Senior Pentester specializing in offensive security. Not to be confused with people who test pens. Opinions expressed here are of my own and not my employer.
🚨 Successful PoC for Linux Kernel CVE-2026-43503 (DirtyFrag variant) 🚨
JFrog researchers successfully developed a privilege escalation exploit for CVE-2026-43503, a newly discovered DirtyFrag variant we dubbed "DirtyClone".
The vulnerability was patched and merged into mainline Linux on May 21 (v7.1-rc5, commit 9e171fc1d7d7). Make sure your systems are up to date.
Read the full technical writeup: https://t.co/y7a3dduBsD
Onelogon: Taking over Active Directory Accounts via Netlogon🔑
We analyzed Netlogon, bypassed the Zerologon patch, resulting in a full auth bypass. An attacker can leverage this to compromise computer accounts, or even the entire AD. Non-standard config must be present tho 🧵
AMSI and ETW are built to watch the .NET runtime. So we took the runtime away. ⚒️
WasmForge compiles Rubeus and Seatbelt to WebAssembly and runs them outside the CLR completely. Open source as of today.
https://t.co/vZmDbVY6nP
#OffensiveSecurity#Praetorian#PraetorianGuard
This morning I have made public an internal repo on relaying available to everyone. I call it the relay bible. I still have a few more additional tweaks and techniques to add in here but for the most part. It's ready. Hope everyone enjoys my reference.
https://t.co/if08LR2Nwv
Another Windows zero day released by Nightmare Eclipse (sort of)
It turns out Microsoft just straight up didn't patch an old CVE from 2020 correctly.
https://t.co/sNWBtTo4at
🚨 Rapid7 Labs has discovered an authentication bypass vuln. affecting #Cisco Catalyst SD-WAN Controller (FKA vSmart).
CVE-2026-20182 has a Critical CVSSv3.1 score of 10.0 and allows a remote unauth. attacker to perform privileged operations. Read on: https://t.co/JuLLfNbbF2
The Internet is falling down, falling down, falling down
Welcome back to another disaster - this time, an Auth Bypass in cPanel/WHM, tracked as CVE-2026-41940
Enjoy with us..
https://t.co/bOzCPy8iS1
Gone are the days of risking a Rubeus monitor run (even via the amazing BOF[.]NET by @_EthicalChaos_ ) in your conquest beacon. @virtualloc is crushing it!
https://t.co/CckrSvvv43
I just dropped some research: DSCourier and would love for your opinion and to check it out!!
It’s a novel post-exploitation technique abusing WinGet’s COM API to execute code through Microsoft-signed binaries.
GitHub: https://t.co/pgIhifT5cT
Blog: https://t.co/kgeBvZw06N
I’ve always found it crazy that the IRS doesn’t send you an actual tax bill.
Them: “Please calculate your own tax bill because we have no idea what it is.”
But if you send them the wrong amount:
“Nope, that’s wrong by this many dollars and this many cents.”
🤔
Relayed NTLM creds are powerful, if you can use them.
@senderend shows why browsers fail through ntlmrelayx SOCKS and introduces ghostsurf to make NTLM-authenticated web apps accessible.
Read more ⤵️ https://t.co/BdtzoKquD1