I've released Puzzle, a research project on deploying malware in monitored environments by abusing Windows minifilters functionality. It includes several utilities and PoCs to interact with minifilters and explore static and runtime analysis evasion 👐
https://t.co/8zWv1g8n79
No te puedes perder a nuestro siguiente ponente, Kurosh Dabbagh, y su charla "Minifilters: Owning the High (and Low) Ground" en la próxima EuskalHack Security Congress IX @_Kudaes_#ESCIX https://t.co/OGqYWOLVsP
Microsoft has addressed a one-click NTLM leak vulnerability affecting Windows Snipping Tool (CVE-2026-33829), discovered by our researcher Marcos Díaz (@Calvaruga).
➡️ Read the write-up: https://t.co/JvMGad5NuI
➡️ Microsoft bulletin: https://t.co/0IbpRxxUY7
@eldpit Siento mucho leer esto, mucho ánimo Rubén. NN es sin duda uno de los mejores congresos a nivel nacional, espero que se pueda restablecer el orden pronto.
Can LNK files ever be trusted?
⚡ My latest blog post demonstrates several new LNK abuse methods, allowing you to fully spoof the target shown in Explorer. It also introduces tools to create your own LNKs, and detected spoofed ones yourself.
🐬 https://t.co/VZYVaEfO07
Hi! I just published a technical deep dive into a complex and fun N-day vulnerability that allows to get RCE in a very popular e-commerce platform.
Check it out!
https://t.co/DaZX3R6ob4
Tangled is a social engineering platform that weaponizes calendar event processing in Outlook and Gmail to deliver spoofed meeting invites that are automatically added to a user's calendar without interaction.
https://t.co/vz4ulB2SL3
Technical breakdown: https://t.co/0Z0LH8hjdM
Meetings You Didn’t Plan, But We Did
In this post, @ineesdv breaks down how calendar event processing in Outlook and Gmail can be abused to deliver spoofed meeting invites that are automatically added to a user's calendar without interaction
➡️Read more: https://t.co/7RApljHair
[RELEASE] As promised, I’m releasing the first blog post in a series. It covers the gaps still present in current stack-based telemetry and how Moonwalking can be extended to evade detection logic and reach “on-exec” memory encryption.
Enjoy ;)
https://t.co/4Yf28y7cT4
This Thursday, our colleague @_Kudaes_ will be at @NavajaNegra_AB presenting Activation Context Hijack: a new code execution technique for Windows environments.
➡️ More info: https://t.co/KLCb6lWNDw
I just released MFTool, an NTFS parser that builds an in-memory map of a volume, allowing you to:
- Read any file without opening a handle
- Get the contents of locked/deleted files (registry hives, pagefile.sys, etc)
- Perform fast, in-memory searches across the entire disk
🔗👇