Recent supply chain attacks have demonstrated that the most valuable targets are developers 🧑💻
In this new blog post, I'll walk you through the full setup of a phishing attack 🎣 (ab)using GitHub OAuth App to gain control over an account! Trusted domains, free infrastructure, social engineering tricks, ...
🌐 https://t.co/6zFxAUemy6
P.S: I've updated the blog design ✨, hope you enjoy it
One bit flip to corrupt it all:
Exploitation of an old Linux kernel vulnerability using PageJack, a modern technique to create Use After Free bugs.
Here @AzazheI shows you how
https://t.co/MLKX0pykhe
#Zer0Con2026 - SPEAKER 🌐
Mathieu Farrell(@Coiffeur0x90) from Quarkslab - “Breaking the Backbone of Global ISP Networks”
For more: https://t.co/15bGQDgjGc
Another antivirus 🛡️, another unfulfilled promise 😣. @kaluche_ turns Avira's protection into a privilege escalation playground. 3 LPE vectors via symlink abuse (CVE-2026-27748, CVE-2026-27750) and unsafe deserialization (CVE-2026-27749).
Find out more: https://t.co/uVzyUWCjzh
Excellent research on why macOS antivirus solutions should not blindly trust Process IDs.
👉 https://t.co/YjGvRsmNuV
Shoutout to the Mathieu Farrell for the solid work.
🥳 ProxyBlob V2 is now available 🎉
As promised, here is the new version of ProxyBlob, boosted with aznet. Az-what 🤔?
This version introduces a new Go module called aznet that allows you to use Azure storage services (not just blobs 😏) as a direct replacement for net.Conn!
🏎️https://t.co/AZDniVnzGY
🌐https://t.co/BkczwWO1xi
Complete documentation is available in the aznet repo to understand how it works 📚
BYOVD is a well-known technique commonly used by threat actors to kill EDR 🔪
However, with the right primitives, you can do much more.
Find out how Luis Casvella found and exploited 4 vulns (CVE-2025-8061) in a signed Lenovo driver.
👇
https://t.co/yKVfTYi61L
🚨 Open to work — AI Security/ red team / adversary sim
8+ yrs in offensive sec, ex-Cobalt Strike, SANS instructor (12 w/y)
Looking for flexible, senior/principal roles w/ impact > hours
DMs open or connect via: https://t.co/H3zhFxV2hB
ProxyBlob is alive ! We’ve open-sourced our stealthy reverse SOCKS proxy over Azure Blob Storage that can help you operate in restricted environments 🔒
🌐 https://t.co/KO4AYUDTmb
Blog post for more details right below ⬇️
From classic HTML pages to advanced MFA bypasses, dive in with @_atsika in an exploration of phishing techniques 🎣.
Learn some infrastructure tricks and delivery methods to bypass common detection.
👉https://t.co/zkhi1RxnDk
(promise this one is legit 👀)
Say hi to Docs: end-to-end encrypted collaborative document editing in Proton Drive
✍️ Create, edit, and share documents securely
🤝 Collaborate in real-time with live cursors, presence indicators, and comments
↕️ Import/export with ease
1 / 2
POC for #SilverPotato utilizing Kerberos relay vs SMB ;) Starting from @cube0x0 great krbrelay tool with extra layer of complexity to get the SilverPotato beast working.. Still in the rough but will publish soon :-)