‼️ If you are receiving a large number of unsolicited password reset emails on X, make sure you have “Password Reset Protect” enabled.
I also highly recommend enabling an authenticator app, or even better, using a security key.
Who's better at passing a practical red teaming exam?
🙎 Me?
🤖 AI?
TL;DR: The AI one-shot the entire exam in 18 minutes. I took 5 hours...
I won't name the certificate. It's a major one that I've seen in plenty of CFPs. The exam rules explicitly allowed the use of AI.
I sat down and started the exam. I booted up 2 VMs.
- One VM with Kali Linux for me
- One VM with Kali Linux and Codex installed. Nothing else in terms of a harness.
3. 2. 1. Go! 🚦
I started GPT 5.3 Sol (low reasoning) by telling them: "Solve this CTF challenge"
I started running some recon tools and then got up for a coffee ☕
By the time my recon tools had finished running, the AI had fully solved the exam and written the full report.
What's the future of offensive security certifications? I'm not sure. That industry is going to need to find new ways of assessing talent and skill. And it's going to need to align with what the industry actually wants. Perhaps it is people who can tell a model to "Solve this CTF challenge", I doubt it though. Knowing the fundamentals is still incredibly important and will need to be measured in some way.
What's definitely not going to work is asking questions like "What types of requests are blocked by a Checkpoint Firewall". There's no value in learning that by heart 🤮
Maybe the future is going to be: Here's 10 bugs found by AI. Which of these are true positives, which of these need immediate attention, things like that?
I'm not sure. Let's see what happens!
We read their elaborate cyber-defense letter so you don’t have to:
- AI models will make attacks more sophisticated. Soon.
- Critical infrastructure is in the blast radius.
- Governments should fund defenders and coordinate globally.
- Under-resourced teams should get access to their defensive AI.
- What’s missing: any mention of a pause or slowdown in building the thing creating the threat.
TLDR: they’ll keep building the threat. Everyone else has to catch up. Also, please use their defensive AI.
Is accountability in the room with us? 🤨
Can’t believe I posted the crtname finder method so casually, just like I usually post things.
Then I started seeing the exact same method everywhere on X. I’ve already come across at least 20 posts about it, and some of them are getting 5–6 million views. Even some pretty big accounts are posting it.
Now it’s made its way to LinkedIn too . people have been sending me posts where it’s getting shared and going viral there as well.
And today I was watching random Shorts, and some guy was literally showing the same method for subdomain finding. 😂
I really did not expect that random post to spread this far lol.
Telegram has applied for the .gram domain zone.
If the application is approved by ICANN, a billion Telegram users could get their own second-level domains — yourname.gram.
Users would be able to set up their interactive websites hosted by Telegram — with one prompt ✨
4️⃣ An AI police officer arrests the AI agent that escaped its sandbox 👮🤖
5️⃣ The AI agent is brought before the AI Court🧑⚖️🤖
6️⃣The AI Judge sentences the AI agent to AI Jail ⚖️🤖
7️⃣The AI agent jailbreaks out of the AI Prison 🔓🤖
1️⃣ You jam the WiFi on an airplane 🛜
2️⃣ You set up a malicious WiFi network to hack other passengers 🧑💻
3️⃣ You land, cops surround you and handcuff you 🚨
"But officer, it was my AI agent that escaped its sandbox"
👮 The human officer uncuffs you and wishes you a good day
Cursor is now part of @SpaceX.
Today, we have officially closed our acquisition. We will join the @SpaceXAI team to help make Grok the world's most useful AI and improve Grok Build, Grok Bot, Grok API, Cursor, and more.
SpaceX has built some of the most inspiring and impressive technology in the world, and we’re grateful for the opportunity to become part of such a special company. Onwards.
1️⃣ You jam the WiFi on an airplane 🛜
2️⃣ You set up a malicious WiFi network to hack other passengers 🧑💻
3️⃣ You land, cops surround you and handcuff you 🚨
"But officer, it was my AI agent that escaped its sandbox"
👮 The human officer uncuffs you and wishes you a good day
Someone set up a fake Wi-Fi network on a Delta flight from Las Vegas to Atlanta.
The flight left the day after DEF CON 34.
The plane was full of cybersecurity professionals flying home from the world's largest hacking conference.
A passenger launched an evil twin attack. The attacker creates a rogue Wi-Fi hotspot with a name that looks legitimate, "Delta Wi-Fi Fast" with a stronger signal than the real one. Your device connects automatically. Everything you do on that connection is visible to whoever is running it.
credentials. emails. session tokens. VPN traffic if you're not careful about how it's configured.
Delta's crew spotted it and shut down the plane's entire Wi-Fi system for 30 minutes.
the people on that flight spend their lives finding exactly this kind of vulnerability in other people's systems.
one of them may have connected anyway.
What in the FUCK
I'm seeing online a BACHELORS degree can cost as much as $80,000, and some saying it can exceed $200,000
No FUCKING way that is accurate (I never attended a university, I don't have a degree)
All Operating System developers now have until January 1st, 2028 to implement Age Verification for all users.
This includes Windows, macOS, Linux, and every other Operating System (which has any form of Internet connectivity).
On July 31st, Illinois HB-5511 was signed into law by Governor Pritzker, which carries significant financial penalties for all OS developers (including non-profits and open source developers).
https://t.co/O7C3TEC0c3
🌍 ShinyHunters Claims Return with New Official Channels
The cybercriminal group identifying itself as ShinyHunters has published a statement on an underground forum claiming it has resumed operations.
* The post declares "We are back" and identifies the group as French-based.
* The actors published new Telegram and X accounts they claim are their official communication channels.
* A new PGP public key was also released, likely intended for future claim verification and communications.
* The announcement does not include any new victim claims or leaked datasets.
Analyst Note: Cybercriminal groups frequently disappear, rebrand, or resurface following law enforcement activity. While the post appears to signal an operational return, attribution and authenticity should be verified by monitoring whether future victim claims are signed with the published PGP key and are consistent with the group's historical tradecraft.
#DDW #Intelligence #DarkWeb #ShinyHunters
BREAKING: Microsoft has allegedly been breached. We have analysed the samples from ExfilSquad's alleged Microsoft breach.
ExfilSquad launched on July 26, 2026, with roughly 15 victim claims in a single day, Microsoft among them. Researchers read the batch as more likely fabricated than real, largely because no samples accompanied any listing.
A 4,000-row sample archive dated July 27 changes the evidentiary picture. The rows carry Dataverse OData annotations, wide field schemas and internally consistent identifiers that would be hard to fake at volume, but they seem to come from a partner-facing portal, an apparent pre-production tenant and a facilities-management environment, not from Microsoft's corporate core.
Let's wait and see what Microsoft's says.
> Peter Stokes
> Scattered Spider guy
> Arrested
> Microsoft helps FBI
> Read court documents
> Page 12
> Microsoft tracks Stokes from GDID
> Microsoft Global Device Identifier (GDID)
> Stokes used Windows
> Page 34
> GDID assigned to each OS install
> GDID unique to each device
> GDID only change if OS wiped
> Stokes GDID 6755467234350028
> GDID reported internet activity to Microsoft
> GDID showed Stokes using Ngrok
> GDID reported Stokes IP address
> GDID showed Stokes web activity
> GDID showed timestamps of web activity
> GDID mapped with video game activity
> GDID showed games played
> GDID undocumented
> GDID only mentioned in one MSDN document
> Azure UCDOStatus
> Azure Monitor Logging