In his latest research, @_xpn_ tears apart VS Code Dev Tunnels and finds a C2 framework underneath — REST → WebSocket → SSH → MsgPack RPC, remote exec, file ops.
Find the Ouroboros tool and protocol breakdown at the link! 👇 https://t.co/U75Ynzr8Sw
We used Claude to discover CVE-2026-34197, a remote code execution vulnerability affecting the #Apache#ActiveMQ Classic web console. This is exploitable with default creds or completely unauthenticated for certain versions.
https://t.co/C1uKzMCrM8
My BlueHammer version ( now redhammer) implements my VDM version patch, deploys and loads the BYOVD for my exploitkit.
It bypasses the new signature for BlueHammer aswell. How is this still unpatched?
A tool for enumerating SharePoint via Microsoft Graph. It recursively downloads files and logs every HTTP request for correlation with SIEM and development of detection rules
https://t.co/mQOYuVgEtD
#blueteam#redteam#pentesting#windows
🛠️ Rustunnel - a open-source tunnel service written in Rust that replicates the core functionality of ngrok.
✅ It exposes local services running behind NAT/firewalls to the public internet through a relay server self-hosted or our managed service. https://t.co/2NC7fy2mt8
Collecting ADCS data with NetExec🔥
Thanks to the addition of CertiHound, developed and implemented by 0x0Trace, we can now collect ADCS data using the --bloodhound collector of NetExec.
As before, the data is exported as JSON files that can be imported directly into BloodHound.
RegPhantom a signed Windows kernel rootkit that turns the registry into a covert execution channel.
Gives the ability to an unprivileged usermode to reflectively load an arbitrary PE into kernel memory, invisible to PsLoadedModuleList and standard driver enumeration tools.
The implant includes several stealth techniques:
- Post-execution memory wipe
- XOR-encoded hook pointers in-memory obfuscation
- Valid code-signing certificates
- CFG obfuscation with opaque predicates
- 28+ samples tracked (June–August 2025), signed with certificates from two Chinese companies.
We're releasing:
- Full technical writeup
- Extensive deobfuscation scripts
- YARA detection rule
Full analysis: https://t.co/cMWxkoaI0p
#MalwareAnalysis #Rootkit #ThreatIntel #DFIR #Windows #KernelDriver
We just open sourced our AI vulnerability scanner 🔥
👉 https://t.co/mhf6TdiJMC
Built for the reality that GenAI security isn’t static:
• jailbreaks & prompt injections evolve weekly
• agents introduce new attack surfaces
• most issues aren’t caught until prod
The scanner:
continuously probes models with real-world attacks
tracks vulnerabilities across LLMs + agents turns findings into repeatable security tests
Powered by the same pipeline behind 0DIN’s bug bounty + threat intel feed.
If you're building with AI, you need adversarial testing not just evals.
PRs welcome.
Payload Development & Evasion Engineering Map
70 technique cards across 16 categories covering the full payload lifecycle from shellcode generation through delivery. 20 attack flow chains showing real-world operator workflows like Node.js Sideload → DLL Hijack, BYOVD EDR Blinding → Kernel R/W, WASM HTML Smuggling → MOTW Bypass, and Polyglot LNK → ZIP Sideload. Dedicated EDR-specific evasion profiles for CrowdStrike, Defender, SentinelOne, Cortex XDR, Elastic, and ESET — covering what each product actually hooks, where the detection gaps are, and what triggers memory scans. 100+ tools catalogued across shellcode loaders, injection frameworks, obfuscation, and testing pipelines.
https://t.co/Ly63orEMTG
#CyberSecurity #RedTeam #MalwareDevelopment #EDREvasion #OffensiveSecurity
I published a Sharepoint and Outlook PowerShell GUI that can be used on RedTeam operation when you've found an Azure AppId with interesting privileges.
You can now use these tools to browse the SharePoint or Mailboxes through a GUI instead the GraphAPI
https://t.co/V80HUxIHEs
Hi friends! We'd like to share our nxc module, https://t.co/HfNCTbM71e, with you. It allows u to find tdata sessions on computers and copy them locally. U can then take the tdata session and steal telegram account.
https://t.co/RvXlCyreIx