‼️ After the MSRC blog post about Nightmare-Eclipse, researchers are coming forward with their own MSRC horror stories.
The response from the security community isn't going Microsoft's way. As they’re not backing Microsoft.
Gabriel Landau, a well-known Windows security researcher, says he reported a Device Guard bypass with a 90-day window. MSRC told him it met their bar and they'd fix it, then asked him to hold disclosure for extra months. He agreed on the condition they issue a CVE. They patched it silently, decided after the fact it "didn't meet the bar," and never issued the CVE. In his words: "MSRC strung me along for a few extra months to keep me quiet, then broke their word."
Another researcher, rootsecdev, says he responsibly disclosed a legacy-auth flaw that allowed password spraying while avoiding smart lockout. Five months later, MSRC replied that it "doesn't meet the bar for servicing," silently fixed it, and closed the case.
Microsoft's post was meant to defend their coordinated disclosure policy. Instead it became a thread of researchers explaining why they've stopped trusting their process.
I just released ProtoPoke.
It’s a TCP/UDP/SOCKS5 proxy for protocol analysis: intercept and modify traffic live, replay sessions, fuzz with pluggable mutators, and control it all with an AI assistant via MCP.
https://t.co/QToXKSSkds
@Void_Sec I agree with your article but I think it focuses only on security research. One aspect of LLM is the possibility to automate part of pentests which is quite interesting.
Former BlackHat board member Vincenzo Iozzo, and co-author of iOS Hacker's Handbook, had a relationship with Jeffrey Epstein.
It appears Epstein attended DEFCON and/or BlackHat in 2013 and 2015, possibly 2016.
If you’re doing security testing and not bookmarking this, you’re missing out 👀
PayloadsAllTheThings has a clean web version 👇
https://t.co/9S5AkbdmYU
#bugbounty#infosec
🎄 XMAS GIVEAWAY ALERT! 🎅✨
🎉🔥 To celebrate the holiday season, we’re giving away TWO 12-month FREE vouchers for any of our premium courses:
▪️ Practical Mobile Application Exploitation
▪️ Offensive Mobile Reversing and Exploitation
▪️ Offensive iOS Internals
▪️ Offensive Android Internals
▪️ Practical AI Security: Attacks, Defenses, and Applications
How to participate:
➊ Like 👍 this post
➋ Comment which course you’d like to win and tag one friend. If you win, both of you get FREE access!
➌ Repost 🔁
➍ Follow @8kSec so we can DM you if you win
�� Two random winners will be selected and announced on December 24, 2025, on our socials. Both the winner and their tagged friend will receive FREE access to the selected course.
🔗 Learn more about our courses: https://t.co/lWUydt1GpC
🚨 Calling all speakers, hackers, and storytellers.
Our old account got banned, but we are back and stronger.
Got a talk brewing for 2025 or 2026?
Submit your CFP on https://t.co/Uj0KYQUpBq and get discovered.
The community is waiting. 🔥
#cfp#infosec#security#hacking
🚨 Hiring Alert – Red Team in France! 🚨
We are looking for 2 new teammates to join us:
🔹 Paris-based (up to 3 days/week remote)
🔹 English/French speaking
👉 Apply here: https://t.co/k2wgS1iWqa
💬 DM me if you’re interested or want more info!