⚠️ JUST IN: @zachxbt Posts a full investigation on notorious fraudster Tiffany (@fraud)
He's linked her to over $5M in crypto theft through fake hardware-wallet and exchange support scams
She recorded calls with victims and even taunted some after their funds were stolen. Previous posts show her flaunting luxury purchases and gambling.
You don't need a USB. You need to look like one.
Emulate the device, Windows fetches a signed package off Windows Update and runs vendor code as SYSTEM. Arbitrary code execution, LPE, standard user or empty logon screen.
DEF CON 34 talk w/ @Qm9yamFN.
Link at the first comment.
Big week for Proxmark5.
The GitHub PR for the Proxmark5 firmware lands this week.
If you ordered the black case, good news: we are fulfilling all black case orders first, both pre-DEF CON and post-DEF CON. Production is running at 400 units a day. 1600 units have already shipped as of today. Most backers will have tracking numbers this week heading into DEF CON.
This is really happening.
Build an MCP for NetExec for small and large models. The AI agent interacts with NetExec, while the user focuses on the path of compromise 🔥
https://t.co/jATLBc5BNU
Back from mission, I released the exploit I used (it was really helpful) for #Apache Tika XFA XXE exposed through #Elasticsearch’s attachment ingest processor, leading to arbitrary file read: CVE-2025-54988 / CVE-2025-66516
- Python PoC
- version-aware Metasploit module
(loot storage, automatic cleanup + no index or document creation)
https://t.co/3W6qUhPixi
@metasploit PR done:
https://t.co/FtwHNnASi5
This seems handy.
Windows agent in Powershell 5.1 that loads C# in memory. No admin needed.
Linux server (Go)
--route 10.10.10.0/24
--redirect
Then you can use (TCP) tools like nxc, nmap, impacket etc for for the set range without proxyxhains.
Also supports DNS.
Please RT for reach.
If anyone knows @I_Am_Jakoby IRL, can they please reach out? I don't know them or I would, but they seem to be in distress.
https://t.co/b2rGKL8wyA
Zero files written to disk. @ccelikanil and Emre Odaman built DFMI, an open-source toolkit that hijacks the Windows Installer's own execution engine to detonate payloads during software installation. Fileless, cross-platform, and slick. 💻
New File Format for Initial Access???. "PPKG" files, had a hard time bringing some of the old XML schema for building these properly but finally got execution!!, These run with high privileges by default so the UAC prompt is shown and a good pretext is still needed but these files are NOT in the block list for Outlook. Also thanks to Pearce as well I had no knowledge of ppkg files and how they worked or what they did some great stuff going offline with web_search capabilities of course.
#redteam
Device code phishing is quietly becoming one of the more effective techniques targeting #M365 environments. In our latest #blog, Lumi Taiwo and Danny Dubree detail how it works and the #ConditionalAccess controls that shut it down. Read it now! https://t.co/eMk45P56cQ
Well, I think I can remove the crypto addresses from @haveibeenpwned’s donation page. This is an impossible requirement from the Aus gov, looks like back to PayPal only 🤷♂️