I am very pleased to announce the official author team for the 7th edition of Gray Hat Hacking through @MHEducation. The book will be published in mid-2027.
Join me in welcoming: @chompie1337, @natashenka, @zodiacon, @ale_sp_brazil, @gf_256 to the team, along with 6th ed. authors @mosesrenegade & @htejeda!
A big thanks to @allenharper for carrying the book since the First Edition, as well as all authors across all editions.
Note: This is a mock up cover
On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
The recording of "Deobfuscation in the Age of Agentic Reverse Engineering" is now public:
https://t.co/jMO0GHRM8l
We (CC @nicolodev) show how to use agents to break protections found in anti-cheats, DRM systems & commercial protectors.
Slides: https://t.co/Fz2DhU2RlT
Series on Android SELinux internals (@8kSec)
Part 1: https://t.co/r8RhF2WIhE
Part 2: https://t.co/57bpqR5IgM
Part 3: https://t.co/SOOqLt0Xdq
Part 4: https://t.co/7DcJeMuol5
#infosec
Supply chain security has no shared vocabulary.
Every vendor in their own silo. Every attack is described in different terms.
No central record.
No coordination.
We proposed SCINTX to the Eclipse Foundation as a starting point 🧵
Supply chain security has no shared vocabulary.
Every vendor in their own silo. Every attack is described in different terms.
No central record.
No coordination.
We proposed SCINTX to the Eclipse Foundation as a starting point 🧵
We are pleased to release tmp.0ut 5 Volume!
Get your viruses, rootkits, strange ELFs, weird machines, tiny files, cool art, and phresh beats here!!
https://t.co/tZLM50HOc0
Want to run an entire Tailscale daemon from memory inside a C2 implant with zero disk artifacts, no kernel drivers, traffic indistinguishable from HTTPS to a CDN, and relay connections from the victim network back through the tailnet.
Now you can. Enjoy!
https://t.co/WmBlShAnLr
New exploit: “xor dword [0xf80c2094], 1<<22”
Unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register, all at once, on 100 million AMD CPUs. As far as I can tell can’t be fixed.
https://t.co/sgAfneFSsf
A hands-on walkthrough of exploiting a Windows stack buffer overflow and bypassing DEP using a manually crafted ROP chain, leveraging VirtualAlloc to prepare executable memory and building the entire chain from scratch without relying on Mona.
Blog:- https://t.co/CzFyUXIsln
if you’ve been on either side of a bug bounty you know the joy in it is gone now. it’s just AI reports coming in, AI patches going out, and decreasing human understanding of either. i wonder what is left of the security industry once the fun clever hacking parts are all outsourced to AI.