SmartScreen bypassed. Mark of the Web removed. No Run Dialog. No PowerShell popup. Just a browser file upload.
FileFix is a new ClickFix alternative. Browser file upload opens File Explorer. File Explorer address bar executes OS commands. cmd.exe spawns as a child of Chrome. The user thinks they are pasting a file path.
Executables launched through File Explorer's address bar lose their MOTW attribute entirely. SmartScreen never triggers.
https://t.co/17VpLAxeoM
Author: @mrd0x
#Malware #Phishing #InfoSec
I just released EIDVirtual v2! 🚀
Get a virtual smart card reader that uses a real USB drive for free. It automatically simulates a GIDS applet to manage your certificates—a perfect alternative to TPM-based MS Virtual Smart Cards.
Check it out here 👇 https://t.co/SDcXAbocOt
Since GLPI maintainers see this as irrelevant: GLPI Agent blindly trusts its configured server,no command signing, no allowlists. Redirect it to a rogue server and a local admin can escalate to NT AUTHORITY\SYSTEM via malicious Deploy tasks.
PoC: https://t.co/iQR854wJse
GitHub isn’t just a code platform anymore. It’s a security boundary.
New from @jaredcatkinson: how GitHub creates real attack paths into repos, secrets, CI/CD, and even cloud environments.
Read more: https://t.co/E8sLYPmEKL
WSL2 is a powerful attacker hideout because it runs as a separate Hyper-V VM, and defenders rarely monitor it.
Daniel Mayer explains how attackers pivot into WSL2 and what it took to build tooling that works across WSL2 versions.
Read more ⤵️ https://t.co/TaPsDDW4Cq
mfw I realize you can use C++ WINAPI COM IUIAutomation to communicate with Copilot directly and tell it do things like "execute this file" (Copilot is now Copiloting my malicious payload)
Since the year is almost over, here’s a thread that links to each cybersecurity thread I wrote in 2025. Topics cover ISO27001, AI threat detection, limiting MS app permissions, MCP, phishing sims, and more. Hopefully there’s something useful:
Tunnelto : un outil CLI Open Source écrit en Rust pour exposer un serveur local via une URL publique.
Une alternative plus simple et auto-hébergeable à Ngrok.
👉 Le projet : https://t.co/oxMiyqYOIT
👉 En savoir plus : https://t.co/fE0fpoQXQu
Interesting. But don’t you think CloudFlare is going to stamp this out soon?
Just read it also uses CAP bypass tricks, one from TokenSmith for InTune ✌️
https://t.co/uu1QbBK6Ll
Mailbox auditing has always been a pain... :(
There is a reason my scripts get ALL mailboxes and iterate through them to force enable auditing and all records instead of trusting attributes
Don't wait until IR to found out you're hosed, follow my guide:
https://t.co/NKtQGQKeRm
The challenge with TP-LINK....
TP Link routers have had IMHO really shit defaults for a long long time.
Today friends and I joke about wifi because in the UK the most insecure WIFI networks we have audited/reviewed have been using TP Link defaults.
hashcat -m 22000 hash.txt -a 3 "?d?d?d?d?d?d?d?d"
this will crack a TP Link WPA2 password on a CPU in minutes (M2 MAC takes about 1-11 minutes)
There's way more to this subject than WIFI.
> Do TP-Link respond well to vulnerability disclosure?
> Do they patch in a timely manner?
> Can TP-Link be coerced to disable updates/deploy updates etc.?
in the UK I don't find a lot of TP-LINK Wireless networks.
This is not true for every country. The USA has a massive chunk of TP Link routers.
There's a lot of questions people should probably be asking about this subject.
People often think there's some kind of 'BIG THING' but largely it's the small things that make up the reality of the world.
They have had weak WIFI defaults for a long time.....
I've been told they don't respond well to disclosures.
Do they pose a security threat?
Do they pose an economic threats?
Are they just a bit shit or is it deeper than that? (don't want to get tin foil.... I don't think it matters which)
anyway, if you are in the policy space/security space/cyber space.... there's things to consider here.
If you have a TP-LINK router with shit defaults, I would suggest you review and take appropriate steps to improve the situation. With the WIFI use a strong PSK as an example, probably change the SSID as well. Make sure you set a strong admin password as well.
💡 List all Intune remediation scripts containing Invoke-WebRequest without UseBasicParsing (CVE-2025-54100)
#MEMPowered#MSIntune@Hoorge
https://t.co/Vg46hEFyRc
After Months of Development, FINALLY ready to share: Harden System Security🎉
✅ Complete System Hardening
✅ Security Posture Analysis
✅ All-in-One Toolkit
✅ Built-in Intune support for Scalability
✅ Beautiful Modern UI
✅ CLI support
https://t.co/lfd3SaDvvM
#Cyber#Windows
🛠️ HikvisionExploiter
HikvisionExploiter is a powerful and automated exploitation toolkit targeting unauthenticated endpoints on Hikvision IP cameras, particularly those running firmware version 3.1.3.150324.
https://t.co/NFb2mlT867
🚨Alert🚨 CVE-2025-10680 : High-Severity OpenVPN Flaw Allows Script Injection on
Linux/macOS via Malicious DNS Server
📊3.6M+ Services are found on the https://t.co/g3tSyh13yE yearly.
🔗Hunter Link:https://t.co/y6D7wneeft
👇Query
HUNTER : https://t.co/yFFcJwdIUc="OpenVPN"
📰Refer:https://t.co/V0uS1CclGD
https://t.co/pdoxcCfOcS
#hunterhow #infosec #infosecurity #OSINT #Vulnerability