I really wish browsers would hurry up and implement private-network-access, developers often don't understand the implications. This weekend I tried a random flashcard application for language learning... and it started a localhost web service 😔
Someone just vibe coded a full 3d flight simulator in a single weekend using Claude Code.
it runs entirely in the browser. real-world terrain. real locations. you can literally fly anywhere on earth.
Giving away 2x full access packages:
Linux Attack, Detection & Forensics v2.0 - Hands-on Purple Teaming Playbook + 90 days PurpleLabs VPN access
To enter:
✅ Follow me
❤️ Like this post
💬 Comment
🔁 Repost
Winners announced March 22nd 🎯
First time doing this, let's see how it goes 😄
https://t.co/SUktIBXgHt
#linux #redteam #blueteam #dfir
We’ve been digging through the #React RCE mess for two days now, trying to get at least some visibility into what’s going on out there. None of this is easy to detect, and most signals vanish in memory before you can even look at them.
My teammate @_swachchhanda_ put together a pair of #Sigma rules that cover the one thing that reliably shows up when someone actually executes code on a Node.js server -> child processes. One rule for Linux, one for Windows. It’s not a silver bullet, just one of the few angles that makes sense right now.
We pushed all our #YARA and #Sigma signatures for the React RCE cases as well, and contributed the Sigma rules upstream:
https://t.co/37MnloL5oV
This whole situation shows how much attack surface lives in places many of us didn’t think about before. I expect we’ll see more of this class of issues now that people realize what’s possible.
https://t.co/8GiM1IwUxb ← Call for articles & art for issue #8 of this technical IT zine is open! As usual, we accept 1-page articles about everything interesting in IT and related fields (be it programming, cybersec, AI, demoscene, retro, electronics, etc).
Bugbounty Tip: Find api paths from a domain using Jsmon and make a wordlist out of it.
Then, scan API hostnames with ffuf, kiterunner or other fuzzing tools.
ffuf -w wordlist.txt -u https://api.[target].com/FUZZ
Always respect the rate limitation policies of a program while fuzzing.
🚨 Doing a giveaway for my Blind XSS Masterclass
Most people think they know XSS, until they meet blind XSS, the kind that fires where you’ll never see it.
Same methods that helped me earn $250K+ from real reports. https://t.co/VL5jwf8alx
🎁 Retweet and reply to enter.
Windows kernel exploitation for beginners
Part 1: https://t.co/nNTKqtgmA4
Part 2: https://t.co/QwbNVNNyt2
Part 3: https://t.co/f1hRv93yrB
Part 4: https://t.co/vS1SUVUF0c
Part 5: https://t.co/2aDetUK8g1
#windows#infosec