We now have a (draft) @metasploit-r7.bsky.social exploit module in the pull queue for the recent Microsoft SharePoint Server unauthenticated RCE zero-day (CVE-2025-53770), based on the in-the-wild exploit published a few days ago. Check it out here: github.com/rapid7/metas...
23.07.2025 13:18 โ ๐ 11 ๐ 8 ๐ฌ 1 ๐ 0
Google fixes bug that could reveal users' private phone numbers | TechCrunch
The bug allowed a researcher to uncover recovery phone numbers of nearly any Google account.
New: A security researcher found a bug that revealed the private recovery phone number of almost any Google account.
TechCrunch verified the bug w/ the researcher, who quickly brute-forced the phone number of a test Google account we had set up.
09.06.2025 14:06 โ ๐ 64 ๐ 24 ๐ฌ 1 ๐ 6
"Windows App to replace Remote Desktop app for Windows"
There's a lot of confusion about what this means, so let me clarify:
This only affects the Remote Desktop App on the *Microsoft Store*, which you most likely don't use
Most system administrators use mstsc, the Windows built-in RDP client
12.03.2025 13:07 โ ๐ 5 ๐ 1 ๐ฌ 1 ๐ 0
We will never knowโ we will never have the faintest ideaโ how much money is getting made in insider trading windfalls from people in Trump's and Musk's circles who have an hour of notice about the daily swings in tariff policy or the occasional announced *expectations* of such swings.
06.03.2025 19:06 โ ๐ 1953 ๐ 648 ๐ฌ 42 ๐ 45
Ghidra 11.3 is OUT!
โจPyGhidra is the new feature to be excited about.โจโจItโs a Python library providing direct access to the Ghidra API. โจโจ
I expect this to massively increase Reverse Engineering tool development, as it significantly reduces the barrier to entry for Ghidra interaction.
06.02.2025 18:34 โ ๐ 36 ๐ 16 ๐ฌ 1 ๐ 1
Musk Cronies Dive Into Treasury Dept Payments Code Base
Overnight, Wired reported that, contrary to published reports that DOGE operatives at...
A 25-year-old DOGE worker named Marko Elez who has admin privileges on Treasury dept systems that control about 95% of payments made by the gov, including Social Security checks, tax refunds and contract payments "has already made extensive changes to the code base for these critical payment system"
04.02.2025 19:12 โ ๐ 574 ๐ 346 ๐ฌ 33 ๐ 65
03.02.2025 01:52 โ ๐ 23 ๐ 4 ๐ฌ 1 ๐ 0
To all our Bluesky friends, feel free to follow us here as we will be posting regular updates as the conference gets closer. See you in May!
21.01.2025 15:32 โ ๐ 8 ๐ 3 ๐ฌ 0 ๐ 0
Project Zero
Just unrestricted an issue that shows a fun new attack surface. Android RCS locally transcribes incoming media, making vulnerabilities audio codecs now fully-remote. This bug in an obscure Samsung S24 codec is 0-click
project-zero.issues.chromium.org/issues/36869...
10.01.2025 00:08 โ ๐ 38 ๐ 16 ๐ฌ 1 ๐ 2
Around 2008 I was in Ottawa and some MoD person mentioned that only a few years ago they stopped wargaming against a US invasion, and I joked "just wait until they run out of water for their golf courses in Arizona"...
09.01.2025 11:08 โ ๐ 24 ๐ 6 ๐ฌ 2 ๐ 0
Someone is using a fake PoC for the LDAPNightmare exploit to infect researchers and threat actors with an infostealer
www.trendmicro.com/en_us/resear...
09.01.2025 10:05 โ ๐ 29 ๐ 11 ๐ฌ 1 ๐ 2
Surfer Gabriel Media leaping from his surfboard at the top of the wave so the he appears to be floating in the air above the water, completely upright, with one arm extended above his head, holding out one finger, his surfboard trailing behind and also floating in the air
Brazil's Gabriel Medina with the best touchdown celebration I've ever seen (Photo: Jerome Brouillet/Getty)
29.07.2024 20:08 โ ๐ 337 ๐ 98 ๐ฌ 8 ๐ 17
in the 90โs, computers would scream every time you went online. thatโs called foreshadowing
07.09.2023 21:40 โ ๐ 8379 ๐ 3059 ๐ฌ 55 ๐ 56
Doesn't get as much attention as what Elon's doing, but every day, a team of people at Google comes to work and asks themselves, "What can we do to make search a little worse?" And they're doing a very good job.
