Rey Bango's Avatar

Rey Bango

@reybango.bsky.social

Advocate for AI & Security | I hack into things sometimes. Opinions are mine. Fortis fortuna adiuvat. Nostalgia is not a strategy. It's a good time to cause a little chaos.

547 Followers  |  119 Following  |  117 Posts  |  Joined: 20.08.2023  |  2.0168

Latest posts by reybango.bsky.social on Bluesky


Preview
ClickFix Exploits Homebrew Workflow to Deploy Cuckoo Stealer for macOS Credential Theft ClickFix is being weaponized against macOS developers by turning a trusted Homebrew workflow into a stealthy delivery channel for a new infostealer dubbed Cuckoo Stealer.

Mac users, be careful when you install HomeBrew.

"The attack starts with typosquatted domains that closely mimic the official Homebrew site, including homabrews[.]org and other lookalike hostnames served from shared infrastructure at 5.255.123[.]244. ​"

gbhackers.com/clickfix-exp...

18.02.2026 15:27 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Flaws in popular VSCode extensions expose developers to attacks Vulnerabilities with high to critical severity ratings affecting popularΒ Visual Studio Code (VSCode) extensions collectively downloaded more than 128 million timesΒ could be exploited to steal local fi...

Vulnerabilities with high to critical severity ratings affecting popular Visual Studio Code (VSCode) extensions collectively downloaded more than 128 million times could be exploited to steal local files and execute code remotely.

www.bleepingcomputer.com/news/securit...

18.02.2026 15:24 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

I've been looking forward to @zephrfish.yxz.red's new course, Malwareless Adversarial Emulation. Just by looking at the course syllabus, I'm confident I'm going to learn a ton and become a better operator. And the price to value is more than reasonable.

The course is at lms.zsec.red

14.02.2026 19:06 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Post image Post image

I've been looking forward to @zephrfish.yxz.red's new course, Malwareless Adversarial Emulation. Just by looking at the course syllabus, I'm confident I'm going to learn a ton and become a better operator. And the price to value is more than reasonable.

The course is at lms.zsec.red

14.02.2026 19:06 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Preview
How AI coding agents workβ€”and what to remember if you use them From compression tricks to multi-agent teamwork, here's what makes them tick.

I feel like @benjedwards.com has written one of the best explanations of how AI coding agents work. The article breaks it down into easy to understand terms that developers new to agents can really grok.

arstechnica.com/information-...

29.12.2025 21:43 β€” πŸ‘ 8    πŸ” 3    πŸ’¬ 1    πŸ“Œ 0
Preview
WebRAT malware spread via fake vulnerability exploits on GitHub The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-conceptΒ exploits for recently disclosed vulnerabilities.

ALWAYS validate proof-of-concept exploit code before you use it.

"The WebRAT malware is now being distributed through GitHub repositories that claim to host proof-of-concept exploits for recently disclosed vulnerabilities."

www.bleepingcomputer.com/news/securit...

24.12.2025 20:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

I hate scammers.

14.12.2025 02:26 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

What do I do on the weekend? I install Game of Active Directory Ninja Hacker Academy on AWS of course! πŸ˜‚

I'm running through the install so I can learn more about the range deployment on cloud services. Always be learning something new. @orangecyberdefense.bsky.social

github.com/Orange-Cyber...

07.12.2025 04:41 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Glad to help shine more light on the great work you're doing to help bring affordable security education to folks. ❀️

02.12.2025 18:08 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Always a pleasure. Keep providing great learning materials and making these important tools accessible. It's appreciated.

02.12.2025 18:07 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Get the latest Black Friday and Cyber Monday Cybersecurity Deals for 2025!
YouTube video by Rey Bango Get the latest Black Friday and Cyber Monday Cybersecurity Deals for 2025!

Black Friday and Cyber Monday deals are out! I review some of them and link to a community GitHub page for you all to get discounts on courses, tools and services!

