Acabo de crear la lista de reproducción de #Spotify 🎶
Tenéis unas 5h de Electro Funk, Drum & Bass, Dubstep, Glitch-hop y algo de Rock. Y una canción del Kanka para terminar, de gratis 😎
Para hacking o ejercicio 👨🏻💻💪🏻
Ya me diréis qué os parece!
https://t.co/2VJDR9Q4zi
🚨🚨Cyberattack Alert ‼️
🇪🇸Spain - Agencia Tributaria
Qilin hacking group claims to have breached Agencia Tributaria.
According to the attackers, 60 GB of data (238,799 files) have been exfiltrated. Sample have been provided.
Observed: Oct 15, 2025
Status: Unverified claim
Sector: Gov / Mil / LE
Claim observed on a dark web leak site monitored by Hackmanac Team.
—
Hackmanac provides Strategic Cyber Threat Intelligence and our posts are shared for early warning and awareness.
Data derived from open and dark web monitoring, no confidential or leaked material is redistributed.
Full analyses, ESIX metrics, and further insights available on https://t.co/eB7qgxLdpI
Hackers can now hijack Microsoft Domain Controllers into a global DDoS botnet—no malware, no creds, no trace.
At DEF CON, researchers revealed “Win-DDoS”: a flaw that can weaponize tens of thousands of public DCs to flood targets, crash systems, or trigger BSODs—remotely.
Here’s how it works → https://t.co/sME1Y0uofd
Gente, sed amables con los demás.
La inteligencia o los reconocimientos que tengáis no os definen como persona, pero la bondad, empatía y comprensión sí.
Vuestra humanidad se mide en lo que hagáis valer a los demás 🫶🏻
Algunos no lo tienen demasiado claro aún.
Me complace anunciar el lanzamiento de Cybersecurity AI (CAI), un framework open source de agentes autónomos diseñado para abordar escenarios y ejercicios de ciberseguridad.
Junto a este framework, publicamos el paper:
📄:“CAI, a bug bounty-ready Cybersecurity AI”,
🧬: https://t.co/5B9mo23Pwc
una contribución al avance del estado del arte abierto en agentes aplicados a seguridad informática.
pip3 install cai-framework
cai
📊 Resultados destacados de CAI relatados en el paper:
• 🧪 Top 30 en HackTheBox España en <1 semana
• 🤖 Top 1 en agentes de IA del CTF competitivo “AI vs Humans” de HackTheBox
• ⚔️ Máquinas medium y hard resueltas de forma completamente autónoma
• 🧭 Máquinas insane con un mínimo nivel de Human-in-the-Loop
• 🐞 Bug bounties reales completados exitosamente
📚 En el artículo analizamos las capacidades reales de modelos fundacionales (SOTA LLMs) aplicados al pentesting, CTFs competitivos y escenarios ofensivos realistas.
🔗 CAI es un framework multiagente, modular, agnóstico al modelo y que ofrece un SDK de agentes para ciberseguridad, con soporte integrado para:
DeepSeek-V3, Qwen 2.5, LLaMA 3, GPT (3.5/4), Claude (Opus/Sonnet), Gemini, O1/O3… y otros modelos abiertos y propietarios.
🧰 Además, Ofrece una CLI interactiva donde el usuario puede:
• Configurar 🛠️ agentes, herramientas ofensivas, targets y entornos
• Seleccionar modelos 🔄 y patrones agénticos
• Compatibilidad con servidores MCP (Especialmente util en Ghidra y BurpSuite)
• Iniciar, Interrumpir, reconfigurar y retomar el flujo de ejecución de los agentes
Todo bajo una filosofía híbrida: 🧑💻 usabilidad de frameworks clásicos de ciberseguridad + 💬 interfaces conversacionales adaptadas a arquitecturas multiagente, con la IA como núcleo operativo.
🔬 Esta investigación ha sido posible gracias a la colaboración interdisciplinar de investigadores y apasionados en ingeniería inversa, IA generativa, red teaming y automatización.
📌 En breve publicaremos PoCs, tutoriales técnicos.
🔬 Código disponible en: https://t.co/AyTmYvo3cA
Unete a nuestro discord:
https://t.co/T35HhM3fFF
Mención especial: @vmayoralv@francisco_oca
A Serbian student protester's Android phone was targeted by a zero-day exploit from Cellebrite, exploiting vulnerabilities in USB drivers to bypass security and unlock the device.
Read the full article to uncover how this exploit was used: https://t.co/dQ3vNxuuo9
T-Mobile confirms being targeted in a Chinese cyber espionage campaign alongside AT&T, Verizon, and others.
Salt Typhoon attack seeks sensitive communications from high-value targets.
Full analysis of this growing threat here: https://t.co/LicCJL9I0Y
#CyberSecurity#Infosec
It's being reported that the CEO of Microsoft, Satya Nadella, is receiving a 63% pay raise. This will make his total compensation be a remarkable $73,000,000 annually.
This comes after dozens of Microsoft security oopsies and layoffs.
Very cool
🔔 Update: The Tor Project has issued an emergency update (v13.5.7) to address CVE-2024-9680, a Firefox flaw currently under active exploitation, reportedly targeting Tor Browser users.
https://t.co/yrjDacbcWK
It may allow control of the browser but likely won't affect Tails' anonymity.
Pro tip for hackers who accidentally get IP banned by Akamai or Cloudflare on their home IP:
Many ISPs will requisition a new public IP if they detect new network hardware installed in a house. If you get banned, unplug your cable or DSL modem.
Then go into your router settings and change the MAC address of your router. Most routers allow you to either change or clone to a different MAC address.
Then plug in your cable modem and enjoy your new IP!
New supply chain attack, Revival Hijack, could target 22,000+ PyPI packages, risking thousands of malicious downloads. Removed packages are being re-registered, exposing developers to supply chain risks. Check your #DevOps pipelines!
https://t.co/XX7TOObuJh
#cybersecurity
Seems to be some confusion with some about the announcement of the OSCP+. Mostly around what happens to the OSCP?
Let's be clear - The OSCP does not expire. Will not expire. And will still be issued. No changes to the OSCP are being made.
However there are a number of cert holders that work places that mandate a certification to expire. The current OSCP does not help these individuals at all. So, enter the OSCP+, which was created to provide benefits to these users and does expire.
If you are not in a situation where you require an expiring certification, thats great. Nothing changes for you, you can ignore the OSCP+.
If you do require an expiring cert, then starting Nov 1st the OSCP+ will help you out.
We set this up in a way where we are careful not to take anything away from existing cert holders or those that do not require an expiring cert. This should be fully an expansion of benefits, with nothing taken away.
Full details of the changes that were announced today are at:
https://t.co/1ntoPjnAMf
https://t.co/bMIv0gBPZi
Also we will be doing a webinar the morning of the 6th, and standard office hours on discord at 1pm eastern. Happy to talk through questions with everyone then! - Jim