Last Week in Security (LWiS) - 2026-02-09
"Negative-day" discovery (@spaceraccoonsec), Exploit gen with LLMs (@seanhn), Harmony LPE (@johnnyspandex + @buffaloverflow), NetSupport Manager RCE (@0xor_solo), Azure blob C2 (@KingOfTheNOPs + @senderend) and more!
blog.badsectorlabs.com/last-week-in...
10.02.2026 19:26 β π 0 π 1 π¬ 0 π 0
Noone asked for this, but I'm trying to get more comfortable with qemu as a whole which has resulted in this overly fancy Qemu Machine Protocol (QMP) socket client, complete with dynamic schema parsing, event subscriptions and tab completion, because why not :P
28.01.2026 22:47 β π 1 π 1 π¬ 0 π 0
A codex session with a message: "Applying patch carefully".
Thank you for applying the patch carefully.
28.01.2026 17:24 β π 1 π 0 π¬ 0 π 0
an easy way to remember the difference between ssh -L and ssh -R is to try both until it works
28.01.2026 01:28 β π 180 π 14 π¬ 13 π 0
PoC authentication bypass for telnetd.
Quick lunch time side quest building a simple lab to play with the inetutils-telnetd authentication bypass as disclosed on oss-sec β.
github.com/leonjza/inet...
β seclists.org/oss-sec/2026...
21.01.2026 11:05 β π 4 π 3 π¬ 0 π 0
Really excited to present this Frida training @1ns0mn1h4ck.bsky.social with @ipmegladon.bsky.social and myself! If you've dabbled with Frida before, but want a practical learning opportunity to improve your usage and understanding, this one is for you!
19.01.2026 09:09 β π 3 π 3 π¬ 0 π 0
We are excited to announce the CFP for the next tmp.0ut Volume 5!
tmpout.sh/blog/vol5-cf...
14.01.2026 09:02 β π 31 π 18 π¬ 0 π 0
It's a nice feeling wrapping up some research! :D
08.12.2025 06:23 β π 2 π 0 π¬ 0 π 0
Two blog posts just dropped - one with the details on the bloatware pwning shenanigans I was up to earlier in the year, and another on pipetap, a new Windows named pipe proxy/tool.
sensepost.com/blog/2025/pw...
sensepost.com/blog/2025/pi...
07.12.2025 07:01 β π 3 π 2 π¬ 0 π 0
Itβs almost time for my @BSidesCapeTown talk, and Iβve just open sourced pipetap. My Windows named pipe proxy & multi-tool. Excited to see what you do with it!
github.com/sensepost/pi...
06.12.2025 13:56 β π 12 π 4 π¬ 0 π 1
Honestly excited for this years BSides Cape Town with fellow hackers and the @sensepost.com crew! See you soon Cape Town!
05.12.2025 09:57 β π 1 π 0 π¬ 0 π 0
[BLOG]
This update solved a big issue I had with merging raw assembly into PIC. I cover the new linkfunc command and the updated addhook command.
rastamouse.me/pic-symphony/
01.12.2025 20:12 β π 3 π 2 π¬ 0 π 0
Where I'm going with this: we're in research territory. We may find patterns that just make sense as the way to tackle certain problems/architectural needs. And, in some cases, tightly coupling things may be the right answer.
Always keep the task/problem first, make elegance a lower priority aim.
02.12.2025 03:48 β π 2 π 1 π¬ 0 π 0
ποΈ Early Bird tickets for Insomni'hack 2026 are live!
Join us in Switzerland for talks, CTF and networking with industry leaders.
Donβt miss out! Secure your spot now: https://ow.ly/iKes50XzTj3
#INSO26 #Cybersecurity #EthicalHacking #Event
01.12.2025 10:25 β π 3 π 2 π¬ 0 π 0
Release 1.12.0 Β· sensepost/objection
The, wow, finally, a release release! π
Honestly, there has been so much that has changed, and it's hard to thank and attribute to everyone that has contributed. To that end, thank you for your con...
We've been waiting 5 years for this: objection has been updated to 1.12.x with Frida17+ support. Thank you so much @leonjza.bsky.social and everyone who contributed!
github.com/sensepost/ob...
Thanks to @ipmegladon.bsky.social for updating the MASTG accordingly (OWASP/mastg/pull/3378)
21.11.2025 12:30 β π 3 π 3 π¬ 0 π 0
I know it took long, and there is work to do, but I'm excited for getting back on track.
21.11.2025 15:50 β π 1 π 0 π¬ 0 π 0
Getting Started - PyPI Docs
We changed two big things today.
