🚨 PATCH NOW: A Firefox bug let attackers fingerprint your browser and follow you even in Private Browsing, and in Tor browser even after a "New Identity."
The vulnerability made it possible for unrelated websites to independently observe the same fingerprint and quietly link your activity across them.
Mozilla patched CVE-2026-6770
on April 21, 2026 in Firefox 150, ESR 140.10, and Thunderbird. The Tor Project shipped Tor Browser 15.0.10 with the fix.
If you are still on an older build, your Private Browsing wasn't private and your Tor session wasn't either. Update now.
All EZ Tools have been updated! New version is 2026.5.0 across the board.
Nuget updates, control updates, bug fixes and general refreshing of everything.
Enjoy!!
#dfir
Microsoft suspended the developer account for WireGuard (and also VeraCrypt).
Why? Literally nobody knows. Presumably it's because Microsoft hates everyone and wants us all to suffer.
This is awesome! Incredibly useful for IR and beats my handmade notes 😆
Thank you to the folks that made this guide public 🙏 🙏
Get the PDF directly from here 🔗 https://t.co/tXu3Y8oTSJ
DFIR analysts who use macOS as their daily driver deserve free and native forensic tooling. So I built one. 🍎
Introducing 𝗜𝗥𝗙𝗹𝗼𝘄 𝗧𝗶𝗺𝗲𝗹𝗶𝗻𝗲 — a timeline analysis app built from the ground up for Mac-based DFIR folks, forensic investigators, or SOC analysts. Built in appreciation of, and inspired by, Eric Zimmerman’s Timeline Explorer.
Every feature in this tool was shaped by real IR casework. Handling massive timelines, parsing artifacts here and there, and pivoting across logs during active investigations. I built IRFlow Timeline to be the native macOS timeline analyzer that actually keeps up with a live case. Every button and view is intentional; if it’s in the app, it’s because I needed it mid-case and realized the standard tools fell short.
No dependencies. Zero setup. Just drag, drop, and analyze.
#dfir #incidentresponse #timeline #macos #threathunitng #digitalforensics
Do you open risky PDFs, Office documents, or images you can't trust? 🛡️
Use this tool that converts potentially malicious files into a perfectly safe PDF using a secure container process.
#Cybersecurity#DangerZone#Infosec
This is really cool. I like this code, proof-of-concept, and paper A LOT.
Basically he is modifying the raw bytes of .LNK files (Windows shortcuts) to make them perform malicious actions while also operating correctly as a .LNK file. When examined from the user they will appear completely legitimate, but it's not.
This is really, really, really cool. This is a great malware technique. I can't recall the last time I read anything on .LNK files being abused in this manner. Historically they're "hijacked", not modified at the byte level.
My only criticism is he wrote this proof-of-concept in Python (not C or C++, like a gangster).
Excellent work.
For convenience: I wrote a small collector that pulls all SHA-256, SHA-1 and MD5 hashes from Notepad++ releases and compiles them into big CSV + JSON files
Use it to check if any Notepad++ installs in your org match known-good release hashes - and spot weird/malicious outliers
https://t.co/W2pYbfYemz
After Months of Development, FINALLY ready to share: Harden System Security🎉
✅ Complete System Hardening
✅ Security Posture Analysis
✅ All-in-One Toolkit
✅ Built-in Intune support for Scalability
✅ Beautiful Modern UI
✅ CLI support
https://t.co/lfd3SaDvvM
#Cyber#Windows
A beautiful winter day today. No wind and –22 degrees Celsius.
Privileged to see the northern lights from the backyard.
There are fresh hare tracks as well. That explains why the cat has been glued to the window.
Someone going by "wwwiesel" on GitHub picked up @securitymeta_’s tradition this year and dropped a full list of #BlackFriday deals in the #InfoSec space
Online Courses & Training
- 8kSec Academy
- AI Security Professional Course
- Altered Security
- Belkasoft
- Blu Raven Academy
- Career Hacking Quest
- CloudBreach
- Cyber Plumber's Lab
- CyberWarFare Labs
- DevSecOps Pro
- DNS for Developers
- Evilginx Mastery
- Hack The Box Pro Labs
- HackSmarter
- HackTricks Training
- Hexordia
- Invictus IR Academy
- Invictus CloudLabs
- LetsDefend
- Mobile Hacking Lab
- OffSec Learn One
- OPSWAT Academy
- Pluralsight
- Practical DevSecOps
- Practical TLS
- http://pwn[.]guide
- CyberNow (SOC Analyst)
- TCM Academy
- TheXero
- Vantage Point / Enciphers
- White Knight Labs
- WiFiChallenge Academy
- ZeroPoint Security
Exams
- The SecOps Group
Mini Courses
- SecDim
Books
- The CloudSec Engineer
Hardware
- Hak5
- KSEC Labs
Professional Services
- Wortell
Tools
- Burp Bounty Pro
- Burp Bounty Go
- FullStro
- Grammarly Pro
- PortDroid
- Proton Mail / VPN / Pass / Drive
- HTTP Toolkit
- http://SEOengine[.]ai
- SubtitleBee
- WebsiteVoice
Services
- Grayhat Warfare
- AirVPN
- CyberGhost VPN
- Proton (second listing in file)
- NordVPN
- Tuta Mail
- InMotion Hosting
- IPVanish VPN
Misc
- Neato Stickers
URL: https://t.co/MX7WkVjmPh
The Qilin ransomware operation was spotted executing Linux encryptors in Windows using Windows Subsystem for Linux (WSL) to evade detection by traditional security tools.
https://t.co/sg3zoVqzZF
Microsoft has released emergency security updates to patch a critical-severity Windows Server Update Service (WSUS) vulnerability with publicly available proof-of-concept exploit code.
https://t.co/zsJSGtuTcR
Just updated our Yamato Security tools Hayabusa, Takajo and Suzaku for our upcoming showcase at Black Hat Arsenal USA in Vegas. All thanks to our contributors: Fukusuke Takahashi, Akira Nishikawa, James Takai, DustInDark and Akkuman!
Hayabusa 3.4.0:
https://t.co/6IEEylbgML
Takajo 2.11.0:
https://t.co/rqs7skcMfV
Suzaku 1.0.0:
https://t.co/35bF3ZuaHr
We will be showcasing Hayabusa and Takajo on August 6th 3-4pm: https://t.co/l66933eQHo
and Suzaku on August 7th at 10-11am: https://t.co/1Frs5sxrAh
Please stop by and say hi if you are attending Black Hat!
Fukusuke Takahashi、Akira Nishikawa、James Takai、DustInDark、Akkumanのコントリビュータのお陰様で、大和セキュリティツールのHayabusa、Takajo、Suzakuをラスベガスで開催されるBlack Hat Arsenal USAでの展示会に向けて更新しました!
8月6日15~16時にHayabusaとTakajoを展示します: https://t.co/l66933eQHo
また、8月7日10~11時にSuzakuを展示します: https://t.co/1Frs5sxrAh
Black Hatにご参加の方は、ぜひお立ち寄りいただき、ご挨拶ください!