Black Hat Ruby โ Offensive Ruby programming book for hackers & pentesters
Available on Amazon, Order your copy Now!
https://t.co/4HrudsNj9k
#BlackHatRuby#Rubyfu#BlackHat#Ruby#Redteam
PoCs for Apache Tomcat Unauth RCE (CVE-2026-34486) and Apache httpd Pre-auth RCE (CVE-2026-23918) are now public on our Github.
Tomcat exploit is fully reliable. httpd chain works in a controlled lab setup with a known info leak.
https://t.co/D3dg5iTuwP
https://t.co/2zyr1ds4Mo
Just pushed a minor update to #mimikatz 2 ๐ฅ(no - it's *NOT* the version 3) to support specific GMSA DPAPI passwords in LSA secrets to be able to to decrypt Masterkeys
> https://t.co/UNUIxSOhtS
Only for @topotam77 convenience ;)
Introducing Combat Theater, a malware technique emulator built for blue teams, detection engineers and security researchers to perform testing and detection validation quickly and easily.
Check out the introduction blog to learn more!
https://t.co/mX8qmWDI9W
Exciting news: Zero-Point Security has joined @fortraofficial and will work alongside the @_CobaltStrike, @OutflankNL, and @_CoreImpact teams to develop the next generation of offensive security training! Get more details on the blog https://t.co/ROlgDlsAje
Never been happier to have a mouse in the house. ๐ญ
@_RastaMouse of @_ZeroPointSec has officially joined @Fortra! The mind behind Red Team Ops, one of the most respected training courses in offensive security, is now building what's next with us.
Details: https://t.co/cITQF1t9nL
The FLARE team now freely distributes its quality reverse engineering and malware analysis educational content at https://t.co/bGCIjBfD3C. Launched with:
- Malware Analysis Crash Course
- Go Reversing Reference
- Intro to TTD
I am releasing a new toolkit I built for IIS-based lateral movement and code execution within IIS worker pool process's memory.
Phantom ASPX Loader & PhantomLink -- a two-part toolkit for reflectively loading native DLLs into IIS w3wp.exe worker processes via ASPX.
https://t.co/EevQysfANT
#OpSec#Red_Team_Tactics
1โฃ. Initial Access. The Art of Getting In https://t.co/grnWfEsr81
// Payload Development (DLL Sideloading, Shellcode Loaders, Syscalls), HTML Smuggling, Phishing (QR Code Quishing, Teams Phishing), AitM/MFA Bypass (Evilginx, Device Code Phishing), Psw Spraying, Exploiting Public-Facing Apps, Vishing, Physical Access (Rubber Ducky, Bash Bunny), Supply Chain attacks with real-world APT case studies
2โฃ. Red Team Infrastructure. The Full Picture: From Domain to Beacon https://t.co/YKTlMfTkTj
// C2 Frameworks, Redirectors, CDN Relays (Azure, AWS, GCP), Serverless Lambda, Cloudflare Tunnels, Phishing Infrastructure, Mail Servers, Malleable Profiles, and full OPSEC hardening
3โฃ. Persistence: The Art of Staying In https://t.co/qm7MfK9lxu
// 50+ techniques across Windows, Scheduled Tasks, WMI, Services, DLL/COM/AppDomainManager, UEFI Bootkits, Active Directory, Linux, macOS, and Cloud (Azure/AWS/GCP, Kubernetes)
Happening right now (open till Sat, 2/21/26)!
A week-long CTF dedicated exclusively to reverse engineering.
Hosted by https://t.co/sVUjIvBUcS, inspired by the legendary Flare-On Challenge.
https://t.co/kK3wKtRe8l