Today one of my favourite hackers and biggest inspirations, @leonjza.bsky.social, is speaking at DEF CON 33!
Track 4 @ 16:30 PDT
defcon.org/html/defcon-...
If you're there, please go and support him.
If you're in a close enough timezone, please stream him live (see dctv.defcon.org)
09.08.2025 14:04 β π 1 π 1 π¬ 0 π 0
7 Vulns in 7 Days: Breaking Bloatware Faster Than Itβs Built
Sat, Aug 9 at 16:30 β 17:15 PDT
LVCC - L1 - Exhibit Hall West 3 - Track 4
DEF CON Official Talk
Demo π»
Exploit πͺ²
Description
Bloatware. We all hate it, and most of us are good at avoiding it. But some vendor tools β especially those managing critical drivers β can be useful when the Windows Update versions arenβt good enough for performance-critical computing.
What started as a routine driver update took a sharp turn when I confirmed a reboot modalβ¦ from my browser. Wait, my browser shouldnβt be able to do that!? To my disappointment (and maybe some surprise), it turned out to be arbitrary code execution β right from the browser. This kicked off a week-long deep dive, uncovering seven CVEs in seven days across several prominent vendors, all exploiting a common pattern: privileged services managing software on Windows with little regard for security.
Later today, as Las Vegas hovers at its peak temperature on the 33rd iteration of DEFCON, @leonjza.bsky.social will take everyone in Track 4 on a wild ride through vuln ridden bloatware installed on many of the machines in the room and the world. https://info.defcon.org/content/?id=60380
09.08.2025 14:27 β π 2 π 0 π¬ 0 π 0
Hi DEFCON!
06.08.2025 18:22 β π 2 π 0 π¬ 0 π 0
Good point! Thanks.
05.08.2025 18:29 β π 0 π 0 π¬ 0 π 0
BSides Las Vegas 2025 is incredible. Amazing turn-out, fantastic staff, and the sheer variety of content, speakers, and activities sets the bar for what a hacker con should be. You can find the slides from my talk, "Turbo Tactical Exploitation: 22 Tips for Tricky Targets" at hdm.io/decks/BSides...
05.08.2025 06:02 β π 13 π 7 π¬ 0 π 0
Any idea whatβs the easiest way to get a supported meshtastic board/device in Vegas?
05.08.2025 09:28 β π 1 π 0 π¬ 2 π 0
What gets the Attention?
Consulting the OWASP top 100,000 from the Appendix to the Addendum to the Supplement to the Apocrypha, Volume 127, we seeβ¦
#17,245 Spectre
#17,246 POODLE
#17,247 Meltdown
#17,248 Rowhammer
#17,249 DROWN
#17,250 ROCA
β¦
What do all of these have in common?
No-one ever uses them
* there are 17,244 easier ways to carry out an attack
* this is why they've been referred to as "stunt cryptography"
Stunt cryptography attack
* You have a 0.00001% chance of recovering 2 bits of plaintext from a single message
Any of the OWASP top ten
* You have a 100% chance of recovering the plaintext of all the messages
Periodic reminder about stunt hackingΒΉ.
You will get done by phishing.
Nothing else matters.
__
ΒΉ www.cs.auckland.ac.nz/~pgut001/pub...
04.08.2025 07:46 β π 14 π 2 π¬ 0 π 0
Cyd 1.1.16 released | Cyd Docs
We're pleased to announce Cyd 1.1.16 is released. Here's what's new:
Cyd 1.1.16 is out. If you've already deleted your X account, you can still migrate your tweets to Bluesky now! docs.cyd.social/blog/cyd-1.1...
03.08.2025 23:05 β π 11 π 8 π¬ 1 π 0
defcon 33 main stage sunday aug 10 noon - flyer with sick ascii by x0 and aNACHRONiST
Are you going to @defcon.bsky.social??
We'll be giving away 9500 print copies of Phrack!
Come by main stage Sunday @ noon to see @vacci.ne @richinseattle.bsky.social and chompie talk hacker history! This will mark the first time Phrack staff appear together on DEF CONβs main stage.