07.09.2023 20:36 โ ๐ 1968 ๐ 391 ๐ฌ 41 ๐ 31
The windows networking stack has been the source of various vulnerabilities over the years, a few of which could lead to remote code execution. This talk wil...
Recon2023 Erik Egsgard HuntForRedOctober
Video of the talk I gave at Recon on hunting for bugs in the Windows TCP/IP stack is now up!
youtu.be/jzA5aLrK4OY
07.09.2023 21:32 โ ๐ 10 ๐ 1 ๐ฌ 0 ๐ 0
DSU Cyber Operations graduate | software vulnerability research | Minnesota Twins | he/him
Offensive security conference in the heart of Paris. 10-11th October 2025
https://www.hexacon.fr/
Degenerate Artist / Sysadmin / Cybersecurity
The worldโs premier hacker conference. Serving the global hacker community since 1993.
Defcon.org
Forum.defcon.org
Defcon.social
Since 1984, 2600 Magazine has published the hacker perspective and documented the development of the hacking community. In addition to the magazine, we have a weekly radio show ("Off The Hook") and a biennial conference (Hackers On Planet Earth - HOPE).
DFIR by day, DFIR by night.
Former vet tech.
Violinist, Salty, Tired, Meme Enthusiast.
Hacker - Helper - Human
JaysonEStreet.com
Friendly neighborhood cybersecurity guy | expect infosec news, appsec, cloud, dfir. | Long Island elder emo in ATX.
vulnu.com <- sign up for my weekly cybersecurity newsletter
security architect / co-founder @digitaldefenseinstitute.com / co-founder Recon InfoSec
โฅโฅโฅ == @eric.zip, nerdery, rainbows, sweatpants
she/her | mama of 3 | ๐ค๐๐ฟ๐๐
unicorns.lol
https://short-stack.net
whitneychampion.com/portfolio
SecOps Witch ๐ฎ
Lego zealot & Blizzard tragic ๐ฎ
Slave to 7yo terror ๐ถ
Australian based ๐ฆ
Provider of sarcasm & profanity ๐คฌ
she/her โ๏ธ
Views ALL MINE ๐
https://linktr.ee/girlgerms
She/Her. Cybersecurity Educator & Engineer. Writer. Keynote Speaker. LinkedIn Learning Author (150K+ learners). Neurospicy (ADHD). Sharing insights to inspire growth and connection. Black and proud.
Stephandsec.com
Itโs me. Sherrod DeGrippo
Software and hardware hacker, (in)security researcher, musician,MTB/Gravel cyclist,politics nerd. Not necessarily in that order.โช๏ธSecurity research lead at that (other) bird company โช๏ธMastodon: https://infosec.exchange/@0xamit
English/ืขืืจืืช/Poco espaรฑol
Father. Grandpa. Geek. Hacker. Former journalist. Security researcher. CMO @BSidesLV.org Member: Curated Intel
Stuff & Things @RedSiege | Founder, Sonar Security | Formerly 18F | art, lego, board games, comics, cute animals | she โต๏ธ
Past: Host of "Tribe of Hackers"; Assoc. Producer "Darknet Diaries."
Current: Cybersecurity researcher and executive. Also, father of the fastest climber who has ever lived. Seriously.
Warning: I talk about my son ALOT
โUt scandis, alios subleva.โ
Adviser, lawyer, and sometimes cybersecurity circus ringmaster - my monkeys fly.
Breaker of software, responder of incidents, IANS Faculty, VP R&D Hunter Strategy, Supreme Allied Commander of ANTIFA.
CEO Of Red Queen Dynamicsโฆ๏ธSenior Fellow for Global Cyber Policy at the Council on Foreign Relationsโฆ๏ธ EFF Board of Directorsโฆ๏ธshe/her โฆ๏ธ
cDc/hack.xxx/veilid
Support Veilid! Badge: ๐
www.veilid.com
Merch at: @hack.xxx
he/him