Did you know MSSQL databases can be exposed via Named pipes ? Welp using Impacket we can now connect to these https://t.co/E1Dy3Nz5qD
Working on the integration on NXC 👀
New option in impacket for ADCS ESC relay attacks:
--altsid
This option is needed with
StrongCertificateBindingEnforcement, enforced on DC's since 2026-02 (KB5014754).
https://t.co/Xsus8THJE3
See reply for example command.
More info:
https://t.co/8Rrb1iR5Z4 by @harmj0y
Onelogon: Taking over Active Directory Accounts via Netlogon🔑
We analyzed Netlogon, bypassed the Zerologon patch, resulting in a full auth bypass. An attacker can leverage this to compromise computer accounts, or even the entire AD. Non-standard config must be present tho 🧵
Linux has stopped patching security bugs, they can’t handle the volume AI is detecting. OpenBSD is in the same boat.
Two years ago I proposed auto-hardened kernel code. I was ridiculed, of course. Now it's too late, perhaps we should air-gap for a while?
https://t.co/LaiQ98p5hp
Impacket 0.13.1 is live! This release includes new relay surfaces, stronger support for modern Windows and SQL Server environments, and a set of practical improvements across the examples scripts. Check out the blog post to get more details>
https://t.co/B52xTyCNMT
Following the blogpost about implementing the Channel Binding token for https://t.co/qGtDan5hW9 on Impacket (https://t.co/0o2cjoszwq), here is the module you can use to check whether or not CBT is required on MSSQL databases via NetExec https://t.co/SHdJMYb0JW 🔥🔥
HOY EN EL EVENTO PRO PRESENTAMOS OPENARG
Desde @colossus_lab hicimos un chat con IA que se conecta a los datos públicos de Argentina, son 1.800 tablas cacheadas con 27 millones de filas de datos pre-descargados.
Se llama OpenArg. Le preguntás lo que quieras -inflación, dólar, presupuesto, declaraciones juradas- y te responde con gráficos, datos y las fuentes. Sin saber programar. Sin descargar nada.
¿Por qué lo hicimos? Argentina tiene más de 16.000 datasets en 32 portales de datos abiertos. Están dispersos, en formatos distintos, y para usarlos necesitás saber de datos. Eso no es transparencia. Los datos están, pero nadie los puede usar.
La idea detrás de OpenArg: si la información pública está estructurada, la IA puede leerla, compararla y analizarla. No para reemplazar a nadie. Para que cualquiera pueda entender lo que hoy solo entienden los técnicos.
¿Cómo funciona? Cuando preguntás algo, se activan 4 agentes:
1- Estratega → arma un plan con tu pregunta.
2- Investigador → busca en 12 fuentes oficiales.
3- Analista → cruza los datos.
4- Redactor → arma la respuesta con gráficos y citas.
No inventa. Cada respuesta tiene las fuentes con links a los portales oficiales. Inflación → INDEC. Dólar → BCRA.
El stack: Next.js 16, TypeScript, arquitectura multi-agente, PostgreSQL + pgvector, 12 conectores a APIs oficiales (CKAN, BCRA, INDEC, Georef, DDJJ, Congreso). 2 llamadas a IA por consulta.
Pero OpenArg no es solo un buscador. Si sos intendente de un municipio de 5.000 habitantes, podés comparar tu gestión con municipios parecidos. Ver qué hacen otros. Copiar lo que funciona.
Esa es la misión de @colossus_lab: que cualquier funcionario pueda ser un buen funcionario. Que gestionar bien sea más fácil.
¿Hacia dónde vamos? OpenLatam. La mayoría de los países de la región usan CKAN. Agregar un país es enchufar un conector al motor que ya anda. Colombia, Chile, Uruguay, México, Perú. Están a un paso.
Lo que estamos armando no es un producto. Es infraestructura pública para la era de la IA.
https://t.co/TwKthPcz5x 🇦🇷 Estamos en fase de prueba con beta testers. Si te interesa participar, escribinos. Y si podés compartir este post, nos hacés un favor enorme. Cada RT acerca OpenArg a alguien que lo puede necesitar.
Releasing one of my research tools: EVENmonitor🖥️
Inspired by LDAPmonitor, I implemented a monitoring tool for the Windows Event log in pure python. You can just attach it via the network and then filter for specific event IDs or keywords.
Available at: https://t.co/TpjEnIW7C0
Rapid7 dropped a write-up on the Notepad++ update-chain abuse and - finally - it comes with real IOCs
- update.exe downloaded from 95.179.213[.]0 after notepad++.exe -> GUP.exe
- file hashes for update.exe / log.dll / BluetoothService.exe / conf.c / libtcc.dll
- network IOCs incl. api[.]skycloudcenter[.]com (-> 61.4.102[.]97), api[.]wiresguard[.]com, 59.110.7[.]32, 124.222.137[.]114
by @rapid7
https://t.co/rrespJ9Ju0
NTLM reflection attacks can be used to compromise Active Directory domains even with SMB signing if systems aren’t fully patched
https://t.co/mnN8AI7jTQ
Hi friends! I've finally written the third part of the Impacket Programming Guide! We explored several MSRPC protocols and also created our own tool for Lateral Movement! Read on medium:
https://t.co/gW1iK79NuE
POC: https://t.co/L20Mudouks
NetExec v1.5.0 has been released!🔥
Merry Christmas everyone!🎉 It's been a very long time since the last release, so there are a TON of new features!
Some of the highlights:
- Built-in LDAP signing and channel binding checks
- RDP command execution
- certipy find integration
[SALUD] La vacuna argentina contra el cáncer de piel ya está disponible: se llama Vaccimel, sirve para tratar el tratar el melanoma cutáneo, fue desarrollada por el CONICET y los Institutos Leloir y Fleming y, por ahora, se aplica solo en el Hospital de Oncología Marie Curie.
Just committed the article about my talk at #MYHack 2025:
"Vulnerability Inception: How AI Code Assistants Replicate and Amplify Security Flaws"
Main result is that you can easily manipulate LLMs and coding agents into writing backdoors for you.
Here's how: (1/7)
The latest version of #Impacket is live! This release includes new attack paths and relay tricks, channel binding updates, MSSQL workflow upgrades, SMB Improvements, and more. Learn all the details of the new release in the update blog: https://t.co/ZndfoVUQX3
''GitHub - 0xflux/Hells-Hollow: Hells Hollow Windows 11 Rootkit technique to Hook the SSDT via Alt Syscalls''
#infosec#pentest#redteam#blueteam
https://t.co/57uWoksWHl
Hi Friends! We continue our series of articles about RPC and impacket. In the second part, we looked at tools that can be used to analyze RPC servers, and also examined RPC security issues : )
https://t.co/f2pIOOMzaf