@MDSecLabs will be running our Red Team Capability Training out in #BlackHatUSA26 again this year. This year the course features a big refresh, with a bunch of new additions on the latest evolving techniques!
Early bird discounts end this month! @BlackHatEvents
https://t.co/l3uAga4TS5
OAIC's CFP is now open!
The first conference dedicated to the cutting edge of the offensive use of AI is returning for its second year. Speakers will enjoy three nights at a four-star beachfront resort, which includes all meals and drinks, three exclusive parties, and a Michelin-star welcome dinner.
Please see https://t.co/Q6XUblStJb for accepted topics.
#ESETresearch released its latest APT Activity Report (Oct 2025–Mar 2026): 🇨🇳China-aligned groups focused on Venezuela, Gulf states, and AI & robotics industry in 🇰🇷South Korea, while 🇰🇵North Korea-aligned APTs targeted the nuclear sector. Full report: https://t.co/5Dzgqwuz9q
We're looking for a cover for the next issue of Phrack!
Retro sci-fi, terminals, dystopian systems, chrome futures, hacker manuals from an alternate timeline.
Make something timeless and strange.
Send your work or idea to [email protected]
Deadline June 30th
Not long after the 9/11 terrorist attacks MSRC published “It’s time to end information anarchy”. It was one step short of labeling security researchers terrorists. The essay was not well received by industry _at all_ and triggered a sea change at MS, ushering in a new era. 1/2
Tax in the UK is the highest it’s been since 1945. That’s well understood – but another trend has been largely missed: the number of taxes in the UK is at its highest since the end of the Napoleonic Wars.
A bunch of ppl complained about ethics of bug hoarding, saying we should report to MSRC etc when we mentioned we hold on to 0days to use during RT ops in https://t.co/7T98Dh0CIx
How the tables have turned 😂
Build better detections without heavy overhead.
- Around 20 high-order detections for Windows and Entra ID
- AiTM, Entra ID token theft, and stolen token abuse detection
- Full attack-chain labs with realistic false positives
- Vendor-agnostic logic adaptable across platforms
I don’t know who needs to hear this but your research is your IP not the vendors IP. You can do whatever you want with that IP. Reporting it, publishing it, selling it to a third party or putting it in a box under your bed 🙄