Chrome 137+ added a CNG wrinkle to App-Bound Encryption.
@harmj0y.bsky.social & @tifkin.bsky.social share how Nemesis 2.2 handles it, automating DPAPI decryption from SYSTEM & user masterkeys through Chromekey1 to cookie/login recovery, w/ retroactive artifact linking. https://ghst.ly/3OzfkFN
04.03.2026 18:08
👍 0
🔁 2
💬 0
📌 0
What’s Running on That Port? Introducing Nerva for Service Fingerprinting
What’s Running on That Port? Introducing Nerva for Service Fingerprinting
02.03.2026 17:39
👍 0
🔁 1
💬 0
📌 0
Havoc Professional Release
The initial release of the long awaited Havoc Professional and the Kaine-kit is finally here and new team member.
Havoc Professional Finally Released! 🕸️🕷️
I'm excited to finally share the work my team and I have put in over the past year. This is just the beginning of what we have planned.
www.infinitycurve.org/blog/release
24.02.2026 01:50
👍 5
🔁 4
💬 0
📌 0
Don’t expose yourself in public — let AWS error messages do it for you
AWS now reveals public permissions in error messages. Learn how a deny-all session policy exposes which actions would succeed safely.
Hey wake up! New offensive AWS meta just dropped! Thanks to Daniel Grzelak, we now have an effective oracle for determining if resources are publicly exposed without leaving logs. (As an offsec person) LFG!!!
www.plerion.com/blog/dont-ex...
20.02.2026 15:43
👍 2
🔁 2
💬 0
📌 0
On Apple M3, a Linux KDE plasma desktop under Fedora Asahi Remix is now WORKING! Super excited to share this update and happy to answer any questions! Co-credits to noopwafel and Shiz. :)
26.01.2026 11:26
👍 413
🔁 69
💬 15
📌 11
On the Coming Industrialisation of Exploit Generation with LLMs
Recently I ran an experiment where I built agents on top of Opus 4.5 and GPT-5.2 and then challenged them to write exploits for a zeroday vulnerability in the QuickJS Javascript interpreter. I adde…
We are on the verge of the commoditization of exploitation. Every vuln will functionally have a public PoC available because attackers can generate them in minutes.
The advantage will increasingly belong to organizations that can detect, respond, and contain fast.
sean.heelan.io/2026/01/18/o...
19.01.2026 03:24
👍 6
🔁 2
💬 0
📌 0
Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8554 | Datadog Security Labs
A look at how Kubernetes CVE-2020-8554 works
I've been meaning to write more about "the unpatchable 4", which are a set of Kubernetes CVEs for which there are no patches, you need to mitigate them with configuration or architecture choices.
First up is CVE-2020-8554.
securitylabs.datadoghq.com/articles/unp...
14.01.2026 09:46
👍 11
🔁 6
💬 0
📌 0
LOC record - Wikipedia
TIL: On peut mettre des coordonnées GPS dans un record DNS !
en.wikipedia.org/wiki/LOC_rec...
Pour tester ça : on se retrouve à l'adresse une-tasse-de.cafe le 12 & 13 février 😇
09.12.2025 15:36
👍 8
🔁 2
💬 0
📌 1
'Unauthorized' Edit to Ukraine's Frontline Maps Point to Polymarket's War Betting
It looks like someone invented a fake Russia advance in Ukraine to manipulate online gambling markets.
So it sure looks like someone invented a fake Russian advance in Ukraine to manipulate the online gambling market Polymarket. Gamblers are making money by betting on the outcomes of battles big and small in the war. Edited map is run by DC-based think tank
www.404media.co/unauthorized...
01.12.2025 18:48
👍 251
🔁 111
💬 13
📌 37
TOAD Attacks via Entra Guest Invites
A new reverse phishing campaign uses Microsoft Entra Guest invites to bypass email filters.
Actual threat intelligence! A few friends and I identified a new reverse phishing campaign leveraging Entra Guest User invitations.
This campaign was newly discovered and corroborated. I recommend reviewing organization email for these invitations.
taggart-tech.com/ent...
14.11.2025 18:12
👍 5
🔁 4
💬 0
📌 1
Insiders – Now free for everyone - Material for MkDocs
We just released 9.7.0 – the final version of Material for MkDocs, which includes all features that were previously exclusive to sponsors
📣 Material for MkDocs Insiders now free for everyone!
