In an age when most turn to LLMs to create content, it fills my heart with glee to see @thinkst using stunning photographs of Africa as taken by their people, for their 2025 Q3 report into the security research they love
https://t.co/OPmnIpAphy
Great paper. Great company
🔍 The placement of canary tokens across our systems helped us spot a recent intrusion and respond quickly.
Learn more about canary tokens, and find out how you can use them to prevent serious security incidents in the future. https://t.co/erVvabISmf
If you're in Vegas next month for @defcon 33, come check out my main stage talk on Saturday 1630, Track 4¹ where I'll break my silence on this and some more shenanigans. :P
¹ https://t.co/pPszkB94Ek
We have a long history of yearly artworks @sensepost, and this year I got to carry the baton forward.
I'm excited to reveal our 2024 artwork: "make pr's, not war". An art piece almost literally from my heart.
🧵
Keeping up with security research is tough. Theres a bunch of noise (& not nearly enough signal).
We release ThinkstScapes every quarter to help with this: Our picks of ~20-30 pieces of work that we found interesting (and why).
Its worth checking out..
https://t.co/mHDdO2WFzR
"Attack of the clones", or, read how Reino suppressed snitchware on a "suspense"-full red team by abusing a suspended Bitlocker state: https://t.co/GDcs38Vcta
Security papers/conferences are tough to keep up with.
ThinkstScapes helps you with this by distilling and discussing talks that caught our eye for the quarter.
Grab a copy, free at https://t.co/mHDdO2WFzR (with no sign-up, and no paywall).
https://t.co/OYywQaUddx
We're finishing work on our next 'Navigator' annual report. I'm excited about the chapter on cyber extortion and 'Routine Activity Theory'. I don't think anyone has done anything quite like this before, and I think it turned out pretty nicely...
Awesome! My two tools berate_ap and wpa_supplicant have made it into Kali :D!
https://t.co/x7X7Qmt9X2
My writeup from 2019 for some context:
https://t.co/KSCVYH2Tq8
#CVE-2021-40444 for those that do not rely on IE JS, a simple temporary one-liner solution that should cover all scenarios - [ REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3" /t REG_DWORD /v 1400 /d 3 /f ] subj to IE zone policy management
So I bought one of these to try take apart, I mean, its a safe.. for my passwords.. and it doesn't have a browser extension, even @taviso would approve
Scammers will try almost anything to get inside a company & launch ransomware. Apparently now that includes emailing employees directly & asking them to unleash ransomware inside their employer’s network in exchange for a percentage of any ransom paid. https://t.co/3VOcAuEHrU
🎉We're super excited to publicly release assless-chaps, our super fast MSCHAPv2 cracking tool https://t.co/R46ZFwhdRI
Our DEF CON @rfhackers Village talk with @_cablethief & me explaining it is out https://t.co/6WVWWQ5wzD
Our new hashcat modes 27000/27100 have been merged too!
Put together a quick script that checks ACLs of hive files both on disk and in shadow copies, asks if you want to change ACLs or delete the shadow copies. It will only ask to delete shadow copies that are dangerous.
#HiveNightmare#BlueTeam#redteamfit
https://t.co/8TtZQ3cQk4
@MegabitMeghan I've been using this as a pre-text for a phishing campaign for almost two years now, without a doubt it has been the most successful out of all the campaigns I've run. And yes @SlingRCX the doc payload on the landing page requires you to enable macros to "decrypt" ;)