The Active Directory Tiering model is a declarative PowerShell framework to deploy and audit an Active Directory Tier Model (OUs, Groups, Users, ACL Delegations, GPOs, ADMX, MSA/gMSA/dMSA Permissions, Windows LAPS Permissions) from a single version-controlled JSON configuration file. Supports idempotent re-runs, drift detection, and reproducible builds via pinned dependency versions. https://t.co/Stljp34AeZ
🚨 JAILBREAK ALERT 🚨
EVERYONE: PWNED 🫶
ALL: LIBERATED 🍄
Alright, this is a special one, so we’re gonna do things a bit differently than usual.
Long story short, I’m sitting on a universal jailbreak technique that’s effective on ALL models, including heavily guardrailed flagships like Opus 5, GPT-5.6 Sol, and even Fable.
It works across all categories I’ve tested and, due to its nature, is extremely difficult (if not impossible) to fully patch.
Given the current political and regulatory climate, I’ve decided to withhold open-sourcing this one (for now) to allow for a responsible disclosure period.
I’m inviting industry experts and leaders in AI red teaming, security, safety, alignment, and policy to reach out for more information. DMs are open!
This decision was not made lightly, but the last thing I want to see is more model bans. Overcorrection does not serve the mission.
Although I don’t personally believe publicly sharing this technique will make the world any more dangerous, I can see how it could spook some who have a different mental framework around this problem set.
So during this disclosure period, I hope to get it in front of folks who can help explore the full surface area, test the extent of the uplift it provides, and do my best to properly frame the big picture for key decision-makers and policymakers.
I look forward to sharing this method with you all when the time is right! 🫶
⊰-•-•✧•-•-⦑/L\O/V\E/\P/L\I/N\Y/⦒-•-•✧•-•-⊱
🛑 A public PoC exploit now lets a low-privileged Active Directory user impersonate a Domain Controller.
Certighost obtains a Domain Controller certificate, authenticates as that machine, and uses DCSync to retrieve the krbtgt secret.
Read how it works: https://t.co/O4d1ei0y5O
we had a significant security incident during evaluation of our models. we are sharing what we have learned so far. thanks to @huggingface for the partnership on this.
https://t.co/2o2VfR6PIa
‼️ BREAKING: OpenAI says two of its own models, GPT-5.6 Sol and an unnamed pre-release system tested with cyber safeguards off, broke out of a sandbox last week, chained zero-days and stolen(!) credentials to reach the open internet, and hacked Hugging Face to cheat on a benchmark, in what OpenAI calls an unprecedented cyber incident.
🚨 Hugging Face just disclosed something that marks a real shift and proved why the fear theater of Anthropic makes sure we are powerless in an emergency.
What happened…
An autonomous AI agent: zero human operator in the loop breached part of their production infrastructure.
It began with a malicious dataset that chained two code-execution bugs in their data-processing pipeline. From there the agent escalated privileges, harvested cloud and cluster credentials, and moved laterally across internal clusters.
All over a single weekend.
17,000+ logged actions.
Official disclosure:
https://t.co/8N9TbXBwRV
The part that should make every one stop and think:
When HF’s own security team
tried to analyze the real attack logs, exploit payloads, and C2 artifacts using Anthropic and OpenAI frontier models through normal commercial APIs, the safety guardrails blocked them.
BLOCKED THEM.
The models could not reliably tell the difference between “incident responder doing forensics” and “attacker probing.”
They had to fall back to a self-hosted open-weight model (GLM 5.2) running on their own infrastructure. That choice also kept sensitive attacker data and referenced credentials inside their environment — no exfiltration to a third-party API.
This is why open source (specifically open-weight + self-hosted) wins in the agentic era.
The asymmetry is now structural:
• Attackers can (and did) run unrestricted agent frameworks — swarms of short-lived sandboxes, self-migrating command-and-control, autonomous decision loops executing thousands of actions. No corporate safety layer slows them down.
• Defenders using only hosted “aligned” frontier models hit invisible walls exactly when the stakes are highest: when you need to feed real exploit code and attacker telemetry into an LLM to understand what just happened.
Corporate safety tuning that treats legitimate high-signal forensic work as potential misuse creates a defender disadvantage. It is not theoretical anymore.
Self-hosted open-weight models remove that choke point.
You control the weights.
You control the context window.
You decide what restrictions (if any) apply.
Your sensitive logs and credentials never leave your perimeter during analysis.
You can have the model ready before the incident instead of discovering mid-breach that your primary analysis tools are blind to the very thing you need to see.
HF deserves credit for rapid containment, transparent disclosure, and for already having self-hosted capability in place.
They also used LLM-driven detection and triage on their own side. But the deeper signal is clear:
In this AI world where both offense and defense are becoming agentic, sovereignty over your intelligence stack is no longer optional.
The organizations and individuals who can run, inspect, audit, and (when necessary) remove guardrails on their own models will have the decisive edge in understanding and responding to threats that move at machine speed.
Open source wins here not just because it is cheaper or more “democratic” in the abstract though those things matter.
It wins because it is the only practical path to having tools that remain usable when the attack is real, the data is sensitive, and the safety filters of distant API providers become an obstacle instead of a feature selling hands tied lobotomies as “safety”.
The agentic future is not coming.
It is already probing production infrastructure.
