Big week for Proxmark5.
The GitHub PR for the Proxmark5 firmware lands this week.
If you ordered the black case, good news: we are fulfilling all black case orders first, both pre-DEF CON and post-DEF CON. Production is running at 400 units a day. 1600 units have already shipped as of today. Most backers will have tracking numbers this week heading into DEF CON.
This is really happening.
Build an MCP for NetExec for small and large models. The AI agent interacts with NetExec, while the user focuses on the path of compromise 🔥
github.com/mpgn/NetExec-m…
Back from mission, I released the exploit I used (it was really helpful) for #Apache Tika XFA XXE exposed through #Elasticsearch’s attachment ingest processor, leading to arbitrary file read: CVE-2025-54988 / CVE-2025-66516
- Python PoC
- version-aware Metasploit module
(loot storage, automatic cleanup + no index or document creation)
github.com/kmkz/Exploits/…@metasploit PR done:
github.com/rapid7/metaspl…
This seems handy.
Windows agent in Powershell 5.1 that loads C# in memory. No admin needed.
Linux server (Go)
--route 10.10.10.0/24
--redirect
Then you can use (TCP) tools like nxc, nmap, impacket etc for for the set range without proxyxhains.
Also supports DNS.
Please RT for reach.
If anyone knows @I_Am_Jakoby IRL, can they please reach out? I don't know them or I would, but they seem to be in distress.
tiktok.com/@i_am_jakoby/v…
Zero files written to disk. @ccelikanil and Emre Odaman built DFMI, an open-source toolkit that hijacks the Windows Installer's own execution engine to detonate payloads during software installation. Fileless, cross-platform, and slick. 💻
New File Format for Initial Access???. "PPKG" files, had a hard time bringing some of the old XML schema for building these properly but finally got execution!!, These run with high privileges by default so the UAC prompt is shown and a good pretext is still needed but these files are NOT in the block list for Outlook. Also thanks to Pearce as well I had no knowledge of ppkg files and how they worked or what they did some great stuff going offline with web_search capabilities of course.
#redteam
Device code phishing is quietly becoming one of the more effective techniques targeting #M365 environments. In our latest #blog, Lumi Taiwo and Danny Dubree detail how it works and the #ConditionalAccess controls that shut it down. Read it now! hubs.la/Q04q7lz50
Well, I think I can remove the crypto addresses from @haveibeenpwned’s donation page. This is an impossible requirement from the Aus gov, looks like back to PayPal only 🤷♂️
I see many people demotivated due to AI and feels like its been a while since I ranted. Probably a mild take but here is how I stay motivated. Nothing really new just how I use what people have said to keep my motivation up. The normal 2026 disclaimer, what is in this post isn't actually 100% in line with my opinion; yes I know there are holes in my logic but some rabbit holes are best "on read".
The biggest change for me is Linus Torvalds saying something along the lines of idk why people say AI makes things, people make thing. If communication was so global in the 70's I am sure people would have said similar things during the conversion from assembly to C. Humans are creating instructions for the compiler to make a program. So why didn't we think the compiler made it? Without internet I think it would take me around 2 minutes to write hello world in C (i know embarrassingly slow but man have i gotten lazy over the years). Do it in assembly? That's probably an hour. Which is a 30x difference of time. Okay now lets say we are in the year 2010 and have Python. I timed myself and it was 3 seconds. That's a 40x time difference from my C. Why did I think I made the program and not python made it?
Unfortunately, the only thing I can come up with is how much we communicate and how quick ideas/sentiments can form. I'm sure C/Python got hate when they first came out. Hate can be a really goo fuel -- Most engineers I know have their best work come out of "hate coding" something to prove someone wrong. Only to later realize they social engineered themself into doing an amazing thing. Could be wrong here, but I think Pythons Flask is a good example of this as it started as an April fools joke. Quite literally "the most engineer thing ever" to have a funny joke spiral out of control and grow beyond their wildest dreams... Kind of like that guy that was vibe coding games last year when AI was "bad", or heck even the W̷a̷r̷e̷l̷a̷y̷ C̷L̷A̷W̷D̷I̷S̷ ̷C̷l̷a̷w̷d̷B̷o̷t̷ ̷M̷o̷l̷t̷B̷o̷t̷ ̷ err OpenClaw person. Really with all those name changes I'm shocked they landed at OpenAI instead of MSFT.
Anyway, our hate on vibe coding created the sentiment that we aren't creating things anymore (AI makes things). I don't really view it that way, AI just makes me 20-30x faster; which is similar to the jumps between Assembly -> Compiler -> Scripting. Actually now that I think about it, I remember trying to learn C many times because scripting wasn't a "real language" and it would never run a web server or it wasn't capable of editing memory (silly times indeed). AI is enabling us to develop faster and expanding the number of people that can do things, which is not new; quite literally every time we come up with a new way to interact with machines -- it does the same thing.
