‼️Security researcher MSNightmare has released a Windows Defender update Denial of Service vulnerability called BigDiskBuster.
“This proof of concept is similar to UnDefend. It prevents Microsoft Defender from performing platform and signature updates.”
https://t.co/khPoOkWO4V
Made a funny tool, completely denies defender from updating so you're stuck with your current version if the tool is running in the background,
https://t.co/5usGRBvPRn
I think it can be better
Driver Buddy Reloaded is an IDA Pro Python plugin that helps automate some tedious Windows Kernel Drivers reverse engineering tasks.
Blog:- https://t.co/k3Njagy1gY
Github tool: https://t.co/UrO7gq3t10
By Paolo Stagno aka @Void_Sec
Antidbg: A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineering. It contains 43 anti debug techniques.
Github:- https://t.co/CxkOP6xbuK
Got access to Jev and tested it as a gate for agent-submitted knowledge entries. Faster and cheaper than my previous LLM review in my testing, and it works!
What cybersecurity project would you try it on?
https://t.co/SdOF7PleFV
🚨 CVE-2026-77179 Docker VMM on Mac
container opens a file. deletes it. replaces the parent with a symlink.
virtio-fs still has the old path string. kernel follows the symlink.
host filesystem R/W. three lines of bash.
Docker Desktop + Docker Sandboxes.
Docker VMM becomes default end of October. this landed first.
fixed in Desktop 4.88.0 / Sandboxes 0.42.0
https://t.co/BrlmxCLcfo
credit: @Accomplish_ai
#ExploitDev #CloudSecurity #InfoSec
Introducing ACLPWN a BOF for abusing ACL permissions in Active Directory.
GenericAll
GenericWrite
WriteDACL
WriteOwner
ExtendedRight(Force-Change-Password)
AddMember
GetChanges + GetChangesAll
If you can write it, you can own it!!. BOF available Day 1 on our training sign up for notifications!!!: https://t.co/YI99YjSZDA
This repository contains public disclosure material for CVE-2026-42980, a Windows kernel WMI integer-underflow vulnerability that can be exploited for local privilege escalation to NT AUTHORITY\SYSTEM on vulnerable lab builds.
poc released by G4sp4rCS :- https://t.co/LS48XVRaun
🔴 CVE-2026-43783 için Exploit/PoC yayınlandı: macOS'ta kötü amaçlı uygulamalar root yetkisine yükselebiliyor! LPE -> Root
macOS 26.5.2 ve öncesini etkileyen DesktopServicesHelper kaynaklı LPE açığı, public PoC ile birlikte istismar edilebilir durumda.
Bu açık, macOS 26.6 ile düzeltildi.
PoC: https://t.co/g4HdieAbk6
PassTheCert-rs: a cross-platform, pure Rust implementation of Pass the Certificate.
Uses Schannel certificate authentication over LDAP/S, enabling AD operations without a password, NT hash, or PKINIT. Includes an interactive LDAP shell plus actions for RBCD, Shadow Credentials, group manipulation, machine accounts, and DCSync-related privilege modification.
Github:- https://t.co/iZvc3SMBIS
tool by: @g0h4n_0