🥷 Now we can inject a payload into a remote process without using VirtualAllocEx and WriteProcessMemory.
No need to suspend the target process
New technique to evade EDRs:
Github: TwoSevenOneT/InjectSetConsole
#redteam#pentest#antimalware
No BloodHound? No PowerView? Query AD yourself.
SpecterOps posts break down manual LDAP enumeration with dsquery/ldapsearch, covering filters, group nesting, SPNs, UAC bitmasks, trusts, and cross-domain relationships. Know LDAP, know AD.
- https://t.co/psGtvhcKjL
- https://t.co/c4voT6KLud
The X Safety team conducted an investigation into suspected Chinese inauthentic accounts involved in influence operations:
We identified a bot farm of approximately 200,000 accounts. Within this farm, we found 200 accounts posting in a manner that could manipulate a legitimate debate about American AI and energy policy.
These posts contained claims that AI data centers are driving up household electricity prices and straining the grid. Others included AI-generated cartoons that depicted data-center operators enriching themselves at the public's expense.
We remain committed to maintaining an open and authentic platform where people debate topics of public interest. We take seriously any attempts to undermine the integrity of the global town square and suspend accounts that violate our Authenticity policy.
Today’s agenda at Apple Park: Introduce the @Pokemon team to John, talk gaming, and politely ask Pikachu to stay out of the pond. Two out of three were accomplished.
If REs are making 8¢ an hour we’re gonna need cheaper tools…
IDA Home now comes with idalib (MCP ready) and code AIRPORT40 gets you 40% off for the next two weeks (new and returning customers). Duncan buried that at the end of the article 😉
“Security researchers are doomed because of AI.”
I kept hearing versions of this, so I went back through 500 years of people saying the same thing every time a machine learned a human skill.
Some were idiots.
Some were right.
Here’s where I landed. https://t.co/ghFe7ONlOi
My #BHUSA 2026 slides are online!
It was an honor to share our AFD research and how a different perspective led to 30+ Windows kernel vulnerabilities.
Blog post coming soon — check out the slides here:
https://t.co/l8xIaRtL7V
ENDLESSDOORS is prompting action. Zbtlink has suspended sales of affected routers, and Canada has issued a security advisory. VulnCheck CTO Jacob Baines told @Reuters that users should remove affected devices and monitor for compromise. More: https://t.co/VKpNL9FaOD
#Proxmox VE finally supports #ARM64 hardware architecture, now!
It was a long journey and several ones complained about a missing ARM64 hardware support for the native hypervisor.
https://t.co/QOsTU4cejQ