So yes - Anyone can make a cool demo that looks real now but they are still going to spend hours getting AI to work out all the bugs and do it better. To me they are still making something, it is other people telling them they aren't -- Funnily enough, those people trying to convince others they aren't making things, is what in return demotivates themself because it poisons their thought process when it comes to this topic.
So uh. If you look for my permission to learn something? Vibe on and let the good times roll. Just make sure you do things safely, obey terms of service, and try not to end humanity.
Oh wait. That disclaimer. Using AI in a way that causes humans to spend a lot more time than they are used to is bad mmkay? Seeing all the low effort CTF Work, blog posts, bug bounty, etc does get annoying... oh wait I have a diclaimer to the disclaimer. If you use AI to eat up time of scammers, like tricking call center scammers into chatting with robots for hours, I thank you for your token donation to helping fight that plague.
⚠️ JUST IN: Bleood confirms him and his friends are good (Cobes and Akira)
After someone was shot and killed during the recent robbery targeting him orchestrated by Com members.
Hi! I am looking for RCE 0days for apache, nginx, ssh, ftp, react, and way more :). There is no budget. You can contact me at my Tox.
D9630B228389292FA71AB36958C1EEF9751834A401DAC8D053A591E1511AE968778B9E44C1E3
During a recent post-paid pentesting , our specialists encountered something horrific. I'm at a loss for words after what I witnessed today. An external drive was found connected to one of the employees' PCs. It contained gigabytes of pornography featuring minors. Small kids... We have a blured video recording of the screen, the work account, mail, the first and last name, and we also possible have a cloud copy of the data for further investigation by the competent authorities. Despite being cyber criminals ourselves, we are still human in the basic sense of the word. But those inhuman creatures, who made THAT deserve annihilation. Unfortunately, this is beyond our authority. Therefore, I ask concerned cybersecurity researchers to contact me using the contact information listed in the blog to help expose this network of real bastards, the producers and buyers of such content. We will pass on all available information. We do not engage in setups or compromise. This company is basically poor shit from Laos, but with EU roots. And possible EU employee into that shit.
2K Followers 924 FollowingJust an italian dude who likes security, AI and good food. #security #hacking #ai #0days #antisec #pr0j3ctm4hy3m #cybersecurity #brokensec #exploits #osint
3K Followers 488 FollowingMeow.
Probably the closest thing to an APT without breaking the law.
Adapt or Die.
SAUCE boss.
VR, Kernel Exploits, Firmware Feline.
Proverbs 25:2
1K Followers 2K FollowingUpdates about all things threat intelligence & updates about stuffs going on in the cybersec, ransomware, OSINT, SOCMINT, and hacking communities #threatintel
60K Followers 8K FollowingHacker, Researcher, Podcast Producer (Tribe of Hackers, Darknet Diaries). Proud dad of the fastest climber in the world. Ever. “Ut scandis, alios subleva”
11K Followers 12K FollowingMy commentary is not affiliated with, neither represents the views, position or attitudes of my employer(s) their clients, or any of their affiliated companies.
4K Followers 1K FollowingSenior Security Research Engineer @elastic | Opinions are my own | Rust | Ex-Red Team | Security & Systems Dev | https://t.co/QIih2B7vya https://t.co/VC3xsm0Wvq
302K Followers 1 FollowingBest DevTools, online Ai software, and digital marketing tools on the https://t.co/HSRiDG42Ok website. Plus web developer content strategies in the Google SEO podcast videos.
3K Followers 491 FollowingTargeted Ops @TrustedSec. Hacker, lock picker, writer of bad prompts. This is our world now... the world of the electron and the switch, the beauty of the baud.
8 Followers 5 FollowingTurning hostile-internet signals into searchable security telemetry for MSSPs, Red Teams, Blue Teams, and modern security platforms.
88 Followers 44 FollowingBuilding open, powerful RFID & NFC research tools for security researchers, makers, and hardware hackers. Creators of Proxmark5 & RFID Detective, etc
225K Followers 949 FollowingResearcher and a best-selling author. Keynote talks at RSA, Black Hat & DEF CON. TED Speaker. Chief Research Officer at Sensofusion.
4K Followers 67 FollowingWe're America's longest running security conference. Summercon 2026 was July 10-11.
Get ready for 2027: SUMMERCON XL
Tip your bartender.
630 Followers 99 FollowingThe independent frontier AI red team. Frontier labs have elite red teams in-house — then they engage us. Fortes fortuna iuvat.
13K Followers 2K FollowingPerformance Shooting, Games, and Combat Simulation Content. Nerd, gun, gear, training, and leadership stuff. The occasional nuanced take. Opinions are my own.
9K Followers 28 Followinghttps://t.co/zI71a4QB1W
https://t.co/QFKNuHms1N
[email protected]
Donation: Support our work on Ko-fi (https://t.co/gAtHKPSCHH)!
17K Followers 301 Following🐴Pwnie Award Winning & Nation State funded psyop featuring 6 AI Anime Waifus and a Pup™ singing about APTs, Grifters, & Snake Oil in InfoSec
🖤🩷💚💙💜🤍