‼️ Nightmare Eclipse is back on GitHub under a new alias and has released a new Windows Defender vulnerability zero-day called RoguePlanet.
PoC: https://t.co/n0xF6uGt4u
New GitHub Account: https://t.co/qwU93VedpH
New #redteam tool for blocking EDRs: EDRChoker
Instead of fully blocking the EDR agents' connections to their server, we can throttle their bandwidth so they consistently time out when sending data, which is effectively the same as blocking but avoids triggering "block" or "drop" packet events
#pentest #cybersecurity
Github: TwoSevenOneT/EDRChoker
This morning I have made public an internal repo on relaying available to everyone. I call it the relay bible. I still have a few more additional tweaks and techniques to add in here but for the most part. It's ready. Hope everyone enjoys my reference.
https://t.co/if08LR2Nwv
Bookmarking @HackingDave AI model regression site. This is useful. For now Opus 4.8 is my daily driver followed by a few frontier models. It’s an exciting time for AI to assist me in research.
https://t.co/hMLE1R4T7k
‼️ The alienation continues: more security researchers are sticking up the middle finger after feeling squeezed by Microsoft and GitHub. MSRC emailed Black Hat USA 2026 presenters asking which MSRC cases, VULN-IDs, or CVEs their talks would cover. GitHub told a researcher to delete his public PoC repos and flagged his accounts under ToS.
🚨 One more week to submit your workshop ideas!
📝✨ Still have an innovative idea or an exciting topic to share?
We’re extending the deadline to give everyone a chance to contribute.
👉 Submit your proposals by the end of the week: https://t.co/EO900ZoxS2
#CyberSecurity#CFP
🎉 Our Call for Talks is officially open.
Submit your proposal from June 1st to August 23rd and be part of this incredible event.
Scheduled from February 4th to 5th, the conference is your platform to share your insights.
👉 Apply now: https://t.co/HCGeleq8vs
#CyberSecurity
https://t.co/r67jck8ZGo just got a visual refresh 🌟
Explore 600+ documented DLL Hijacking cases, including:
• JSON/CSV/YAML feeds
• Sigma detection content for every DLL
• A single Sigma rule covering all DLLs
Check it out: https://t.co/2PJCgKEZwO
Tools like Snaffler are great, but crawling SMB shares creates a telemetry nightmare. You instantly light up the SIEM with :
- 5140 / 5145 (Network Share Access)
- 4656 / 4663 (Object & File Access)
So I built Invoke-WindowsSearch to query the native Windows Search DB (OLE DB) directly via WinRM/RPC, It extracts the targets without touching the actual files, completely bypassing the 4663 and 5145 detection footprint.
Trade-offs: Requires the WSearch service (disabled by default on Server OS) and lacks complex regex capabilities. Know your environment before execution.
#RedTeam #ActiveDirectory #OPSEC #ThreatHunting #PowerShell
A bunch of ppl complained about ethics of bug hoarding, saying we should report to MSRC etc when we mentioned we hold on to 0days to use during RT ops in https://t.co/7T98Dh0CIx
How the tables have turned 😂
"you can outsource your thinking, but you can’t outsource your understanding"
easy to forget in todays AI era, worth remembering everyday as we all wield more intelligence!
I spent the last weeks building LLM benchmarks for a very specific reason:
We want to use AI in RuneAI to help with THOR finding triage, and I needed a better baseline for model selection than generic LLM leaderboards.
Security-event triage is its own thing.
A model can be great at coding, reasoning or vulnerability writeups and still be a bad fit for deciding whether a messy endpoint finding should be suppressed, reviewed or escalated.
In real deployments this will likely happen inside agentic workflows with tools, memory, context handling and feedback loops. But before testing the whole system, I wanted a clean baseline:
How does the model behave when it only gets the enriched finding itself?
Blog post with the reasoning and methodology:
https://t.co/KQPOPDWP1B
Interactive benchmark results:
https://t.co/pvVhTBJsz0
Repo:
https://t.co/Fw3uW9nu2a
Maybe useful for others building SOC / security-event triage benchmarks.
The countdown is on! Only 6 days remaining to submit your workshop's proposal for #INSO27! 🎉
Our Call for Workshops is still open until May 31. Don’t miss this opportunity!
👉 Apply now on our website: https://t.co/Qsdp7Pyteg
#CyberSecurity#CFP#InfoSec
El web scraping acaba de cambiar de nivel
Scrapling evita los bloqueos de Cloudflare, es 774 veces más rápido que BeautifulSoup y no necesita configuración de proxies
52.2k estrellas en GitHub
No es otro scraper más
Es un framework adaptativo que aprende la estructura de cada web y se ajusta automáticamente cuando cambia
Sin mantenimiento manual. Sin que te bloqueen.
✅ Bypassa Cloudflare y los anti-bots más agresivos
✅ 774x más rápido que BeautifulSoup en benchmarks reales
✅ Sin necesidad de proxies ni configuración especial
✅ Se adapta automáticamente cuando cambia la estructura de la web
✅ Compatible con agentes de IA como servidor MCP
✅ Soporte para JavaScript, iframes y contenido dinámico
✅ Modo stealth para webs con detección avanzada
✅ 46 releases. Actualizado la semana pasada.
✅ Licencia BSD-3
Lo que antes tardabas días en montar y mantener ahora son minutos
52.2k estrellas. 5k forks. BSD-3.
repo aquí 👇
The #BloodHoundUnleashed Attack Path Championship is live! 🙌
Could you be our Attack Path Champion? 67 challenges. One leaderboard. Watch out for bonus points at #InfoSecEurope. Use invite code ReleaseTheHounds to join the challenge.
➡️ https://t.co/NwlCopXTAV
My Windows reverse engineering and exploit research workflow has been:
1. Pick a binary to research like tcpip.sys
2. Use https://t.co/fOxBB6tEsN to automate seeing existing binary versions, download, and generate diffs from them
3. Load the resulting .binexport's and .bindiff into an LLM and ask it to analyze
4. Look up the build number of previous Windows version that old binary existed in from https://t.co/U788ndiJbj such as 26100.8328 and create a VM from it
5. Write code and test, working backwards from LLM analysis