I recently tore apart SuperBox streaming devices and found that "free TV" has a serious catch. Our new report breaks down how these boxes are weaponized into residential proxies via exposed ADB ports, root access & rogue apps bundling Popanet. https://t.co/hYol0WefLq
Anyone interested in what you need for proper loader development in 2026? My talk for @x33fcon was accepted, so I'll take about Malware again. 🔥 It's a unique talk and will only be held there this year! Hope to see some of you in Poland. 😎
I often need to explore Windows kernel crashdumps when I'm on Linux/macOS.
WinDbg unfortunatelly doesn't work in Wine.
So... I did a thing. It's multiplatform - doesn't depend on dbgeng.dll nor DIA. WinDbg-flavored.
And it's fast. Really fast.
https://t.co/sd44mJo9ax
Highly recommend reading this if you're into windows kernel vuln research!
Juian found some cool vulns using this technique -which we can't publish :/ -
Something new is also coming out for pypykatz bc of this in the upcoming months
Finally, it is published 😁 Making Vulnerable Drivers Exploitable Without Hardware - my latest research on driver vulnerability hardware-gating, explaining the concept of hardware-dependent code and diving deep into creative deployment techniques - software-emulated phantom devices, driver restacking, and forced driver replacement — all explored through the lens of Bring Your Own Vulnerable Driver (BYOVD) attacks:
https://t.co/COJ0BKpZQe
Just pushed a minor update to #mimikatz 2 🥝(no - it's *NOT* the version 3) to support specific GMSA DPAPI passwords in LSA secrets to be able to to decrypt Masterkeys
> https://t.co/UNUIxSOhtS
Only for @topotam77 convenience ;)
New Mimikatz
Researchers took an old version of Mimikatz and taught it how to dump credentials from the latest operating systems!
The research: https://t.co/JxZwg135Mr
The repo:
https://t.co/Lpsu09AMng
#redteam#pentesting
@UK_Daniel_Card pypykatz had this logic implemented since last year, most of this article is just porting that logic to mimikatz... without mentioning me. Again.
At this point this is a running joke that I'm getting 0 fucking kudos either deliberately or by "forgetting"
@abdo_mhanni@lowercase_drm@0x64616e Nah man, don't try to make my projects mainstream. After the fifth time I'm sure they'll get it right and they won't have to credit me again...
Ohh... you have reached the API limits, so we replaced your coder with a mental patient who will use half a crayon to randomly change values in your code. (he already ate the other helf)
Research workflow:
1. Idea
2. discussions with peers
3. chatting with LLMs
4. feasibility check
5. Airbus guys already did that 5 years ago
I'm.... eeehhhh....
(Airbus people doing some really underrated research btw, props to them!)