Deals from
@rastamouse.me, OffSec, EvilGinx, @antisyphontraining.bsky.social
and a whole lot more.

youtu.be/hkJfhM1T5bI

30.11.2025 16:11 β€” πŸ‘ 3    πŸ” 0    πŸ’¬ 2    πŸ“Œ 0
Preview
a man is standing in front of a microphone with the words `` help me '' written on it . ALT: a man is standing in front of a microphone with the words `` help me '' written on it .

Seeking video camera advice for content creation.

I've gotten back to creating tutorial & teaching videos on YouTube. Currently using a Brio MX but interested in the @elgato Facecam 4K. It looks to offer a lot more software features.

Has anyone used it & can give their thoughts?

05.10.2025 20:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Did I Just Fall for a Phishing Attempt?
YouTube video by Rey Bango Did I Just Fall for a Phishing Attempt?

After getting a scam email saying someone tried to access my Twitter account, I decided to look into it a little. The first of many new videos to come as I work to share more information with the community.

youtu.be/IFy_96Dg__E?...

26.09.2025 17:09 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
AOL announces September shutdown for dial-up Internet after 34 years Around 175,000 households still use dial-up Internet in the US.

The end of an era. For so many people, AOL was the internet.

arstechnica.com/gadgets/2025...

11.08.2025 23:22 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
RubyGems, PyPI Hit by Malicious Packages Stealing Credentials, Crypto, Forcing Security Changes RubyGems and PyPI hit by credential-stealing packages targeting automation and crypto users, prompting new security rules.

RubyGems & PyPI under attack:

πŸ”Έ 60 fake RubyGems stole social media logins (275K+ downloads)
πŸ”Έ PyPI fakes hijacked crypto staking wallets

Both hide credential-stealing code in legit-looking packages. #CyberAlerts thehackernews.com/2025/08/ruby...

08.08.2025 21:30 β€” πŸ‘ 4    πŸ” 4    πŸ’¬ 0    πŸ“Œ 1
A black-and-white satirical cartoon on a plain white background, depicting the progressive decay of the Apple company logo as it transforms into a silhouette of Donald Trump’s head, symbolizing Apple’s β€œfall” or moral compromise due to a gift from Tim Cook to Trump that many critics viewed as resembling a bribe to secure tariff exemptions. 2 0 1 Five solid black silhouettes of apples are arranged in a diagonal line descending from top-left to bottom-right, each showing increasing damage as if being eaten or rotting away: the first is the intact Apple logo with a small bite on the right side and a leaf on top; the second has a larger bite; the third is more eroded; the fourth appears partially exploded or flowered open; and the fifth is heavily disintegrated into petal-like fragments that form a caricatured profile of Trump, complete with his distinctive comb-over hairstyle. In the top-right corner, handwritten text reads β€œThe Buffalo News Adam Zyglis Cartoonist /2023/ something,” suggesting a commentary on decline or downfall tied to this controversial gestureβ€”a commemorative glass plaque with a 24k gold base, engraved as a memento of the first US-made Mac Pro, offered amid discussions on trade policies.

A black-and-white satirical cartoon on a plain white background, depicting the progressive decay of the Apple company logo as it transforms into a silhouette of Donald Trump’s head, symbolizing Apple’s β€œfall” or moral compromise due to a gift from Tim Cook to Trump that many critics viewed as resembling a bribe to secure tariff exemptions. 2 0 1 Five solid black silhouettes of apples are arranged in a diagonal line descending from top-left to bottom-right, each showing increasing damage as if being eaten or rotting away: the first is the intact Apple logo with a small bite on the right side and a leaf on top; the second has a larger bite; the third is more eroded; the fourth appears partially exploded or flowered open; and the fifth is heavily disintegrated into petal-like fragments that form a caricatured profile of Trump, complete with his distinctive comb-over hairstyle. In the top-right corner, handwritten text reads β€œThe Buffalo News Adam Zyglis Cartoonist /2023/ something,” suggesting a commentary on decline or downfall tied to this controversial gestureβ€”a commemorative glass plaque with a 24k gold base, engraved as a memento of the first US-made Mac Pro, offered amid discussions on trade policies.