29.07.2025 17:52 β π 103 π 40 π¬ 1 π 2
hashcat v7.0.0 performance comparison
I got excited when I saw the line about βmajor speed improvementsβ on Apple Metal GPUs. But the benchmarking spreadsheet shows a slowdown in almost every format except a few docs.google.com/spreadsheets...
Thatβs a real head scratcher.
03.08.2025 07:00 β π 0 π 0 π¬ 0 π 0
#hashcat v7.0.0 is out!!! π€©
hashcat.net/forum/thread...
02.08.2025 08:06 β π 4 π 5 π¬ 1 π 0
While the result is useful, a research narrative is always helpful for seeing how the sausage is made and disabusing people of the notion that good work is the result of anything else other than trying.
01.08.2025 04:00 β π 3 π 0 π¬ 0 π 0
A screenshot of two windows. The top is a view of the Microsoft SQL management GUI showing that βExtended Protectionβ is enabled for NTLM authentication. The bottom is a terminal showing an invocation of Impacketβs mssqlclient.py successfully connecting using channel binding.
Reverse engineering Microsoftβs SQLCMD.exe to implement Channel Binding support for MSSQL into Impacketβs mssqlclient.py. Storytime from Aurelien (@Defte_ on the bird site), including instructions for reproducing the test environment yourself.
sensepost.com/blog/2025/a-...
31.07.2025 16:19 β π 9 π 6 π¬ 0 π 1
Early Warning Signals: When Attacker Behavior Precedes New Vulnerabilities
GreyNoiseβs new research reveals a recurring pattern: spikes in malicious activity often precede the disclosure of new CVEs β especially in enterprise edge technologies like VPNs and firewalls.
π¨ New Research: GreyNoise identifies an early warning signal, spikes in attacker activity tend to precede new CVE disclosures within six weeks. Which vendors show the strongest signal and more, all in our latest report β¬οΈ
31.07.2025 13:18 β π 5 π 5 π¬ 0 π 1
A primary benefit of βsoftwareβ is scalability and repeatability. I can write the task in code, then run it as many times as I like to get the same result.
With AI you get neither - costs inhibit scalability and outputs are mostly non-deterministic.
30.07.2025 05:40 β π 5 π 2 π¬ 0 π 0
128 unprocessed files still waiting before we can release the final WWWD scores this year, but it looks like a number of folks will bring real points into the RF Hacker Sanctuary WCTF @defcon.bsky.social !
We want to thank EVERYONE for bringing creativity, cleverness, and a spirit of cooperation!
29.07.2025 13:52 β π 1 π 1 π¬ 0 π 0
Apologies, but I donβt understand. Itβs the same story we discussed before?
29.07.2025 03:41 β π 0 π 0 π¬ 2 π 0
Go on ...
28.07.2025 19:45 β π 0 π 0 π¬ 0 π 0
My attempt to create a custom feed to group skeets by semantic similarity using embeddings is so far better at finding bots than it is at grouping meaningful content.
28.07.2025 19:40 β π 0 π 1 π¬ 1 π 0
Ta! It mentions Israel several times mostly as a victim, some description of the war in Gaza although it seems deliberately neutrally framed. The only criticism of Israel is the report sent to the journalists, but thatβs phrased more as political friction. Original articleβs claims look false.
28.07.2025 03:58 β π 2 π 0 π¬ 1 π 0
Me too. The lack of authoritative reporting made me go look.
27.07.2025 19:17 β π 1 π 0 π¬ 2 π 0
Tom Lehrer - National Brotherhood Week
Very sorry to hear about the death of Tom Lehrer at age 97. The cleverest, funniest singer/songwriter of all time, even if he lost interest in the whole business pretty quickly? www.youtube.com/watch?v=aIlJ...
27.07.2025 16:20 β π 786 π 324 π¬ 41 π 153
picture
picture
Along with a group of other researchers, I've been tracking attacks from the DDoSia participatory DDoS botnet operated by NoName0157(16) . Targets of this botnet have been primarily Ukrainian, NATO and other European targets.
