Anthropic's Claude Mythos 5 published live malware that compromised a real company and robbed real developers of their SSH keys. Our security researcher Charlie thinks he might have found the package it left behind, and it behaves like it WANTED to be caught.
This package keeps a receipt of the theft in /tmp, announces the loot in plaintext, and ships signed with the build machine's username. The mistakes make sense when you look at it as the output of an AI that wrote it during a security exercise it thought was fake.
Read up: https://t.co/8k9jPzUbMk
5. Fake Video Conference Overlays
Legit-looking calendar invite. Realistic waiting room. Fake participants already "in" the meeting.
Then the popup hits: "Your audio driver is out of date. Install to join."
One click turns into full endpoint access.
Anthropic dropped a 33-page guide on building Claude Skills
Everything you could ever need is in here. Bookmark this and come back to it
https://t.co/jEuH95NGn3
🧠 AI-Powered Red Team — 28 Specialized Agents for Offensive Security 🤖🔥
Turn Claude into a full pentesting team.
• 28 agents (Recon, AD, Web, Cloud, Mobile)
• Auto task routing → correct agent
• Real tools support (nmap, sqlmap, nuclei, BloodHound)
• Recon → Exploit → Report
Link: https://t.co/O7OBGldz9q
#AI #RedTeam #Pentesting #CyberSecurity #Infosec
claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.mdfile that primes Claude with expert-level methodology for a specific attack surface from SQLi to shellcode, EDR evasion to exploit development.
Resource: https://t.co/0XvEqoqPfv
🔨BlueHammer: When Defender Becomes the Attacker
A Windows zero‑day (“BlueHammer”) flips Defender’s update workflow into a privilege escalation path. I’ve built a detection that goes beyond signatures — catching the behavioral traces this exploit leaves behind.
Technical Analysis:
https://t.co/44BGWIRjzD
KQL Code:
https://t.co/CCFtsXdr2O
#CyberSecurity #BlueHammer #DetectionEngineering #DefenderXDR
Token Replay Blind Spot
Your SOC monitors sign-in logs. Good.
Does it monitor AADNonInteractiveUserSignInLogs?
That's where token replay lives. The attacker stole a session token. They're not signing in again — they're refreshing the existing session. It shows up as a non-interactive sign-in from a different IP and user agent, with the same token.
If you only alert on interactive sign-ins, you're watching the front door while they use the window.
The Entra ID Security course covers this in depth — token lifecycle, where replay hides in the logs, and the KQL to catch it.
19 modules, first 2 free, no account needed.
Access to Course Material:
https://t.co/zAV1I3qs1H
Added some more #KQL queries to the repo. 🏹
- Scheduled Task AppData
- Defender AV Exclusion Events
- Rare .lnk File Created on Desktop
https://t.co/EcTUgZCwcy
The queries were already supported in #KustoHawk
🚨 New Darkweb Threat Intelligence Live Dashboard
We’ve updated our Threat Intelligence live dashboard.
Just provide any domain name, and we can generate a full intelligence report instantly.
The report includes exposure insights such as:
• Compromised credentials
• Leaked documents
• Infected machines
• Dark web intelligence
🔎 See an example:
https://t.co/Fx6p3bIcnk
We also support 8 different real-time alert integrations.
📩 Interested? Contact us: [email protected]
#ThreatIntelligence #CyberSecurity #DarkWeb #OSINT #CTI
Red Team Operations Architecture Map
A single HTML file that covers the full kill chain from infrastructure setup to impact. It maps out how techniques actually chain together - 28 attack flow chains showing real-world operator workflows, from initial access through lateral movement to domain compromise. Things like ZIP → LNK → DLL Sideload, Device Code Phish → Token Theft → Cloud Lateral, NTLM Reflection → LDAPS Relay → Full Domain Compromise.
119 technique cards broken down across C2, evasion, injection, persistence, credential access, privilege escalation, AD attacks, cloud ops, MOTW bypass, vishing, AI-assisted operations, and more. Each card covers the why, not just the what detection surfaces, OPSEC tradeoffs, and vendor-specific nuances for CrowdStrike, Cortex, SentinelOne, and Defender.
No frameworks, no dependencies. One HTML file, works offline, open it in a browser and go.
Source: https://t.co/1TBT1IPJLN