08.08.2025 23:31 β€” πŸ‘ 364    πŸ” 99    πŸ’¬ 19    πŸ“Œ 4
Post image

Hi @defcon.bsky.social

07.08.2025 23:08 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

Picked up this very cool @crowdstrike.com t-shirt for my son and the action figure that goes with it. He’s going to love it.

06.08.2025 22:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@crowdstrike.com says they’re seeing threat actors are targeting GenAI workloads to try poison the models. The inherent trust being built as we continue to use AI systems will lead to threat actors becoming an insider threat.

06.08.2025 18:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Walking back to my room I passed the Google Cloud Security party at Blackhat and it looked jumping. Almost considered social engineering my way in. 😈😈

06.08.2025 02:16 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Ghost in the Zip | New PXA Stealer and Its Telegram-Powered Ecosystem PXA Stealer uses advanced evasion and Telegram C2 to steal global victim data, fueling a thriving cybercrime market.

Great analysis by @SentinelOne on a threat actor working out of Vietnam to target users in 62 countries.

Starts with a phishing campaign that leads to DLL sideloading of legitimate and signed software, including Office 2013, for persistence.

www.sentinelone.com/labs/ghost-i...

05.08.2025 16:46 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

πŸ˜‚πŸ˜‚kerberoasting 4eva amirite @timmedin.bsky.social

05.08.2025 16:02 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
hashcat v7.0.0

Hashcat v7.0.0 released with speed and GPU support improvements

hashcat.net/forum/thread...

04.08.2025 17:56 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Trump Still Polling Well With Working-Class American Pedophiles WASHINGTONβ€”Despite the president’s sagging approval rating overall, a Gallup Poll released Tuesday confirmed that Donald Trump’s support remained overwhelmingly strong among working-class American ped...

theonion.com/trump-still-...

The Onion just straight-up reporting real news, again.

03.08.2025 17:22 β€” πŸ‘ 25    πŸ” 7    πŸ’¬ 0    πŸ“Œ 0
Preview
VMware fixes four ESXi zero-day bugs exploited at Pwn2Own Berlin VMware fixed four vulnerabilities in VMware ESXi, Workstation, Fusion, and Tools that were exploited as zero-days during the Pwn2Own Berlin 2025 hacking contest in May 2025.

Unfortunately @broadcom.bsky.social still hasn't fixed the VMWare Workstation update server link so be sure to upgrade to 17.6.4 to fix a security issue found at Berlin Pwn2own

www.bleepingcomputer.com/news/securit...

18.07.2025 16:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Mozilla frets about Google's push to build AI into Chrome : AI could bring a new round of browser wars

www.theregister.com/2025/06/11/m...

11.06.2025 17:29 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

"Wo unto you rich men, that will not give your substance to the poor, for your riches will canker your souls; and this shall be your lamentation in the day of visitation, and of judgment, and of indignation: The harvest is past, the summer is ended, and my soul is not saved!"

02.06.2025 01:19 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
A Reality Show Where Immigrants Compete for U.S. Citizenship? D.H.S. Is Considering It.

β€œThis isn’t 'The Hunger Games’ for immigrants,” Worsoff told the newspaper

This absolutely disgusting and a pathetic way of taking advantage of immigrants by this producer.

www.nytimes.com/2025/05/16/u...

17.05.2025 22:57 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
a pixelated image of a little girl in a red coat ALT: a pixelated image of a little girl in a red coat

When you play an internal CTF against 10 other teams and win! Booyah! 😈

07.05.2025 22:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image 18.04.2025 21:51 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@reybango is following 20 prominent accounts