@Castle_io 's research team just open sourced a disposable email domain list built from real abuse telemetry 🔎
Disposable email providers are a core piece of infrastructure behind fake account creation and signup abuse, similarly to how proxies enable large-scale traffic distribution.
A few things we cared about:
- curated, not aggregated from public lists
- strictly disposable domains
- updated daily
- ranked by observed abuse prevalence
And yes, before someone says it: attackers also use aged Gmail accounts, compromised inboxes, freshly registered domains, etc 😄
Disposable domains are not the whole problem, but they’re still one of the clearest infrastructure-level signals behind large-scale signup abuse.
Repo:
https://t.co/M7nx959KHE
the watchers: how openai, the US government, and persona have been secretly running an identity surveillance system since nov 2023.
https://t.co/Zz04WDF8Lz
researched by @vmfunc, @MDLcsgo, @DziurwaF
Hoy !
Pas de stream ce soir... MAIS !
Release d'une petite série que j'ai pris plaisir à vivre, tourner, et réaliser sur le travail fait ave d'autres nombreux bénévoles pour @hack_4_values !
On y parle de l'organisation, des enjeux, des ONG évidemment, mais aussi des bugs trouvés, de méthodologie, et de l'aspect HuMaIn ! 💌
Vos partages -très- appréciés, et je vous souhaite une -très- bonne semaine 🌻
https://t.co/NLaqj5auW5
🔍 New research on a niche technique to abuse "GPP Local Users and Groups" to elevate privileges locally through sAMAccountName hijacking.
This research comes with a new GPOHound update to detect this misconfiguration.
🔗 Read more: https://t.co/bE3rEEJNfT
I have just released my first tool : GPOHound 🚀
GPOHound is an offensive tool for dumping and analysing GPOs. It leverages BloodHound data and enriches it with insights extracted from the analysis.
🔗Check it out here: https://t.co/bMiOK8jiTE
I think many people are familiar with the topic of blind CSS exfiltration, especially after the post by
@garethheyes
However, an important update has occurred since then, which I wrote below ->
New Active Directory Mindmap v2025.03! 🚀
📖 Readable version: https://t.co/gQd6WsLnzG
🔧 Now fully generated from markdown files—way easier to update and maintain!
💡 Got improvements? PRs welcome! 👉 https://t.co/o52PAmek7b
Hi it's me again, I've been calling for a while now, you need to pay your health insurance Sir...
Or have some replays? 😏
La dernière Techno Watch avec @Drypaints@Maltemo et @pentest_swissky !🌿
FYI: Pas de stream ce mardi 4 Fev ➡️ HTB Meetup Lyon !
Rdv au Elephant and Castle, début à 19h+ et miniconfs à ~20h ! 😘
https://t.co/z9NJNEHdE1
@navlys__@Haax9_ yep je m'en servais de temps en temps, il était bien utile.
Après tu peux toujours le laisser en dépôt git, ça ne me pose pas de problèmes :)
⚠️ NEW UPDATE: In October, @Bandrel wrote about a vulnerability he discovered called #EKUwu. This vulnerability was patched on November 12. Find more information about EKUwu and the link to the patch on our blog! https://t.co/bBro2A8WlY
Just recieved legal policies’ update by mail.
« **For the moment**, we don’t activate IA training on European countries ».
FOR THE MOMENT
Note that Strava already does that on your medical data and doesn’t even let you opt out.
GrEaT ��
Not suprised, but this will happen with increasing frequency.
Fortunately, Europe, UK and Switzerland were spared.
Nothing is free.
https://t.co/qPohCR4UpJ
🔴 Alert 🔴 LinkedIn is using your data to train its generative AI by default.
No, you didn’t opt in. LinkedIn did it for you! 🙈
Here’s how you can stop LinkedIn from using your data 👉 https://t.co/vCYIgfDYWH