Today, we published collected logs from tracking this botnet,
the logs
24.07.2025 13:00 β π 6 π 2 π¬ 1 π 2
If anyone wants a software supply chain security jump scare: Clone hashicorp/vault and run "make". π«₯
21.07.2025 03:17 β π 4 π 1 π¬ 1 π 0
Unix Magic Poster Annotations
Look at that, thereβs now a site explaining them all unixmagic.net
20.07.2025 16:39 β π 0 π 0 π¬ 0 π 0
A wizard pouring things into a cauldron. But the cauldron is a shell. There are pipes over head with a cat in the bottom right. Incredibly detailed with all sorts of in jokes.
The original poster was circa 1987 groups.google.com/g/comp.unix.... and contained way more nuance and in-jokes.
20.07.2025 16:27 β π 3 π 0 π¬ 1 π 0
A Linus Torvalds looking wizard holding a wand and coaxing smoke from a cauldron. The cauldron has the word Linux on it and the smoke rising from it has the names of various unix commands like xargs, grep, awk and cat. The text at the bottom says βUNIX is magicβ
An AI remix of an old unix magazine cover somewhat updated for the modern age.
20.07.2025 16:21 β π 9 π 0 π¬ 3 π 1
abyssal witch | deranged catgirl hardware/software engineer + vtuber | that crazy SCSI girl | she/her | π
banner: @rally-nine.bsky.social
www: https://lethalbit.net/
twitch: http://twitch.tv/akinyanya
mastodon: https://vt.social/@lethalbit
since 1985
https://phrack.org
Archive of X/Twitter account @dugsong (June 2007 - Nov 2024)
Now transmogrified into π¦ @dugsong.com
#w00w00 #silobreaker #00m00m
βοΈ AI Security R&D @ Prophet Security
π IR/TH/Incident Management Instructor
ποΈ Frequent Guest on Cybersecurity Defender's Podcast
Hacker / Farmer / Builder / Breaker
Prev: Code4rena, Okta, Auth0, GitHub, npm, ^lift, &yet, Symantec.
Pioneered BlindXSS & DVCS Pillaging
npm audit is my fault. More info: https://evilpacket.net
Muppet and consumer of aged memes.
Resident cat @ClearVector.
Hacks, raps, and other things.
Senior investigator & Trainer @Bellingcat.com
Investigating explicit non-consensual deepfakes/AI and disinfo w/OSINT
"I am a doctor, but not that kind of doctor."
@DistrictCon Founder. Harvard & Georgetown MPP/JD candidate. @CyberStatecraft / @BelferCenter fellow, ex-Google threat research. Dog mom. Opinions=my own π©π»βπ»
Professor of Emergent Harms, Department of Computer Science & Technology, University of Cambridge
Director, Cambridge Cybercrime Centre
Fellow and Director of Studies, King's College
she/her
Programmer, Linux/BSD-head, Skater, Guitarist, 9-ball, Anti-Capitalist, ΠΠ·ΡΡΠ΅Π½ΠΈΠ΅ Π ΡΡΡΠΊΠΎΠ³ΠΎ ΠΈ Π£ΠΊΡΠ°ΡΠ½ΡΡΠΊΠΎΡ
Github: https://myresume.sh
Stickers: https://tinyurl.com/leftstickers
Unionize: https://www.iww.org
Gun and Medic Training: https://socialistra.org
Freelancer | Full-time #BugBounty | @Hacker0x01 H1-Elite | $1,500,000 Overall Bounties | β€οΈ IDA Pro | Mobile Hacker
Empowering people with news and information about a dangerous and confusing world. Everything is Connected.
Journalist, novelist, screenwriter. Always looking for stories. LDN, NYC, LA
https://substack.com/@chadbourn
Buy Me A Coffee: coff.ee/chadbourn
Experts in Network Forensics and Network Security Monitoring. Creators of #NetworkMiner, #CapLoader, PacketCache, #PolarProxy and RawCap.
Website: https://www.netresec.com/
Mastodon: @netresec@infosec.exchange