Hacking into modems: 30+ vulnerabilities in devices used in homes, ATMs, buses, and critical infrastructure. ☎️🌐👨🏻💻💡🍟
More details on:
LinkedIn: https://t.co/M4C4d1GUSa
Substack: https://t.co/m9BTLjtsgZ
Every Entra ID assessment ends here: “How do I get a token without triggering Conditional Access controls?” 🤔
@rbnroot built CAPSlock, an offline ROADrecon-based Conditional Access engine that simulates sign-ins & flags gaps without touching the tenant. https://t.co/MRogABIkL2
NTLM relays failing because of EPA? 😒
@zyn3rgy & @Tw1sm break down how to enumerate EPA settings across more protocols + drop new tooling (RelayInformer) to make relays predictable.
Check out their blog for more: https://t.co/RrTww92lNO
Credential Guard was supposed to end credential dumping. It didn't.
@bytewreck just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled.
Read for more ⤵️ https://t.co/mYPHg1mTKj
We are looking for a junior security researcher 🤠
No university degree or previous work experience required, but MUST be able to demonstrate interest in the field and some basic skills by either:
1. Have published blog post detailing 0-day vulnerability (found by yourself) or n-day (analysing someone else's vuln in detail), preferably with exploit code published for the vuln detailed in the blog post.
2. We can also accept private write-ups for vulns you have found / exploited but never published (even if they are already fixed).
3. OR if you don't have any of the above, but have a way to prove your skill, hit me up and we'll talk!
We're also accepting mid-level security researchers with a few years experience!
What we offer:
- Fully remote working environment with regular company meet-ups.
- Great salaries and bonuses!
- Flexibility to work on different CUTTING EDGE projects (mostly related to mobile).
- Mentoring and training by some of the world's top security researchers
How the NSA (Equation Group) allegedly hacked into China's Polytechnical University 👀
I analysed intelligence reports from Chinese cyber firms (360, Pangu, CVERC) to aggregate TTPs attributed to Equation Group.
🔗https://t.co/2dQuwx0lxN
Transform your smartphone into a portable hacking lab
Lear how to set up Kali Linux #PiTail and control it with just your smartphone. Plus, get some of my tips on troubleshooting common issues along the way
Read more: https://t.co/A2RBL05WqR
new blogpost time!!
this one's a fun writeup on a vulnerability chain i found across multiple google services that earned me a $4133.70 bounty
lots of fun css as usual! i had to recreate a bunch of drive/docs/gmail/youtube UIs c:
have fun!
https://t.co/64ZAIVHoSO
The time has come, and with it your reading material for the week.
Phrack #71 is officially released ONLINE! Let us know what you think!
https://t.co/BRnK9lnGjI
Boom!
Windows Hello fingerprint authentication bypassed on top three devices:
- Dell Inspiron
- Lenovo ThinkPad
- Microsoft Surface Pro
Still waiting for recordings from our BlueHat talk to drop, but here's our writeup: https://t.co/GzqqadMdeg
#infosec#security#vulnresearch@blackwinghq
Just released the write-up for CVE-2024-4367, a bug I found recently in PDF.js (and hence in Firefox), resulting in arbitrary JavaScript execution when opening a malicious PDF.
https://t.co/sex6fR0xHS
Our latest blog post from @Icemoonhsv uncovers the complexities in manual LDAP querying. Check it out & gain a deeper understanding of your AD environment and recognize some of the common issues that can arise from querying manually. https://t.co/qyvPDQIfVu
The PS4 (up to FW 11.00) and PS5 (up to FW 8.20) were vulnerable to CVE-2006-4304: https://t.co/e3JBDFFnqW. I'll share details about successful exploitation at TyphoonCon.