🕵️♂️ Web-Check – OSINT todo-en-uno para webs
IP · DNS · SSL/TLS · Puertos abiertos · Tecnologías · Headers · WAF · Carbon footprint · Malware & Phishing detection y +30 checks más.
Entiende la infraestructura real y protege mejor tu sitio.
#osint#recon#pentest#bugbounty#web
🚨 ¡ÚLTIMA HORA VENEZUELA! 🚨🇻🇪
URGENTE — ¡LO ÚLTIMO! 🇻🇪 🇺🇸
Venevision confirma que Luis Olavarrieta y Shirley Varnagy van a estar encargados de la emisión nocturna de Noticias Venevision.
A partir del lunes 13 de abril a las 7:00pm
Listado de webs que todo programador debería conocer.
Decenas de sitios donde encontrarás:
→ 📰 Noticias
→ 🧠 Ejercicios
→ 📘 Guías
→ 💼 Preparación de entrevistas
→ 🎓 Tutoriales
→ ��️ Blogs
→ 📚 Libros
→ 🛠️ Herramientas
→ 👨💻 Ofertas de trabajo
Y mucho más…
#WebRecon v5 is officially out!
Excited to share a new feature I have implemented in WebRecon Pro that goes beyond basic web scraping. Now extracting and analyzing images with metadata intelligence for deeper reconnaissance insights.
#OSINT#Cybersecurity
Pentesting firms don't want you to see this.
An open-source AI agent just replicated their $50k service.
A "normal" pentest today looks like this:
- $20k-$50k per engagement
- 4-6 weeks of scoping, NDAs, kickoff calls
- A big PDF that's outdated the moment you ship a new feature
Meanwhile, AI agents are quietly starting to perform on-par with human pentester on the stuff that actually matters day-to-day:
↳ Enumerating attack surface
↳ Fuzzing endpoints
↳ Chaining simple vulns into real impact
↳ Producing PoCs and remediation steps developers can actually use
And they do it in hours instead of weeks and at a fraction of the cost.
This approach is actually implemented in Strix, a recently-trending open-source framework (14k+ stars) for AI pentesting agent.
The framework spins up a team of AI "attackers" that probe your web apps, APIs, and code.
It then returns validated findings with exploit evidence, remediation steps, and a full PDF report that looks exactly like what you'd get from a traditional firm, but without a $50k invoice and a month-long wait time.
You can see the full implementation on GitHub and try it yourself.
Just run: `strix --target https: //your-app .com` and you are good to go.
Human red teams aren't disappearing but the routine pentest (pre-launch, post-refactor, quarterly checks) is clearly shifting to AI.
Strix is one of the first tools that makes that shift feel real instead of hypothetical.
I've shared the GitHub repo in the replies.
OSINT 106: Who Owns This Email?
In this video, I made a quick demo using different methodology and tools to build a richer profile of my target email address > advanced search operators > data aggregation > Google > Bing > Yandex, etc.
#OSINT#Cybersecurity
🚨 Ordinary PDFs just became hacker weapons.
A new “MatrixPDF” toolkit turns any file into a phishing lure. Even legit docs now hide fake secure prompts + JS redirects.
One click = stolen creds or malware payload.
Details ↓ https://t.co/uSQfiYtTbZ
#threatsday#cybersecurity