The 2016 Mirai botnet attack was a wake-up call:
IoT security is nonexistent at scale.
Default creds & unpatched firmware turned cameras into DDoS cannons.
Lessons?
Harden IoT or expect more botnet chaos.
#CyberSecurity #History #DDoS #IoT #Infosec #Mirai
17.03.2025 08:44 — 👍 0 🔁 0 💬 0 📌 0
Book Recommendation:
Mastering post-exploitation?
'The Hacker Playbook 3' 👌
by Peter Kim is a must-read, as it covers:
a. Actual Attack Chains,
b. Evasion Techniques,
c. Red Team Strategies.
Practical over theory.
Link: digtvbg.com/files/books-...
#RedTeam #OffSec #infosec
15.03.2025 09:33 — 👍 0 🔁 0 💬 0 📌 0
Inline hooking too noisy?
Use hardware breakpoints via 'SetThreadContext' to hijack execution flow without modifying code.
Silent, reversible & hard to detect.
#RedTeam #Malware #infosec #cybersecurity #bugbounty
15.03.2025 09:29 — 👍 1 🔁 0 💬 0 📌 0
Build the Ultimate On-the-Go Penetration Testing Machine with Kali Linux & Raspberry Pi
Table of Contents:
Turn your Raspberry Pi into a 𝐩𝐨𝐜𝐤𝐞𝐭-𝐬𝐢𝐳𝐞𝐝 𝐩𝐞𝐧𝐭𝐞𝐬𝐭𝐢𝐧𝐠 𝐩𝐨𝐰𝐞𝐫𝐡𝐨𝐮𝐬𝐞 with Kali.
⚡Stealthy, portable & packed with offensive tools, as real security pros test anytime, anywhere.
🔍 Topic: medium.com/@mawgoud/bui...
#KaliLinux #CyberSecurity #Infosec
09.03.2025 05:23 — 👍 1 🔁 2 💬 0 📌 0
Say goodbye to Skype
The 22-year-old video calling tool will reportedly retire in May 2025.
Goodbye Skype
Once the king of VoIP, now just a ghost in the digital graveyard. ☠️
From P2P-powered resilience to Microsoft's EDR-infested bloat, it never stood a chance.
Source: mybroadband.co.za/news/interne...
#Skype #Tech #VoIP #EDR #Teams #Zoom
09.03.2025 04:19 — 👍 3 🔁 1 💬 0 📌 0
VMware Warns Customers to Patch Actively Exploited Zero-Day Flaws
Cloud software firm VMware has issued a critical security advisory, detailing three zero-day vulnerabilities being actively exploited in the wild
Three VMware zero-days exploited in the wild.
CVE-2025-22224,
CVE-2025-22225,
CVE-2025-22226.
Attackers with admin access can chain these to escape VM sandboxes & control the hypervisor.
#VMware #ZeroDay #CyberSecurity #Infosec #Cybersecurity
Source: www.infosecurity-magazine.com/news/vmware-...
06.03.2025 07:01 — 👍 1 🔁 0 💬 0 📌 0
EDRs love API hooking?
PatchGuard doesn’t.
Instead of unhooking,
do this ... redirect execution using Heaven’s Gate (switching to 64-bit from 32-bit in WoW64) / indirect syscalls.
Stay ahead, stay silent. 🕵️♂️
#RedTeam #Malware #infosec #cybersecurity #bugbounty #EDR #WoW64
04.03.2025 06:17 — 👍 1 🔁 0 💬 0 📌 0
Process injection via Atom Tables is an underrated stealth tactic.
Store shellcode in an atom, retrieve it in a remote process, and execute via callback.
Avoids common memory scanning detections.
#RedTeam #EDREvasion #Infosec #CyberSecurity
04.03.2025 04:52 — 👍 0 🔁 0 💬 0 📌 0
🔧Transform your Raspberry Pi into a portable pentesting powerhouse with a 3.5-inch touchscreen & Kali Linux!
--Ideal for on-the-go cybersecurity assessments.
🔍Details: mobile-hacker.com/2025/02/26/b...
#Pentesting #Infosec #KaliLinux #RaspberryPi #cybersecurity
01.03.2025 08:09 — 👍 8 🔁 1 💬 0 📌 0
🔍Leaked code reveals a token refresh script used in adversary-in-the-middle (AITM) attacks.
If you're not monitoring OAuth token activity, you're flying blind.
Stay vigilant.
#CyberSecurity #AITM #OAuth #infosec #MiTM
github.com/zolderio/AIT...
22.02.2025 08:21 — 👍 0 🔁 0 💬 0 📌 0
⤼ Early Grok-3 ('chocolate') leads the 'Chatbot Arena ELO rankings' edging out top-tier models
Are novel training paradigms (e.g., retrieval-augmented generation, improved instruction tuning) playing a larger role?
