Pentester | MD (Intensivist & Healthcare Simulation in another life) |
Infosec, Geopolitics, Defense, Hybrid warfare, DCS, Gaming, Metal
Opinions are my own
We built four malicious skills to test whether skill scanners actually work. Three took less than an hour to conceive and implement. ClawHub, Cisco, and Vercel's https://t.co/nUlnRcQWyG marked them as safe. đ§”
This has quietly been a miracle month in medicine.
In the last 5 weeks weâve got news on:
- retatrutide, the triple agonist GLP-1 from Lilly, basically melting fat and body-wide inflammation at record levels
- RevMedâs new pancreatic cancer drug showing unprecedented abilities to extend life
- small trial of a one-and-done PCSK9 gene editing therapy for slashing LDL cholesterol
- Mayoâs AI-assisted radiology showing vastly improved cancer detection
- this new therapy for metastatic solid tumors
This stuff is at varying levels of evidence. Retatrutide is ~100% on its way, other stuff needs more clinical trial data. But put it together and weâre maybe on the verge of majorly reducing the mortality of heart disease and cancer, the two leading causes of death in America.
> Published a tool for Security Researchers.
> Added features & Fixed 10+ IoCs and major bugs.
> Pushed it to my repo
> Got shadow banned on github.
This is how security researchers are treated. Weâre very disappointed @github. Kindly fix the issue.
Token id: #4440743
#issue
Small QOL update for NetExec: Ctrl+C will now immediately exit NetExec without any weird stack tracesđ
However, keep in mind that this still does not exit gracefully, but immediately kills all existing threads. Only do so if necessary.
Made by @T1erno_
0days-in-the-Wild â Real Zero-Day Exploits Analyzed by Google Project Zero đđ„
Want to study how real-world zero-days happen?
âą Tracks vulnerabilities actively exploited in the wild
âą Includes detailed Root Cause Analysis (RCA) reports
âą Covers browser, mobile, OS, and enterprise software exploits
âą Shows exploitation trends, bug classes, and attack techniques
âą Maintained by Google Project Zero researchers
Instead of learning from theoretical examples, this repository lets you study actual zero-days that attackers used against real targets.
đ https://t.co/zGYKKXyNnj
#ZeroDay #ThreatIntelligence #GoogleProjectZero #CyberSecurity #InfoSec #RedTeam
Tools like Snaffler are great, but crawling SMB shares creates a telemetry nightmare. You instantly light up the SIEM with :
- 5140 / 5145 (Network Share Access)
- 4656 / 4663 (Object & File Access)
So I built Invoke-WindowsSearch to query the native Windows Search DB (OLE DB) directly via WinRM/RPC, It extracts the targets without touching the actual files, completely bypassing the 4663 and 5145 detection footprint.
Trade-offs: Requires the WSearch service (disabled by default on Server OS) and lacks complex regex capabilities. Know your environment before execution.
#RedTeam #ActiveDirectory #OPSEC #ThreatHunting #PowerShell
llama.cpp now has an official website: https://t.co/vztdUpdBWL
Our goal is to make local AI accessible to everyone, and improving the user experience is a big part of that. On the new landing page youâll find a single-line cross-platform installer. The installation provides a single unified `llama` entrypoint which you can use to run/serve models and interface with 3rd-party agentic applications.
While oriented towards simplified user experience, the new `llama` application also provides all the advanced functionality of the existing llama.cpp tooling with which experienced users are already familiar. Also note that all GGUF models that you might have already downloaded with llama.cpp in the past will be automatically available to use without downloading again (they are stored in the common HF cache on your machine).
We have many improvements in the pipeline both at the UX and at the engine level and we plan to iteratively ship new things over the coming months. One of the main focuses will be seamless integration with local-friendly 3rd-party agents (such as Pi). In the meantime, weâll continue to listen for feedback from the community and adjust accordingly, so keep letting us know what you think and need.
âïžđš BREAKING: Security researchers are now handing Nightmare-Eclipse vulnerabilities for free, in what looks like both a show of support and a reaction to how Microsoft treats researchers. First up: "Bitskrieg," violates Secure Boot trust and fully bypasses BitLocker.
It seems aimed squarely at Microsoft's recent blog, where the company said its Digital Crimes Unit would bring cases against threat actors "and those that enable their criminal activity," language many researchers read as a threat pointed at them.
Big news for @NVIDIAAI Blackwell users!
nvidia/Qwen3.6-35B-A3B-NVFP4 spotted on @huggingface đ
https://t.co/cyrgvbTnp3
Great model for your local agent teams!
Phishing sandboxes donât play fair.
In his latest blog, @synzack21 walks through a real red team engagement against modern email sandboxes and techniques that helped keep payload redirects hidden from crawlers while preserving a familiar user experience. https://t.co/jdCGMLGNWa