Excited to share my latest research paper on DigiMesh security best practices, providing practical hardening guidance for deployments across industrial, agricultural, smart cities, and critical infrastructure environments: https://t.co/PTm0kD1iyy
I am starting a new project BoxPwnr, using LLMs to solve HackTheBox machines autonomously 🤖
So far it solves 6 out of 9 of the very easy boxes from Starting Point. https://t.co/VeqFvR9G1v
Just tried Gemini 2.5 Pro on BoxPwnr against all the HackTheBox StartingPoint machines.
It solved 15/25 in one shot!
First time solving Tactics, Bike & Base 🦾🤖
Super interesting how it solved Base, it's the longest exploration I have seen with 112 turns...🧵
CVE-2025-24071> Windows Explorer automatically initiates an SMB authentication request when a .library-ms file is extracted from a .rar archive, leading to NTLM hash disclosure. The user does not need to open or execute the file...
https://t.co/d1myefHndw
Behind the hype, missteps, and marketing buzz, there’s great work with USB Bluetooth (https://t.co/Qw2keYKwBD) and the research that supports it! Congratulations @antonvblanco
Today I'm releasing a new minor version of Monkey365. This new version adds some fixes and a new ruleset (CIS Benchmark 4.0) for Microsoft 365 was added.
https://t.co/ijQcVKZrgx
#azure#EntraID#microsoft365#cloudsecurity
🚀 Introducing binaryninja-ollama-plus!
A fork of the original Binary Ninja Ollama plugin, now with:
• requests replacing ollama for easier integration
• Function explanations
• Basic vulnerability analysis
• Optimized AI interactions
@vector35
🔗 https://t.co/p7RkHP3uj7
I'm thrilled to announce a new release of #Monkey365! This new release contains a lot of improvements and fixes. For example new flags were added to list collectors and CIS benchmarks for both Azure and M365 were updated to 3.0 version. Check it now!
https://t.co/NmbsgNh0Nv
Today I'm releasing a new major version of Monkey365. This new version adds a bunch of fixes and include a lot of new improvements to the core module.
https://t.co/NmbsgNh0Nv
#cloud#azure#azuread#microsoft365#cloudsecurity#compliance
Just published details of 5x SMM vulnerabilities in Insyde Software. The bugs span several SMI handlers including a fun parsing bug when performing a BIOS Guard Update. https://t.co/m44Cqlywve
I reported a SMM TOCTOU vuln to Intel, but unfortunately it was a dupe of an internally discovered issue. Intel's advisory was vague, so I decided to publish my own detailed analysis. Check it out: https://t.co/CMMRWYbDu9
Working on the new version of #Monkey365. There will be a lot of new features like new rules, support for CIS 1.5 benchmarks, bug fixes and much more. Actually using it right now for bug fixes and other improvements.
https://t.co/NmbsgNh0Nv
#Azure#AzureAD#Office365