Nad's Avatar

Nad

@nadsec.online.bsky.social

Hacker (the good kind[mostly]). Breaking things, fixing them, then breaking them again. AI, robotics, honeypots, and whatever else keeps me up at night https://github.com/Rat5ak https://medium.com/@Nadsec https://x.com/Nadsec11

35 Followers  |  85 Following  |  31 Posts  |  Joined: 04.12.2024  |  2.1054

Latest posts by nadsec.online on Bluesky

Read that as neutering.

11.09.2025 20:51 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

If 13-year-olds can breeze through your millions in next-gen firewalls, intrusion boxes, AI juicers and zero-trust microwaves while laughing uncontrollably in a Discord server, then this industry’s clearly been swindled by slick talking yokels wearing suits. Shoulda listened to the kids in hoodies!

11.09.2025 20:49 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Those ratbag kids claim to have practically every single data set available, which likely isn’t far from the truth given how much crypto they would happen to have laying around.

The biggest question here is, wtf have we all been doing for the last decade with all of these bolt on security products.

11.09.2025 20:40 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I thought everything was meant to be bigger in Texas.

10.09.2025 18:48 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I mean, I use AI vibe coding to create malware based on security research/technical blogs.. You can give it a POC, or even part of a somewhat redacted POC and within about 20 minutes of messing about have a spray and pray vuln cannon that probably just works.
- Keyword, probably.

05.09.2025 01:37 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Seems very likely these different groups are gearing up.. The report from Greynoise is actually looking at a botnet from a few days earlier which interestingly I actually did not capture as in the instance Greynoise are looking at is targetting the united states...

05.09.2025 01:12 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

That is certainly concerning, wonder if we are dealing with an undisclosed zero-day that just hasn't been widely used yet.. The usual children are carrying on in their telegram channels about having a Cisco dump they are not willing to release..

05.09.2025 01:08 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Skill issue.

01.09.2025 04:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I can confirm, it’s just not worth it! Oh lord! Why must I be burdened with this genetically-gifted admin overhead!?!?

31.08.2025 02:20 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I only use browsers rated GPT-7 or higher..

30.08.2025 07:32 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Well if everybody just gets the brain implant, this won’t end up becoming a problem..

30.08.2025 07:30 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Bonus jank:
github.com/Rat5ak/Anato...

29.08.2025 19:21 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

This isnt what I signed up for!

29.08.2025 18:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Honeypot Report: A Coordinated Reconnaissance Wave Against Cisco ASA Appliances Author: Rat5akΒ  https://otx.alienvault.com/user/conrat45/pulses

Cisco ASA honeypot blew up Aug 28:
– 200k probes in 20h
– 3 ASNs only: NYBULA / CHEAPY-HOST / GCS
– Each IP ~10,102 reqs (scripted)
likely prepping for CVE-2025-20182/20134 (DoS), disclosure bugs, or legacy RCEs.
Report: medium.com/@Nadsec/hone...
OTX Pulses: otx.alienvault.com/user/conrat

29.08.2025 17:01 β€” πŸ‘ 1    πŸ” 3    πŸ’¬ 2    πŸ“Œ 0

from dangernoodle import snakes

cobra = snakes.Cobra()
cobra.hiss()

21.08.2025 00:12 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

If it weren’t for all the damn snakes the internet would be a lot safer!

21.08.2025 00:07 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

And no matter how hard you try you can never truly be sure whether you have the world’s most secure environment, or if you’re harbouring the world’s most sophisticated malware!

07.08.2025 14:29 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

As a further note, I regularly change phone providers to whoever has the cheapest deal and every single time I’ve been able to effectively sim swap myself without providing the network operator/isp any form of valid ID.. the most I’ve ever handed over is a photo of a Medicare card lol….

08.05.2025 04:22 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I am finding that workplaces simply are not providing employees with a device to use outside of the office, a work phone to use with MFA etc etc…
Assuming this may have been the case here - currently I use my personal phone for mfa via sms for work and I feel like a sitting duck.

08.05.2025 04:20 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

That’s no problems! Tbf I’d skip right over an email from a personal Gmail account with 15 pdfs attached too 🀣
Thanks and more to come :)

Appreciate all you guys do for the community.

08.05.2025 02:53 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Was quite interested to see Cisos and the likes trying this out on their PCs and being gobsmacked they can rdp in with old creds 🀣. Crazy how long this has been going on and even crazier to me to find out just how many people didn’t know how this worked. Onya Microsoft! Another job well done!

08.05.2025 01:52 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0

Can’t argue

08.05.2025 01:44 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@patrick.risky.biz
Cheers for the shoutout!
Heard my name pop up on the podcast on way to work this morning :)
Fav podcast, long time listener. Also I sent y’all over a big pack of docos regarding the rdp stuff a few weeks ago. If ya interested in the specifics have a suss.

08.05.2025 01:42 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

I am so glad to have grown up just in time to have have witnessed these products 🀣🀣🀣. I want them back.

It can’t be me… it’s the children who are out of touch!

06.04.2025 00:32 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I am so glad to have grown up just in time to have have witnessed these products 🀣🀣🀣. I want them back.

It can’t be me… it’s the children who are out of touch!

06.04.2025 00:31 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Mass Scanning Targeting Palo Alto GlobalProtect Portalsβ€Šβ€”β€ŠMarch 2025 Threat Intelligence Report Introduction

Mass Scanning Targeting Palo Alto GlobalProtect Portalsβ€Šβ€”β€ŠMarch 2025 Threat Intelligence Report medium.com/@Nadsec/mass...

#cyber #palo #vulnerability #cybersecurity #report #infosec

04.04.2025 01:08 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

I’ve already seen Terminator. I don’t need to see it again in 3d.

04.04.2025 00:10 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
200 Million X User Records Released β€” 2.8 Billion Twitter IDs Leaked More than 200 million claimed leaked and stolen data records relating to X users have been posted on a popular hacker forum. What you need to know.

And there we go..

www.forbes.com/sites/daveyw...

03.04.2025 12:07 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
FlickJect: Exploiting Powerline Ethernet via Light Switch Flicker By @Rat5ak and @BitTwig

🚨 New vuln drop: FlickJect (CVE-2025-0401)

Inject code into powerline Ethernet adapters using light switch flicker patterns.

Yeah. For real.

πŸ‘‡ Full technical write-up (PoC, traces, affected devices):
medium.com/p/flickject-...

#infosec #CVE #FlickJect #Cybersec

03.04.2025 11:58 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Twitter (X) Is a Hacker’s Playground: How Layoffs Left It Vulnerable in 2025 Introduction

A comprehensive analysis of the current state that twitter/X has been left in. This report was spurred on by the ease of which I was able to create accounts/spin up bots. There is no game of Cat and Mouse to be played at twitter HQ.. They fired all of the mice..

medium.com/@danjwade95/...

17.03.2025 23:28 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

@nadsec.online is following 20 prominent accounts