Got an ethical pentest for a kiosk-esque environment, but you're stuck in a browser? Have access to websites, but have a need to go deeper?
Look no further! With https://t.co/gSWLVmmkVq you have access to tools that enable lateral enum, calculator://, file browsing, and more!
Completely nerdsniped myself today and expanded on this. New source in the same place:
https://t.co/a1MM5wLw7g
Now looking for reappearance across multiple git instances (one can hope) and automatically tracking if there's a hit.
Follows his blog too. Adding rss for tweets l8r
Yesterday I wrote a scraper to monitor NEs GitLab account in case they drop anything interesting.
>mfw I deploy it, and it doesn't work.
Between testing the script locally and deploying, gitlab dropped their account. π
Heres the sauce regardless:
https://t.co/a1MM5wLw7g
Yesterday I wrote a scraper to monitor NEs GitLab account in case they drop anything interesting.
>mfw I deploy it, and it doesn't work.
Between testing the script locally and deploying, gitlab dropped their account. π
Heres the sauce regardless:
https://t.co/a1MM5wLw7g
GitLab has apparently taken down the Nightmare-Eclipse account just days after the researcher moved there following the GitHub ban.
The drama started after Nightmare-Eclipse released several Windows exploits and Defender bypass tools, including BlueHammer, RedSun, and UnDefend. GitHub removed the account earlier this week over concerns that the tools could be misused and weaponized.
Security company Huntress says some of the tools have already been seen in real-world intrusion cases, showing how quickly proof-of-concept research can end up being used in actual attacks.
βοΈ **NEW BLOG:**
Malware can be stopped by taking down infrastructure.
What if the Defenders could not rely on this techniqueβ
I investigated how Nostr's censorship resistant model could be used as robust comms for Malware.
Read more about it here:
https://t.co/l0TjomHRcJ
ChatGPT wont help with malware but if you just start with a base, GPT-5.4 will gladly help you via opencode. It won't pick up the context clues.
Just dont mention the malware is malware.
I had a blog post in mind, "scraping with scraps" where I would've used the Vultr free tier VPS for a free crawler setup. The need for this lightweight scraper has been **completely** killed.
Here's the docs:
https://t.co/qUZA3SW6eT
https://t.co/9hiKE78hHt