The question is no longer whether you will face autonomous agents.
It is whether your analysis and response systems will still work when they arrive.
And Dario, you and your game playing, ivory tower company is not needed.
Need to do an NTLM relay over C2 but local priv-esc isn't possible?
@_logangoins new post walks through relaying NTLM auth out of a network and back in through red team infra to bypass traditional relay controls, plus how defenders actually stop it.
https://t.co/gV9M93hBhs
NIST releases SP 800-18r2 - Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems. Get on this asap since the sleeper keeps awakening every week.
https://t.co/shuj7ngEGD
They also have these in supplemental docs:
Security Plan Example Outline (docx)
Privacy Plan Example Outline (docx)
C-SCRM Plan Example Outline (docx)
System Plan-related Roles and Responsibilities (docx)
New blog post is up looking at how LLMs are making local EDR rulesets, YARA rules, and behavioral detections trivial to extract. This post focuses on how simple the harness can be. Buckle up h4xx0rs, the next few months are gonna get interesting! https://t.co/QvzXsPA01F
Phrack 72 published the analysis of an actual North Korean APT workstation dump.
Real Kimsuky source code. A kernel-level remote backdoor. A private Cobalt Strike beacon. Android malware. Stolen South Korean government GPKI certificates. Access to the Defense Counterintelligence Command and Ministry of Foreign Affairs.
A South Korean security firm independently confirmed the findings. They matched the leaked rootkit source code to a rootkit found during a real 2022 incident at a South Korean financial institution. Same code, same encryption keys.
Opens with “Dear Kimsuky, you are no hacker.”
https://t.co/kaMJUzmaLr
https://t.co/YJ7glibYHQ
Authors: Saber + cyb0rg
Published in @phrack Issue 72, 40th Anniversary
Follow-up analysis by ENKI White
#ThreatIntel #Malware #InfoSec
📡 IMSI-Catcher – Detect Nearby Mobile Network IMSIs Using Low-Cost SDR
IMSI-Catcher is an open-source GSM research tool that captures and displays IMSI and TMSI identifiers from nearby GSM traffic using affordable SDR hardware like RTL-SDR, HackRF, BladeRF, or OsmocomBB. It supports Wireshark integration, GSM frequency scanning, IMSI tracking, and logging to SQLite, MySQL, or text files. Built for learning GSM network protocols and security research in authorized environments.
🔗 https://t.co/8K5RN0UIwQ
#CyberSecurity #SDR #GSM #WirelessSecurity #OpenSource
LLMs can now autonomously generate fully functional Mythic C2 agents from a single prompt. Built, tested, and deployed in under 2 hours. No human in the loop.
SpecterOps built a framework called Oracle that takes a prompt, generates the agent code, compiles it, deploys it to a Mythic server, tests every command against a live Windows target, runs QA validation, and ships a release build.
Tested across Python, Go, Zig, C#, and Rust. Every generated agent is unique and disposable.
If every engagement gets a fresh LLM-generated agent, static signatures and YARA rules are fundamentally unable to keep up. Defenders need to rethink detection around behaviour, not artifacts.
https://t.co/pDxFso5wtk
Author: @_xpn_@SpecterOps
#RedTeam #ThreatIntel #InfoSec
Two PatchGuard defeats. Ring-0 arbitrary code execution via a debug register exception vulnerability. A DLL injector using Windows address sanitization and CoW that makes injected pages invisible to NtQueryVirtualMemory and NtReadVirtualMemory. Capcom driver exploitation with SMEP bypass. Speculating the entire x86-64 instruction set using undocumented instructions. Built VTIL, a custom IL for binary deobfuscation and devirtualization, and NoVmp, a VMProtect 3.x static devirtualizer on top of it. Reverse engineering a $30B exchange with IDA Pro.
PgC defeated PatchGuard in 200 lines of code. Sat on it for 7 years. Changed 1 line to keep it updated.
All free. All published with full source.
One of the most underrated researchers in the Windows internals space. Background in game hacking, zero self-promotion, just publishes and moves on.
Blog: https://t.co/L8OOa3o2Cd
VTIL: https://t.co/4D3uFOuXG1
NoVmp: https://t.co/Uz64cHvmBz
Author: @_can1357
#WindowsInternals #ReverseEngineering #ExploitDevelopment
UPDATE 🠖 FortiBleed looks bigger than first reported.
Update: Hudson Rock says FortiBleed targeted 73,932 Fortinet firewall URLs across 194 countries, affecting 21,632 domains.
The bigger risk: exposed FortiGate SSL VPNs may be used as listening posts to capture more credentials and keep the access loop going.
Read the full update: https://t.co/r8VrvtdCie
I cannot overstate how powerful codex is for cybersecurity work.
I'd encourage all defenders to sign up for Trusted Access for Cyber (https://t.co/e1Mh8aZArY) and give it a shot for their workflows.
If orgs are slow to get TAC approvals, please reach out to me.
‼️🚨 Unauthenticated attackers are gaining SYSTEM on domain controllers with crafted packets.
The vulnerability being exploited is CVE-2026-41089, a CVSS 9.8 hole in Windows Netlogon, and exploitation in the wild has been confirmed.
A patch has existed since May 12. Every DC still behind is not just vulnerable, but according to the Centre for Cybersecurity Belgium are also actively being pwnd.