With 9.7.0, we release all Insiders features previously exclusive to sponsors! This marks the last version of Material that includes new features, as we now enter maintenance mode.
A thread ⬇ 1/4
squidfunk.github.io/mkdocs-mater...
11.11.2025 16:21
👍 8
🔁 4
💬 2
📌 0
Same, I followed their webinar and now I'm less worried about getting replaced by AI :)
13.11.2025 19:34
👍 0
🔁 0
💬 0
📌 0
Nano Banana can be prompt engineered for extremely nuanced AI image generation
Nano Banana allows 32,768 input tokens and I’m going to try to use them all dammit.
New blog post up: I spent a lot of time researching Nano Banana, Google's new generative AI model, and not only is it substantially better than ChatGPT, it is capable of taking extremely nuanced prompts even thousands of tokens long to generate exactly what you want. minimaxir.com/2025/11/nano...
13.11.2025 17:40
👍 26
🔁 3
💬 0
📌 0
"I did give a heads up to Elastic before publishing this post. They have taken this technique into account and are working on updates to the detection rules to catch this."
"Provided as a Crystal Palace shared library. Format inspired by @rastamouse.me 's LibTP. "
Ground truth security research.
06.11.2025 15:38
👍 5
🔁 2
💬 0
📌 0
Introduction - OWASP Top 10:2025 RC1
OWASP Top 10:2025 RC1
Here we go, new OWASP Web Top 10:
06.11.2025 17:52
👍 1
🔁 2
💬 0
📌 0
FBI Tries to Unmask Owner of Infamous Archive.is Site
The FBI has subpoenaed the domain registrar of archive.today, demanding information about the owner.
The FBI is trying to unmask the owner of infamous archiving site Archive.is, according to a subpoena the site posted. No other information given, the site quietly posted the document a few days ago. FBI telling domain registrar to hand over all sorts of ID'ing info
www.404media.co/fbi-tries-to...
06.11.2025 15:16
👍 550
🔁 279
💬 22
📌 29
Found an XSS but got blocked by the CSP?
https://cspbypass.com has a compiled list of ways to bypass the Content-Security Policy. Check out the video below 👇
21.10.2025 09:16
👍 7
🔁 6
💬 1
📌 0
Parts 136 and 137 of the UK ICO report detail the Costs of Implementation of Active Directory tiering at Capita. Specifically, acknowledging that this Standard of Care requires a complex, potentially costly, and resource-intensive task to meet.
Penalty Notice Capita Plc by UK ICO
Detailed breach analysis after 2023 ransomware attack. £14M fine. Which standards of care weren't met?
* Understaffed SOC (1 analyst/shift)
* 58hr SOC response vs. 4.5hr AD takeover
* Failure to implement Active Directory tiering.
ico.org.uk/media2/pv5nh...
16.10.2025 08:34
👍 3
🔁 2
💬 0
📌 1
pagedout.institute ← we've just released Paged Out! zine Issue #7
pagedout.institute/download/Pag... ← direct link
lulu.com/search?page=... ← prints for zine collectors
pagedout.institute/download/Pag... ← issue wallpaper
Enjoy!
Please please please share to spread the news - thank you!
04.10.2025 10:40
👍 19
🔁 17
💬 1
📌 3
I'll unpack a few thoughts on this...
28.09.2025 05:11
👍 4
🔁 1
💬 1
📌 0
1/ PingCastle now highlights when no policy is in place to prevent scripting files (such as .js) from being executed via double-click.
21.09.2025 11:06
👍 1
🔁 1
💬 1
📌 0
A meme I created. It shows Calvin (from Calvin & Hobbes) seated at a table with a sign saying "Chaining two instances of Burp Suite is such an underrated technique. Change my mind"
The talk @parsiya.bsky.social gave at Defcon should be a required read for all users of Burp Suite
Bonus point: it contains a meme I created 😊
github.com/parsiya/Pres...
16.08.2025 20:21
👍 8
🔁 5
💬 1
📌 0
A top-level overview of the presentation presented as a grid of thumbnails, showing 42 slides.
Thank you to everyone who made it out for my DEF CON 33 presentation, "Shaking Out Shells With SSHamble", you can find the materials online at hdm.io/decks/MOORE%...
This deck includes some lightly-censored zero-day (more decks @ hdm.io)
10.08.2025 21:14
👍 9
🔁 4
💬 0
📌 1