Someone dropped this Windows LPE writeup online yesterday along with a PoC.
But the mentioned CVE-2026-62737 is not released yet, maybe it will be in the Patch Tuesday tomorrow.
And the PoC still work in the lastest version of Windows 😂
https://t.co/rcOasDPOV7
ResetNightmare POC - a validation flaw in the Kerberos Change Password protocol that allows for resetting the password of any target user/computer account, without knowing the current one.
https://t.co/b0LW72pQOp
🥷𝗗𝗲𝗳𝗲𝗻𝗱𝗶𝗻𝗴 𝗮𝗴𝗮𝗶𝗻𝘀𝘁 𝗞𝗲𝗿𝗯𝗲𝗿𝗟𝗼𝘀𝘀 (𝗖𝗩𝗘‑𝟮𝟬𝟮𝟲‑𝟮𝟱𝟭𝟳𝟳)
https://t.co/6QB4v4joOW
Hidden characters can create duplicate objects that look identical—but aren’t. My latest KQL detection hunts these ghosts in your directory before they haunt your domain.👻
https://t.co/8GLsZenkfs
#KerberLoss
OGhidra
It bridges Large Language Models with Ghidra's reverse engineering platform, enabling AI-driven binary analysis through natural language. Analyze binaries conversationally, automate complex workflows, and maintain complete privacy with local AI models.
Resource/Source: https://t.co/K7bADQyxXt
CVE-2026-34348 exploitation demo from my #BHUSA "Pass-the-Passkey Family of Attacks" talk: WebAuthn assertion from recent YubiKey authentication is extracted from Windows Event Log and replayed against Microsoft Entra ID using Passkey Injector.
Whitepaper: https://t.co/bp5sriMB5z
You don't need a USB. You need to look like one.
Emulate the device, Windows fetches a signed package off Windows Update and runs vendor code as SYSTEM. Arbitrary code execution, LPE, standard user or empty logon screen.
DEF CON 34 talk w/ @Qm9yamFN.
Link at the first comment.
Hey, hackers! 👋🏻
I hope this note is bookmarked on your belt!
It contains awesome pdfs including:
- Red team Operations
- Reverse engineering content
- Red Team x Blue team
- Practical social engineering
- Windows Privilege escalation
- AD, & Road to OSCP
- JR to Specialist career
- Many Offsec notes
- & Many more
Thanks to Joas A Santos
https://t.co/NntQfKxejU
(I recommend you to follow his profile on Linkedin)
#cybersecurity #Pentesting #Hacking #bugbountytips #infosec #cybersecuritytips #redteam #coding #100DaysOfHacking #vulnerabilities #BugBounty #100DaysOfCyberSecurity #CyberSecurityAwareness
nanonets/graft: Turbocharge Claude Code, Cursor, Codex, Gemini & every coding agent: faster, cheaper, with contextual understanding specific to your codebase. https://t.co/JtEp5aIMGg
Forgot to post about this, its still being worked on but its a universal Linux LPE for 6.x up to 7.x :”).
Will be released; publicly on many mirrors so cuckrosoft and cuckhub don’t ban me again like they did when I RE the flock cams, cheers!
@cyb3rops how about this big boy?
Open-source OffSec model for local Run, A 35B MoE (only 3B active) specifically for autonomous real offensive security agent workflows.
No more fabricated Nmap output or No more infinite loops.
- SecEval 81.39% (#1)
- MITRE ATT&CK 93.94% (#1)
- CWE 93.05% (#1)
- Fine-tuned for real pentest agent workflows
- Real structured tool calls
- Correct agent routing
- Clean termination (24/24 in their eval)
- Zero fabricated observations or recon
actually works with a real harness, Worth testing if you’re building local red team agents.
GGUF quants available.
New ARTOC review just went up. 👀
A student who'd never touched Cobalt Strike before taking it walked away calling the redirectors and cloud C2 section the standout after testing against a live CrowdStrike deployment in the lab.
Full review. ➡️ https://t.co/F48kCdTdCE
A handy .NET reverse engineering trick:
Add a sample.exe.config file next to your sample and you can trace e.g. all network requests, including content and headers without hooking or bothering with proxies. Helpful to e.g. quickly inspect c2 traffic:
https://t.co/WE6gFSQAkg
Awesome Cyber & AI Arsenal
A curated, battle‑tested collection of offensive, defensive and AI‑powered security tools.
Source: https://t.co/7k8lKfUbSm
Three zero-days in Windows 11 and Microsoft Entra ID. Over 20 novel attack techniques against passkeys. Toolkit open sourced. Microsoft declined to fix one of them.
Passkeys were supposed to be unphishable. @MGrafnetter from @SpecterOps just presented Pass-the-Passkey at Black Hat.
Global Admin impersonation from a standard user account. No user interaction. Bypasses phishing-resistant MFA Conditional Access policies. Zero alerts from Defender for Identity or Entra Identity Protection on M365 E5.
Windows Hello passkeys are still vulnerable after the patches because they always send signature counter 0.
Microsoft scored it 6.5 Medium and paid $1,000. The researcher scored it 8.6 High. Their advisory described it as 'could potentially read small portions of heap memory.'
This is the same team behind BloodHound, Certified Pre-Owned (AD CS), Rubeus, Certify, Seatbelt, SharpDPAPI, SharpUp, Ghostwriter, Nemesis, SharpSCCM, and CuddlePhish. They consistently ship research that changes how the industry thinks about Active Directory and identity security.
If you do red teaming, pentesting, identity security, Entra ID, FIDO2, WebAuthn, Windows Hello, phishing-resistant MFA, or detection engineering, this is the most important identity research to drop this year.
Pass-the-Hash for the passwordless era.
https://t.co/zZgx8JP89F
#Infosec #RedTeam #DetectionEngineering
My #BHUSA 2026 slides are online!
It was an honor to share our AFD research and how a different perspective led to 30+ Windows kernel vulnerabilities.
Blog post coming soon — check out the slides here:
https://t.co/l8xIaRtL7V
‼️ BREAKING - A newly discovered #WordPress pre-auth XSS affects every version.
XSS2Shell (CVE-2026-64638) can run attacker-controlled JS in a site's origin without a login. With a logged-in Administrator, one click, and required deployment conditions, it can be chained to PHP code execution.
Update your WordPress sites ASAP 🠖 https://t.co/WxHpU2DkIC