I'm excited to be able to finally publish the public disclosure for CVE-2026-4387. Check out my blog on discovering the reuse of the state.kv file to get authenticated sessions with StrongDM (now fixed). https://t.co/IbS1IjPxJL
Phishing sandboxes don’t play fair.
In his latest blog, @synzack21 walks through a real red team engagement against modern email sandboxes and techniques that helped keep payload redirects hidden from crawlers while preserving a familiar user experience. https://t.co/jdCGMLGNWa
Just added krb5 auth over ADWS in my tool SOAPy. I noticed since SOAPy released 2 yrs ago with the first ADWS python code nobody had implemented krb5 auth in python.
Check it out here, and stay tuned for an upcoming blog post + big release 👀
https://t.co/PvIQC4iWlh
NTLMv1 is still out there. And now it’s easier than ever to break.
@skylerknecht walks through how Google’s rainbow tables make NT hash recovery practical, no third-party service required.
Check it out! ⤵️ https://t.co/AoC1NFBNK1
I explored how privilege connects DevOps and MLOps into attack paths that are often missed in traditional threat models. I will be presenting this at #SOCON2026 next week.
@ArmadinSecurity Research here 👇
https://t.co/kG7hiH3RWZ
Pasting API keys in an LLM makes me feel kinda gross, so I created agentcordon. It's an agentic key vault that's:
✅Agent agnostic
✅Cedar policies for clear authorization
✅Fully auditable
✅Remote MCP Support
I got tired of manually doing the "enum DNS -> figure out which ones are live -> request each one in the browser to populate Burp target sitemap" loop ad nauseam. I built a lightweight command line tool + Burp extension to automate this entire process.
Simply run the tool with very basic args, load the extension, and get everything into your Burp project with no hassle.
Also really nice for passive checks (--no-nmap) in the pre-sales/scoping process with prospective clients to get an idea of what all they have actually exposed from an application standpoint at a birds-eye view.
Enjoy.
https://t.co/kqr780RSFx
Idk what happened but the end of last year MSRC was quick, responsive, and overall just better. Lately it's a ghost town with auto responses and no updates.
everyone freaking out about quotes dropping
haven't people been warning about this for weeks? that everything was heavily subsidized and wasn't sustainable?