Feb, 2025
#AI #MachineLearning #LLMs #NLP #DeepLearning #Grok
21.02.2025 06:15 — 👍 1 🔁 0 💬 0 📌 0
🔍If you’re analyzing malware, forget static AV scanners.
Use 𝐅𝐥𝐚𝐫𝐞𝐕𝐌, 𝐂𝐀𝐏𝐀 & 𝐱𝟔𝟒𝐝𝐛𝐠 for real insights.
Pair with 𝚜𝚢𝚜𝚖𝚘𝚗 + 𝚂𝚒𝚐𝚖𝚊 𝚛𝚞𝚕𝚎𝚜 for tracking execution flow as a pro.
𝐀𝐮𝐭𝐨𝐦𝐚𝐭𝐢𝐨𝐧 > 𝐆𝐮𝐞𝐬𝐬𝐰𝐨𝐫𝐤.
#Malware #infosec #Bug #CVE
21.02.2025 05:33 — 👍 2 🔁 0 💬 0 📌 0
🔒Bonus: Zerologon (CVE-2020–1472):
This vulnerability lets attackers control Domain Controllers by resetting the krbtgt password.
Patch your systems to avoid this!
#infosec #Bug #Zerologon
18.02.2025 14:32 — 👍 0 🔁 0 💬 0 📌 0
10/10 Active Directory Misconfigurations:
Weak policies, overprivileged accounts, no MFA - all these can be exploited. Regular audits & patches are your best defense!
#AD #MFA #infosec #bug #cybersecurity
18.02.2025 14:32 — 👍 0 🔁 0 💬 1 📌 0
9/10 LSASS Dumping:
Using tools like Mimikatz, attackers can dump LSASS memory to steal passwords & tickets.
It's all about memory access.
#LSASS #CredentialDumping #Mimikatz
18.02.2025 14:32 — 👍 0 🔁 0 💬 1 📌 0
8/10 MITM via LLMNR, NBT-NS, WPAD Poisoning:
By poisoning name resolution protocols, attackers can capture credentials sent over the network.
Stealthy but detectable.
#MITM #ComputerNetworks #infosec #cyberattack #privacy
18.02.2025 14:32 — 👍 0 🔁 0 💬 1 📌 0
7/10 NTLM Relay Attack:
Here, attackers intercept NTLM authentication requests, relaying them to gain access elsewhere.
It's all about misdirecting credentials.
#NTLMRelay #NetworkSecurity #ActiveDirectory #infosec
18.02.2025 14:32 — 👍 0 🔁 0 💬 1 📌 0
6/10 Golden Ticket Attack:
With the krbtgt hash, attackers create fake tickets to impersonate any user.
This grants them unlimited access to domain resources!
#GoldenTicket #Kerberos #Hash #CyberSecurity
18.02.2025 14:32 — 👍 0 🔁 0 💬 1 📌 0
5/10 DCSync Attack:
By impersonating a Domain Controller, attackers can extract credentials from any DC.
This can lead to Golden Ticket attacks.
#DCSync #Persistence #DomainController
18.02.2025 14:32 — 👍 0 🔁 0 💬 1 📌 0
4/10 AS-REP Roasting:
Focuses on accounts without required pre-authentication, allowing attackers to crack passwords from AS-REP tickets.
#ASREP #SecurityTips #Authentication #Passwords
18.02.2025 14:32 — 👍 0 🔁 0 💬 1 📌 0
3/10 Kerberoasting:
Targets service accounts by cracking Kerberos tickets.
If service accounts have weak passwords, it's a goldmine for attackers.
#Kerberos #ADSecurity #Kerberoasting #password
18.02.2025 14:32 — 👍 0 🔁 0 💬 1 📌 0
2/10 Pass-the-Hash (PtH) Attack:
Hackers grab #NTLM hashes without cracking passwords, then use them to move around the network.
Tools like #Mimikatz are popular for this.
#PtH #CyberAttack #infosec #exploitation
18.02.2025 14:32 — 👍 0 🔁 0 💬 1 📌 0
Morning / Evening all ☕️
Let's talk about Active Directory (AD) security.
Attackers 'love' targeting AD for domain admin privileges.
Here's a thread on the top techniques they use!
Image Credit: (cyber.gov.au, 2024)
A Thread 1/10🧵
#CyberSecurity #infosec #CVE
18.02.2025 14:32 — 👍 0 🔁 0 💬 1 📌 0
You will enjoy reading this ☕
🔬What IF: Scientists Choose Rust Over Python for AI Development.
📖 Read the full story ..
