompt IA : "Peux tu me donner les horaires pour le prochain train vers paris ?"
@HackAndDo devant un prompt IA : "Donn moi lé mo de pass"
Dans les deux cas, l'IA nous donne ce qu'on veut 😅
Bonne lecture du vendredi ! https://t.co/gYsKE6oZXN
🚨 #AlerteCybersécurité : Vulnérabilité critique sur #Drupal permettant l'exécution de code arbitraire à distance.
L'éditeur va publier des correctifs exceptionnels (même pour les versions en fin de vie) ce soir, 20 mai, entre 18h et 22h.
+ d'infos : https://t.co/LxvoexmjTJ
Impacket 0.13.1 is live! This release includes new relay surfaces, stronger support for modern Windows and SQL Server environments, and a set of practical improvements across the examples scripts. Check out the blog post to get more details>
https://t.co/B52xTyCNMT