1. Packaging is now using uv. While you can still pip install objection, you can now also run it with: uv run --with objection
2. Pushing updates to PyPi now happens on git tag, using trusted publishing: docs.pypi.org/trusted-publ....
21.11.2025 15:50 β π 0 π 0 π¬ 1 π 0
Getting Started - PyPI Docs
Apart from all of the epic effort @ipmegladon.bsky.social and other contributors have put in, I'm really happy with the new CI. Manual pypi releases are no longer needed and we can finally move fast again with tagging which is huge.
21.11.2025 15:50 β π 1 π 0 π¬ 1 π 0
It's... been a while since the last objection release got tagged. We finally landed a 1.12 release today which also means pypi is up to date again, and for the foreseeable future! Work never really stopped, and plenty of bug fixes are included. More in π§΅
github.com/sensepost/ob...
21.11.2025 15:50 β π 3 π 3 π¬ 1 π 0
Need to open doors from the outside without touching anything? Turns out thats possible with no touch sensors as @shifttymike.bsky.social details in his latest blog post.
sensepost.com/blog/2025/no...
19.11.2025 13:29 β π 4 π 2 π¬ 0 π 0
The new kids use uv, so:
uv run raw.githubusercontent.com/sensepost/CV... !
18.11.2025 17:11 β π 2 π 1 π¬ 0 π 0
Tradecraft Engineering with Aspect-Oriented Programming
Itβs 2025 and apparently, Iβm still a Java programmer. One of the things I never liked about Javaβs culture, going back many years ago, was the tendency to hype frameworks that seemed to over-enginβ¦
Tradecraft Engineering with Aspect-Oriented Programming
@rastamouse.me pretty much predicted what was coming in his last blog post. attach (Win32 APIs), redirect (local funcs), capability right-sized IAT hooks, and PICO function exports.
Yes, attach can incept its PIC.
aff-wg.org/2025/11/10/t...
10.11.2025 18:21 β π 10 π 9 π¬ 0 π 1
ATT&CK v18: Detection Strategies, More Adversary Insights,
ATT&CK v18 is released with new Detection Strategies, Analytics, and revamped Data Components!
ATT&CK v18 is now out! Today marks the release of Detection Strategies, where we've moved from single-sentence notes to structured, behavior-focused strategies across the board. A new blog post describes the changes medium.com/mitre-attack... with details at attack.mitre.org/resources/up....
28.10.2025 14:56 β π 9 π 5 π¬ 0 π 2
Three terminals stack on top of eachother. The top is running hub.pl on the host. The middle is running pool.pl on the βhackerβ server. And the bottom shows a connection from the host through the hacked server to a target server over SOCKS.
Just added SOCKS support to this reverse tunnelling tool github.com/singe/contun...
28.10.2025 14:58 β π 2 π 1 π¬ 0 π 0
Open source maintainer at https://github.com/nalgeon. Author & educator at https://antonz.org
reverse engineering, cryptography, exploits, hardware, file formats, and generally giving computers a hard time
Fedi: @retr0id@retr0.id
Macroblog: https://www.da.vidbuchanan.co.uk/blog/
Created http://adventofcode.com, http://compute-cost.com, http://anoik.is, http://was.tl/projects/; Principal Architect at https://acvauctions.com
Swiss dude working in IT security. Enthusiast about tech, music and flying things.
Red Team & Offensive Security Research @amberwolfsec.bsky.social
Bringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things: https://xbow.com/traces
US Editor-in-Chief, @pcgamer.com | tyler@pcgamer.com
I like making computers misbehave. Does stuff at http://specterops.io.
Github: https://github.com/leechristensen
Mastodon: @tifkin_@infosec.exchange
ceo exe.dev, tailscale co-founder, programmer
CEO / Founder of https://textualize.io Hyperborean Python expert, author, humanist, husband, sometimes wildlife photographer. Carbonara aficionado. He/him.
Official account for Cobalt Strike. Benchmark red teaming tool known for its flexibility and powerful user community. Follow for new releases and other updates.
#rustlang, #jj-vcs, atproto, shitposts, urbanism. I contain multitudes.
Working on #ruelang but just for fun.
Currently in Austin, TX, but from Pittsburgh. Previously in Bushwick, the Mission, LA.
thedarktangent@defcon.social
All about #infosec Call for Papers : cfptime.org
Specializing in pen testing, red teaming, and Active SOC. We share our knowledge through blogs, webcasts, open-source tools, and Backdoors & Breaches game.
blackhillsinfosec.com & poweredbybhis.com
Threat modeling. BH Review Board. Affiliate Professor, UW. Fixed autorun. Helped create CVE.
Not sure why we're building graphs on yet another (effectively) centralized system. https://infosec.exchange/@adamshostack
Creators of BloodHound | Experts in Adversary Tradecraft | Leaders in Identity Attack Path Management
Founder and Chief Swig at PortSwigger. Creator of Burp Suite and the Web Security Academy. Author of The Web Application Hacker's Handbook.