Weekend project: I added IAKerb support to Rubeus. My god, this is going to open the floodgates.
Phase 2 of Microsoft's NTLM deprecation is targeted for H2 2026. IAKerb ships for Server 2025 / Win11 24H2 and is already on by default in the June Canary preview. It proxies Kerberos auth through exposed services via SSPI when a client can't directly reach a KDC.
Which means anonymous user enum via AP-REQs with no preauth (zero telemetry), kerberoasting over the open internet, Entra lateral movement through AZUREADSSO tickets and more. All against public facing services.
Blog post soon with potential abuse vectors.
Radical VA Secretary Doug Collins is again attacking veterans benefits in extreme and unprecedented ways.
And the VFW and most other leading veterans organizations are alarmed and hitting back.
With all the other disruption and mayhem, extreme VA changes under Trump and Collins are way below the national (and media) radar. But the culture war and attack on the agency, its programs, and its people continue—and are severe.
This comes after staff cuts, DOGE, and changes like the near-total ban of abortion care and counseling—which is no longer provided, even in cases of rape, incest, or health emergencies.
Collins is on an ideological and highly-political rampage. Decades of progress and the lives and wellness of millions of vets are in the crosshairs. And getting very little attention and oversight. Share, watch this space, and stand with our vets.🚨🇺🇸
🚨 0-Day Alert: Full-chain exploit for Apple Safari/WebKit in the wild (just patched)
CVE-2025-43529: UaF in JSC Escape Analysis (RCE)
CVE-2025-14174: Buffer Overflow in ANGLE (Sandbox Escape)
⚠️The sandbox escape bug is same as reported in Chrome last week
@TaylorMadeGolf@McIlroyRory@TommyFleetwood1 I’m choosing @TommyFleetwood1 Spider putter because he’s one of my favorite players and his putting has been rock-solid for years. His touch on short and mid-range putts is elite, and I’d love to use the same style putter that helps him stay so steady under pressure.
How do you get into cyber?
Need to bridge the gap from no experience to jr?
Today we are releasing three modules for FREE from our course “Hacking Your Career”!
These modules cover my favorite training resources across every domain: Blue, Purple, and Red additionally organized by cost tier: free, cheap, and expensive.
Each recommendation made the cut because it actually builds skill, and most include certifications you can add to your resume!
https://t.co/hMzciodVVV
So, here's the deal--If you're a pen tester who says, "I don't pen test for AI injection flaws," it's like saying that you don't test for SQLi, or XSS, or command injection. You are missing the boat on some of the most important vulns today. It's like saying in 2004, "We don't test SQLi or XSS." You've gotta test for it. NOW.