A PoC/exploit has been discovered for vulnerability CVE-2026-54121
PT ID: PT-2026-58514
Vendor: Microsoft
Product: Windows 10 Version 1607
Description: Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
References:
• https://t.co/Bv0OpKQzG8
• https://t.co/dr5GoBAf3l
#dbugs_vuln
Seems that wp2shell PoCs are now floating around the internet, so we've published our blog post including our research methodology for finding the bug as well as a deep dive into the chain itself - https://t.co/iuU0yiYJBT
22 Windows LPE reported by one of my colleagues at @Seasecresponse .
This data should not be in any public dataset so if you plan to do any fine-tuning it would be helpful we hope.
All credit goes to him.
https://t.co/FnkQe5jWd4
lolcreds
Living Off the Land Credentials
“Application, appliance, and platform credentials: where they live, what they look like, known defaults, and what they unlock”
By @haxxm0nkey
https://t.co/hO3ABWok4k
⚠️ UPDATE: New Court Files Reveal How Microsoft Helped the FBI Identify Peter Stokes "Bouquet" (Scattered Spider Member)
The court files reveal that Microsoft helped the FBI track Peter Stokes down using GDID — a Global Device Identifier, which is assigned to every Windows installation and cannot be changed unless the OS is wiped. The GDID helped them track:
• IP history
• Full web activity
• Video game activity and games played
• Logged-in social accounts, including Snapchat, Facebook, and Apple
According to the court documents, the critical mistake was using a VPN to create the ngrok account used in the May 2025 Tiffany & Co. hack from the same Windows device associated with his GDID.
Although the account was created from a VPN IP address ending in .168, Microsoft records show that the same GDID (6755467234350028) accessed the ngrok signup page at the exact time the account was created, linking the hack to his personal social accounts.
Just open-sourced CredSpy
Couldn't find any tools that allowed unauthenticated enumeration of auth methods for @Microsoft accounts, so I created it.
Shows whether target accounts use Passkeys, certificate auth, passwordless push, etc...
Find it here: https://t.co/BZ7XfHi5KW
SpecterInsight v6.0.0 is live! Inveigh workflows, local and remote exploit integration, native Zig payloads with source code obfuscation, network intelligence, and SSL C2 to enhance your threat emulation activities.
https://t.co/LuwKxolcYj
I'm tired of my tools getting sig'd so I built a pipeline to keep our tools alive for longer and bring some classics back.
Post 1 of 3 is live now. The final post will drop our Go/C# -> WASM toolchain. It builds #Sliver, #Chisel, and some of #GhostPack.
https://t.co/yFF65A8MQO
https://t.co/laDOE5LChz
"When an organisation uses Exchange Online (or on-premises exchange in hybrid mode) with a third-party mail server or spam filter as its MX record, it is possible to send mail from any sender to that organisation. Outlook delivers it without warning"
AWS pentesting today is less about servers and more about identities, permissions, and trust relationships.
Guide covers IAM abuse, privilege escalation, SSRF, S3, Lambda security, and cloud attack methodology.
Source: https://t.co/lJXtQUJcrb
#AWS#CloudSecurity#BugBounty
@darkrai@instagram lol yeah, major exploit but there’s nothing you can do. It’s like the roblox ai assistant exploit from a few days ago where you could reset emails if you had their billing. Instagram on the other hand is even easier, you only need the user