SMB share enumeration via ACLs with NetExec🔥
NetExec now detects share permissions via ACL enumeration, instead of trying to write a file. In addition, we can now detect if a user has indirect access to the share, e.g. by having ACL write permissions!
Made by @PytelJack🚀
This morning I have made public an internal repo on relaying available to everyone. I call it the relay bible. I still have a few more additional tweaks and techniques to add in here but for the most part. It's ready. Hope everyone enjoys my reference.
https://t.co/if08LR2Nwv
[Slides/資料公開] 本日のBSides Tokyo 2026での講演資料です。
TLPT2.0の提案 -「敵を知る」と「自分を知る」の分離
(A Proposal for TLPT 2.0: Decoupling "Knowing the Enemy" from "Knowing Yourself")
https://t.co/KddOdQOrcd
#BSidesTokyo#TLPT#レッドチーム#RedTeam
In my latest blog "Now You See Me: AADGraphActivityLogs" I explore the newly released Azure AD Graph logs and demonstrate how you can detect tools like ROADtools and AADinternals that rely on this API and have been under the radar for defender so far.
https://t.co/TXlkbsqKHa
Join us next Friday, May 8th at 11AM with Elias Bachaalany (@allthingsida) for the next @offby1security stream on, "Automated Reverse Engineering with LibGhidra, GhidraSQL, and AI Agents!
https://t.co/tLrD3qUvEk
We've just released a high fidelity scanner for CVE-2026-41940 (cPanel/WHM authentication bypass). All public PoCs so far lead to false negatives, and are not reliable. @SLCyberSec's research team's notes on this here: https://t.co/7gik0IY4Cl & tool here: https://t.co/RKoB6WaSQk
The Internet is falling down, falling down, falling down
Welcome back to another disaster - this time, an Auth Bypass in cPanel/WHM, tracked as CVE-2026-41940
Enjoy with us..
https://t.co/bOzCPy8iS1
Just presented AirSnitch at Black Hat Asia 2026!
The presentation covered how we could often bypass Wi-Fi client isolation in home and professional access points. This was an awesome collaboration with UC Riverside!
The slides and our NDSS'26 paper are linked below ⬇️