GitLab has apparently taken down the Nightmare-Eclipse account just days after the researcher moved there following the GitHub ban.
The drama started after Nightmare-Eclipse released several Windows exploits and Defender bypass tools, including BlueHammer, RedSun, and UnDefend. GitHub removed the account earlier this week over concerns that the tools could be misused and weaponized.
Security company Huntress says some of the tools have already been seen in real-world intrusion cases, showing how quickly proof-of-concept research can end up being used in actual attacks.
CVE-2026-26215 - Unauthenticated RCE in manga-image-translator (9.3k stars)
Two FastAPI endpoints call pickle.loads() on raw HTTP bodies. Auth exists but defaults to an empty string, which is falsy in Python, so the check never runs.
First reported by sud0why in May 2025, auto-closed by a stale bot. Still unpatched.
https://t.co/Qz4hphqkfN
This is more than a session; itโs a front-row seat to real pro hacking techniques!
Save the Dates:
30th August โ Mallam Challenge https://t.co/6PV2k5Jfqk
6th September โ Ifowosowopo Challenge
https://t.co/l1FAlAsEQq
Donโt miss out. Come. Learn. Level up.
#AfriHackBox#CTF
Hello guys,
I've already talked about WPProbe, my tool to fingerprint WordPress through its REST API.
This time, I'm sharing some behind-the-scenes: the idea behind it, and a few struggles I had along the way.
Not that complex, but worth the effort.
๐ https://t.co/vdQgsuBWBO
๐จ [CVE-2024-56145] Exploit released! ๐จ
Iโve successfully reproduced the Craft CMS RCE vulnerability, thanks to the outstanding research by @Assetnote.
Details, PoC, and setup instructions:
๐ https://t.co/0866MkkJrv
Learn more:
๐ https://t.co/gZfcFNcesd
๐ Huge thanks to Assetnote for this amazing work! ๐