If you had FOMO during #SOCON2026 or you want to run back your favorite talk, the talk playlist is now available!
👀 Watch all currently available sessions: https://t.co/MrcmfXAmsZ
��: Access the presentation slides: https://t.co/qSjOXlELgF
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.
The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance.
Access to all other Claude models is not affected.
We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible.
Read our full statement: https://t.co/bwn0sximKZ
🚨 BrEaKiNg: Splunk, a security product, has zero authentication in its built-in database service and accepts any credentials, according to the security researchers who just dropped a full pre-auth RCE chain for Splunk Enterprise (CVE-2026-20253, CVSS 9.8).
Splunk Enterprise on AWS is vulnerable out of the box.
I downloaded the release and tested it. I didn't observe any alerts or blocking during execution.
The interesting part is that it's leveraging native Windows QoS policy functionality rather than exploiting a vulnerability. From what I observed, the tool simply creates QoS rules that throttle traffic for selected processes. In that sense, there's no single malicious API call that Windows/CS itself would block.
That doesn't mean an EDR can't detect or respond to it. A vendor could alert on QoS policy creation, policy changes targeting security products, unusual command-line activity, registry modifications, or the resulting telemetry disruption. But in my testing, the execution itself wasn't prevented.
AI-Powered Penetration Testing with Metasploit
🔥 Telegram: https://t.co/upuP8k8ckB
✴ Twitter: https://t.co/Za7rYILz6E
Artificial Intelligence is transforming the way security professionals perform penetration testing, making reconnaissance, analysis, and exploitation workflows more efficient than ever ⚠️
📚 What You'll Learn in This Guide
🤖 Introduction to AI-Powered Pentesting
🔍 AI-Assisted Reconnaissance & Enumeration
⚙️ Integrating AI with Metasploit Framework
🧠 Using LLMs to Analyze Scan Results
🎯 Automated Vulnerability Identification
🚀 AI-Driven Exploitation Workflows
📋 Generating Security Reports with AI
🔄 Streamlining Post-Exploitation Tasks
🛠️ MCP & AI Integration Concepts
📂 Enhancing Red Team Operations
🛡️ Ethical Considerations & Safe Testing
⚠️ Limitations of AI in Penetration Testing
💡 AI can help penetration testers interpret results, automate repetitive tasks, prioritize vulnerabilities, and accelerate security assessments. When combined with Metasploit, it enables more efficient workflows while still requiring human oversight and validation.
📖 Article:
https://t.co/ql3dLXKIZV
#AI #Metasploit #Pentesting #CyberSecurity #RedTeam #ArtificialIntelligence #EthicalHacking #InfoSec #LLM #SecurityAutomation
Bitkocker exploits go brrrr
Nothing is safe, everything is vulnerable ;) (that’s not true but it sounds like a cool marketing line)
Not tested this but I’m sure many will.
Just woke up! Need tea 🫖
#bitlocker#microsoft#windows#exploits
https://t.co/OFFbzToOIZ
MSSQL has always been a favorite target. Now it ships its own egress channel.
@gershsec's latest research breaks down how SQL Server 2025's native AI features enable exfil, NTLM coercion, and C2 transport, all functioning as intended.
Read more 👇 https://t.co/ugDN4IcZXW
🔴 NetExec for OSCP & AD Pentesting: Complete Guide
🔥 Telegram: https://t.co/upuP8k8ckB
✴ Twitter: https://t.co/Za7rYILz6E
NetExec is becoming the go-to tool for Active Directory enumeration, credential attacks & post-exploitation ⚡
⚡ What You’ll Learn
���� SMB, LDAP & WinRM enumeration
🔑 Password spraying & credential validation
🎯 Kerberoasting & AS-REP Roasting
🩸 BloodHound data collection
📂 LAPS & shares enumeration
🚀 Remote command execution & lateral movement
⚔️ AD exploitation techniques for OSCP labs
💡 NetExec combines the power of CrackMapExec with modern modules, better performance & streamlined AD operations 🔥
⚠️ One tool can uncover the entire attack surface of Active Directory
📖 Article: https://t.co/WciPIQmfq0
#cybersecurity #activedirectory #redteam #oscp #pentesting #infosec #netexec #windows
EDRUnChoker😀registers a permanent WMI subscription with a 5-second timer runs embedded VBScript (fileless) that deletes malicious MSFT_NetQosPolicySettingData policies targeting known security products or aggressive app-path throttles.
https://t.co/A1hcrpav2X
New #redteam tool for blocking EDRs: EDRChoker
Instead of fully blocking the EDR agents' connections to their server, we can throttle their bandwidth so they consistently time out when sending data, which is effectively the same as blocking but avoids triggering "block" or "drop" packet events
#pentest #cybersecurity
Github: TwoSevenOneT/EDRChoker
LPE in the Linux kernel's CIFS client implementation
CVE: CVE-2026-46243
PT ID: PT-2026-45478
Vendor: Linux
Product: Linux
CVSS: 7.8
Credits: Asim Viladi Oglu Manizada
Description:
A privilege escalation vulnerability was found in the Linux kernel's CIFS client implementation. This could allow a local attacker to impersonate other users, bypass authentication in SMB mount operations, and potentially gain unauthorized access to network file shares or escalate privileges.
References:
• https://t.co/L5OiuPXz4B
• https://t.co/mIieH2yll0
PoC/Exploit:
• https://t.co/a8NDymy5TB
• https://t.co/baod4Pqm2z
#dbugs_vuln
Wrote a blogpost about how you can use the Windows server 2003 source code as a red teamer to make your tools look less like tools.
I also go over and map out the main/important files and practical examples of using it to augment MS-*/RFC specs: https://t.co/HfUYBAdCJJ
❤️ Favorite queries!
Log in, heart the queries you use most, sort for Most Favorites, and use Show Favorites to filter your list. For now, this applies to the BloodHound Query Library source.
5/6
🔗 Sharing custom-source queries now carries BYOL source context. If a recipient has not added that source, the library will prompt them to import it before loading the query.
3/6
Happy #BloodHoundBasics Day! This week, @martinsohndk walks through:
https://t.co/3MarnVCbvD helps you find & run the queries you need. Caught up on the latest features?
- Multi-source loading
- Multi-server management
- Favorites
- Cypher cheat sheet
Quick glance in 🧵
1/6