Ok. They’ve pissed me off.
I’m back to tell you 3 things about ID cards:
1. Migrants ALREADY HAVE biometric ID cards & govts have been trying to digitise them for years w repeated fuckups & failures causing complete chaos - they don’t work, you do not want that system for you.
When asked if they wanted to approve a social engineering email before we send, an amazing client gave this response:
"The bad guys don't give us review rights"
This is the way. 🏆
Ready to master covert entry like a pro? 🔑 Join us at #x33fcon for an awesome 3-day training - hands-on lockpicking, RFID cloning & more hands-on action with @babakjavadi, @Tatramaco and Jiří Vánek!
💻 Learn more: https://t.co/1JAecUhUMh and sign up at https://t.co/lNL90vrFaD
Let’s unlock some fun together! 😄🔓
#CyberSecurity #SkillUp #training #RedTeam
What's that, you have a talk or workshop you would like to submit to Sheffield's best security conference happening between July 11 and 13 2025? Well, you are in luck, our CFP has just opened, throw your details in here:
https://t.co/sWm1WnlynO
Any questions, just ask.
A little while ago I tweeted about a potential BOF-PE design. So here it is, a new design that includes a fully linked PE, C++ exceptions and use of the STL template library.
We're not irrational, but this Pi Day Sale definitely is!
31.4% off EVERYTHING for 31.4 hours. Stock up on all your favorites before time runs out. Code: ENJOYTHEPI at https://t.co/pZ24h5ou08.
Attacks against AD CS are de rigueur these days, but sometimes a working attack doesn’t work somewhere else, and the inscrutable error messages are no help. Jacques replicated the most infuriating and explains what’s happening under the hood in this post https://t.co/eF5nhHfPuS
[BLOG]
I had a series in mind like "Rubeus' Hidden Secrets" or something like that. Basically, highlighting features of the tool that seem less well known. I'm starting off with a basic one for getting crackable hashes from cached service tickets.
https://t.co/IBbBzLVxtH
#DSInternals 5.0 is out. Supports recovery of BitLocker keys, LAPS passwords, DNS zone files, contact information, organizational structure, and OS versions from #ActiveDirectory ntds.dit files. Includes some performance improvements as well. Examples: https://t.co/zOPzVv6c3x
After yesterday's events in the White House, Haltbakk Bunkers, one of Norway's largest marine fuel companies, appears to have announced that it will no longer refuel American Navy vessels.
Haltbakk has called on other European companies to refuse service to American forces.
I'm going to kick a hornet's nest... but I think it needs done.
Some of y'all owe @defcon an appology.
I remember how rabid folks were about Chris Hagnagy's expulsion and "wanted the truth out there"
Well... it is now... and it's fugly.
https://t.co/NbongXnI7J
1
I see we're doing the quarterly open source tools/research debate again. I'll just say this:
Phishing got much harder when @mrgretzky released evilnginx
AD got more secure after @SpecterOps released Certified Pre-Owned
AD got more secure when @TimMedin showed us kerberoasting
This speech is full of half-truths, distortions, misleading claims and outright lies.
Basically living up to every meme, trope and unfair stereotype, of Americans being ignorant morons.
I'll go through each of the claims he made in this segment and what the actual facts are. /1
Crazy it’s 2025 and Device Code Phishing is still going strong and is a trending TTP used by threat actors.
@knavesec and I recently did a Device Code Phishing campaign to dump the company directory which fueled a successful malware Vishing campaign.
Device code phishing has gotten harder, Microsoft email is good at detecting it now, but those protections don’t exist when the phish is delivered by text or voice. We have noticed they added additional warning prompts when the user enters the code as well, but that hasn’t prevented anyone from doing it unfortunately. We’ve also noticed some clients preventing the attack by disabling device code authentication in the tenant or by using strict conditional access policies to prevent authentications, which is good to see.