Microsoft has failed to properly patch RoguePlanet (CVE-2026-50656), ShieldBreak, a PoC that demonstrates a full bypass to the previous patch is now public.
https://t.co/YFfn559z6o
The PoC works with the latest August 2026 patch
👋Joined @watchtowrcyber
💀 Implemented IKEv2 protocol in Python
🩸Pre-auth RCE on VPN
This was a fun exploit which on paper is simple but turns out a bit more tricky to pop a reverse Python shell against the (in)famous WatchGuard CVE-2025-9252 🔓
Aaaaaaand... We have a lift-off!
Pre-sale of RTO: MalDev Advanced (Vol.2) is now open!
Ends: Sep 30th (20:00 Zulu)
Course release date: Oct 1st (12:00 Zulu)
Diving into Windows kernel...
You can't miss it!
https://t.co/JZt5wBlE8R
#RTO#redteam#onlinelearning
So MSRC first say that they cannot reproduce ,now say that no security boundary is crossed. Tested this on few different machines and it was successful on all of them.
This is bug in GamingServices , non default service so impact is not high.
https://t.co/ZH4jhQUhMT
#Lazarus exploited a flaw in the Windows AppLocker driver (appid.sys) as a zero-day to gain kernel-level access and turn off security tools.CVE-2024-21338
Beyond BYOVD with an Admin-to-Kernel Zero-Day
https://t.co/irFNz3Dntt
Four years after publishing my code stealing passwords from WinLogon I have just realized that NPLogonNotify() has a twin!
NPPasswordChangeNotify() obtains old and new cleartext passwords changed via CtrlAltDel. Clearly documented by MS and easy to use: https://t.co/lXiIELh7SI
Should iexpress.exe count as #LOLBin? 🤔
It's "only" 14 lines of a batch file but the real question is: WHY iexpress is still included in the default Windows installation?
BTW please let me know if you have any idea how to make the .sed file smaller.
If you are looking for an easy way to access O365 refresh tokens when landing on an endpoint, have a look at the log files on the endpoint stored in "%localappdata%\Microsoft\Olk\EBWebView\Default\Session Storage\" [1/2]
Use .contact file attachments for your malicious URLs. More than half of your malicious emails aren’t even reaching the target inbox and it’s sad. You can use .vcf too but the URL isn’t clickable. Make attachments malicious again. Happy holidays!
Not sure if it's new or interesting but when Discord launches, it tries to execute `C:\Program Files\NVIDIA Corporation\\NVSMI\nvidia-smi.exe`. Would be a shame to hijack that non-existent bin if user's have Discord set to launch on Windows startup.
Presenting my research at @defcon was incredible!
The repo for my tool #NoFilter is:
https://t.co/dx2PzQEATB
Slides available here:
https://t.co/q9AXD8ARn1
The research will be published as a blog post soon
#DEFCON#DEFCON31
Ok fellas... Let me teach you a nice trick... For 10$ you can get this and turn it in a portable microscope for inspecting PCBs #HardwareHacking#ProTip
You are welcome 👍😎