The monkey is still curious 🐒 Teleboy has topped up its bug bounty program with another CHF 10'000 in rewards. Explore a platform serving 400'000+ users across TV, internet, and telephony. Ready for another hunt? #bugbounty#ethicalhacking#cybersecurity
https://t.co/oXuB0Xld85
🦖 Meet RAPTR: our new open source platform for red and purple team collaboration. Plan engagements, document attacks and detections, evaluate results, and generate reports, all API-driven. Beta is live, feedback welcome! #PurpleTeam
https://t.co/GyXw40nN2p
The final part of our Entra ID blog series looks at common Conditional Access weaknesses, practical attack scenarios, and how to identify such issues with EntraFalcon.
https://t.co/vx43hX6mDj
🏃♂️Time for a security workout. Sanitas is launching its #bugbounty program and inviting ethical hackers to help keep its digital healthcare services in peak condition.
Hunt vulnerabilities and help protect critical healthcare systems: https://t.co/6qUcSQJd9J
Foreign enterprise apps can expose your Entra ID tenant. Today, we release part 1 of our 4-part weekly series on common Entra ID pitfalls and how to detect them with EntraFalcon. Learn how external apps can lead to data access or worse: https://t.co/kwMWrC4tKA
Unprotected groups in Entra ID can lead to privilege escalation.
Part 2 of our 4-part series shows how weakly protected groups can be abused to bypass controls, gain privileged access, and lead to full compromise—and how to detect this with EntraFalcon: https://t.co/gnAgcDzoEQ
EntraFalcon update 🚀 The new Security Findings Report turns Entra ID enumeration into actionable findings with 60+ checks and color charts. Read the blog post of Chrigi @ZH938472 and try the tool now on your tenant! https://t.co/07gzDox92b
#EntraID#CloudSecurity#EntraFalcon
WinGet can be more than a package manager. We show how .winget configs + a self-referencing LNK become a viable initial access payload when Microsoft Store is enabled. Includes detection queries & mitigation tips.
https://t.co/1MLtOjzfaU
#RedTeam#Windows#LOLBins#InitialAccess
John Ostrowski (Compass Security) and Manuel Kiesel (Cyllective AG) worked together on CVE-2025-13154, a Lenovo Vantage LPE. Even after Microsoft closed a known primitive, collaboration led to a working PoC.
https://t.co/vunXyr408d
#Windows#CVE#SecurityResearch#PrivEsc
In a new video, Nicolò Fornari walks through how to fuzz with AFL++, how to pick targets, avoid common pitfalls, and boost effectiveness. Find performance tips, fuzzing theory, and AFL++ internals. https://t.co/S21LcYIUJZ
#security#fuzzing#AFLplusplus#appsec
NTLM relay works against HTTPS if channel binding is missing. Our new blog post explains why, shows how tooling evolved, and highlights defensive measures.
https://t.co/gXcsZZ01oP
Learn about a FortiProxy Domain Fronting Protection bypass discovered by our analyst @emanuelduss . Details in the advisory: https://t.co/aO2913oKxj
Curious how web filters are evaded? Read his blog series: https://t.co/4DcLNl7BBq
#cve#pentest#bypass
The leaked LockBit chats give a rare inside look at ransomware ops.
Read our blog for an analysis and lessons for defenders: https://t.co/5BmoOSvfyn
#CyberSecurity#Ransomware#LockBit
NIS2 means stricter rules and steep fines.
Penetration testing is key to proving compliance & improving security, uncovering flaws before attackers do.
Our latest blog explains why you need it now: https://t.co/aojDd78IFN
#CyberSecurity#NIS2#Pentesting
The final episode of our Kerberos deep dive is live!
RBCD opens new attack paths in Kerberos. Learn how misconfigs enable privilege escalation and how to defend.
https://t.co/IvZtdcF4ea
#Kerberos#ActiveDirectory
Episode 5 of our Kerberos deep dive is live.
Constrained delegation isn’t bulletproof. See how attackers exploit it, and how to defend with monitoring & best practices.
https://t.co/wIqDBT5gnH
#Kerberos#ActiveDirectory
Episode 4 of our Kerberos deep dive is live.
Unconstrained delegation can expose critical credentials. Learn how attackers abuse it. And how to lock down your systems.
https://t.co/4X6x5eH9Xw
#Kerberos#ActiveDirectory
Episode 3 of our Kerberos deep dive is live. AS-REP Roasting abuses accounts without pre-auth. Learn the risks, how attackers exploit it, and how to defend.
https://t.co/BMxG2PQIEg
#Kerberos#ActiveDirectory
We use James Kettle’s (@albinowax) Burp extension Collaborator Everywhere daily. Now our upgrades are in v2: customizable payloads, storage, visibility. Perfect for OOB bugs like SSRF.
Find out more here: https://t.co/HhGUYrJNvQ
#AppSec#BurpSuite#Pentesting
Episode 2 of our Kerberos deep dive is live.
Kerberoasting lets attackers steal AD service account credentials. See how it works and how to protect your systems: https://t.co/FW4p9srPxQ
#Kerberos#ActiveDirectory