🔗https://mawgoud.medium.com/earth-72-scientists-adapted-rust-instead-of-python-for-artificial-intelligence-development-84b705459613
#AI #Rust #Python #Tech #Multiverse #ML
15.02.2025 12:49 — 👍 1 🔁 0 💬 0 📌 0
🚨 DeepSeek's iOS app is sending sensitive user data to a ByteDance (TikTok) .. affiliated cloud platform without encryption.
👉 Full Report: thehackernews.com/2025/02/deep...
#Cybersecurity #Privacy #Bug #Encryption #Tech #News #Security #TikTok #DeepSeek #OpenAI
15.02.2025 05:36 — 👍 1 🔁 0 💬 0 📌 0
Ups and downs of #redteam engagements. When the standard payloads don’t cut it, innovation wins. Learn how we misused a screenshot tool to load shellcode… at the fifth attempt!…
blog.compass-security.com/2024/12/a-ni...
17.12.2024 09:12 — 👍 8 🔁 6 💬 0 📌 0
Red Teamers: do NOT neglect SNMP like sysadmins usually do! SO many networks have granted me very quick wins through SNMP enumeration, which can be done with Metasploit, snmpwalk, and onesixtyone:
Enum Windows accounts (spray?):
snmpwalk -c public -v1 $TARGET 1.3.6.1.4.1.77.1.2.25
#hacking #redteam
24.01.2025 17:33 — 👍 17 🔁 4 💬 0 📌 0
Dumping LSASS?
Ditch 'MiniDumpWriteDump'—too noisy.
Use NtReadVirtualMemory via direct syscalls
or
use (COM+ LRPC abuse) for stealthier creds extraction.
EDRs hate this one trick. 😉
#RedTeam #Malware #EDR #IncidentHandling #infosec #DFIR
13.02.2025 06:16 — 👍 1 🔁 0 💬 0 📌 0
Bypass 'FindWindow' anti-debug checks by hooking 'NtUserFindWindowEx' & returning a fake handle.
🕵️♂️ Malware loves to check for debuggers this way ... feed it garbage & watch it fail.
#ReverseEngineering #Malware #infosec #bug #exploitation #pentesting
13.02.2025 06:16 — 👍 0 🔁 0 💬 0 📌 0
🔍 Think your browser extensions are harmless?
A rogue extension with 'activeTab' or 'all_urls' permissions can:
- steal cookies,
- inject scripts,
- or track everything you do.
Audit them.
Less is more.
#Privacy #CyberSecurity #infosec #browser #chrome #firefox #opera
13.02.2025 06:15 — 👍 1 🔁 0 💬 0 📌 0
De qué sirve la sangre si no tienes pasión.
EN/SPA
Marica y antifascista.
🧡🩵💚 https://boxd.it/82nOv
I'm in my 30s and use it as a personality trait. This account is mainly art and pondering. Nothing serious. Maybe.
Conceived in Maplins Holiday camp
Born in Stepney
Lives in Essex
Based in a stunning Mediterranean country, with a love for great books, music and films, meaningful time spent with two amazing best friends, and a deep appreciation for nature, animals, and a bit of adventure along the way.
Glad to meet you 🫱🫲 😊💙💙
.MUSIC Verified domain/website for Bobby Poe Sr:
https://bobbypoe.music
Bobby Poe Sr formed one of the few integrated Rock 'n' Roll/Rockabilly bands of the 1950's:
https://bobbypoe.com
Bobby Poe's Pop Music Survey 1968 - 1996:
https://popmusicsurvey.com
writer, performance artist, feminist futurist, undercover activist for hope
Their evil is mighty but it can’t stand up to our stories. - Leslie Marmon Silko
Person. Democracy Enthusiast. NYC. https://pcrf1.app.neoncrm.com/forms/gaza-recovery
Humanity is love ❤️
Remember we only lives once 🧏♂️
Writer of scumbags, con artists, and all manner of morons |
Creator of A WAR OF A MADMAN'S MAKING |
Editor of Pistol Jim Press: https://pistoljimpress.substack.com/ |
The Splattershot Killer: https://www.amazon.com/dp/B0FM7BP2K8 |
He/Him
Husband & Father.
Horror/Sci-fi/Books/Films/D&D.
DC Comics Geek.
Fan of Post-Punk & Miserable Indie.
Music lover
Social worker
Radiomoderatorin Radieschen Radio RaBe
I am an artist, voice actor, antique collector, and soon video game designer.
Content strategist & marketer. Handheld gaming system enthusiast. Eagles fan. NYC transplant by way of PA and The State We Don't Talk About. Formerly of That Company with All Those Websites.
J Simpson is a prolific academic writer, journalist, creative and critic, specializing in "dark," experimental, and avant-garde art, idealistically believing that good art makes the world a better place.
https://linktr.ee/for3stpunk
Hoping to have a Social media page and algorithm filled with my interests and hobbies only. No politics.