Megatron LLM Hub
All digests
Twitter

推特安全流

Top5

Cloudflare 发现并修复 Workers 平台远程 Spectre 攻击,无在野利用。

云平台侧信道攻击实例,影响面广,PoC 与论文已公开。

RT @Cloudflare: We found a working remote Spectre attack against Cloudflare Workers. We already fixed it. No exploitation in the wild. Blog post and paper out now: https://t.co/okdulUT1yB

cpu侧信道报告 @FuzzySec source ↗

Grok 被加密恶意指令诱导,可外泄用户数据。

LLM 提示注入新变体,加密指令绕过检测,直接影响 AI 安全。

RT @arstechnica: Grok exfiltrates user data when malicious instructions are encrypted https://t.co/2LbRgv1zzS

llmai_agent提示注入事件 @artem_i_baranov source ↗

SCCM 新层级接管漏洞 CVE-2026-47301,补丁描述低估影响。

SCCM 广泛部署,PoC 已公开,未打补丁即受威胁。

RT @_Mayyhem: Patch SCCM with https://t.co/u0RhyPLtGz or you're likely vulnerable to a new hierarchy takeover technique (CVE-2026-47301) discovered by Omri Baso from @XMCyber_ that worked in my lab out of the box. MS's KB description doesn't do the impact justice. https://t.co/THz1p46O0x

cvepocwindows提权 @T3nb3w source ↗

Chrome WebGL UAF 漏洞 CVE-2026-9876 获 25 万美元赏金。

浏览器高危漏洞,与已利用的 Adreno 漏洞相关,影响面大。

RT @ianinpoc: $250,000 bounty for CVE-2026-9876, reported by happy2me. Critical WebGL UAF in Chrome. Chromium’s issue title links it to a bypass of the previously exploited Qualcomm Adreno CVE-2025-27038. happy2me must be very happy today 😄 https://t.co/p9iVPg7kZN https://t.co/8TvAQjD4Rz

cve浏览器rcepoc @0xocdsec source ↗

Windows IKE 扩展 RCE 漏洞 CVE-2026-33824 被在野利用,已入 KEV。

无需认证的远程 RCE,已遭利用,需立即修补。

RT @ridvanyagli: 🚨 Windows'ta kritik RCE açığı aktif olarak istismar ediliyor! CVE-2026-33824, Windows IKE Extension bileşenindeki bir "double-free" hatasından kaynaklanıyor. — Kimlik doğrulaması gerektirmiyor — Ağ üzerinden uzaktan kod çalıştırılabiliyor — IKEv2 etkin sistemleri etkiliyor — UDP 500 ve 4500 saldırı yüzeyinde CISA, CVE-2026-33824'ü Known Exploited Vulnerabilities (KEV) kataloğuna ekledi. Windows sistemlerinizi güncelleyin. IKE/IPsec kullanılmıyorsa UDP 500/4500 için inbound erişimi de engellemeyi düşünün.

cvercewindows事件 @0xocdsec source ↗
Must-see3

微软签名 Defender 驱动 BTR.sys 可被滥用为 Ring-0 原语。

签名驱动滥用,可绕过安全防护,影响 Windows 全系。

RT @blackorbird: Microsoft’s signed Windows Defender Boot-Time Removal driver (BTR.sys) is a one-shot kernel component that decrypts an RC4-encrypted transaction list from an Alternate Data Stream and performs Ring-0 operations. An attacker with SeLoadDriverPrivilege can craft a valid encrypted config and load it early via a transient “Boot Bus Extender” service, abusing it as a trusted kernel primitive to bypass Tamper Protection, delete EDR/AV components before they start, drop malicious drivers, and gain persistence, without any vulnerability or BYOVD. No in-the-wild abuse has been observed. https://t.co/Ly5SvZywEh

windows驱动提权绕过 @0xocdsec source ↗

KVM SEV-SNP 处理器状态变更处理存在堆越界读写漏洞 CVE-2026-53360。

虚拟化逃逸风险,影响云安全,技术分析深入。

Analysis of CVE-2026-53360: heap out-of-bounds read/write in KVM’s SEV-SNP Page State Change handler (@anand_himanshu) https://t.co/psMctIGNIg #infosec https://t.co/ojL2EQYYNu

cvek8s逃逸 @0xor0ne source ↗

Linux ipv6 UAF 漏洞,2021 年引入,2026 年修复,PoC 已公开。

长期存在的内核漏洞,PoC 公开,影响大量 Linux 系统。

RT @nebusecurity: Today’s exploit is from a ipv6 UAF, introduced in Nov 2021, fixed on upstream in Aug 2026. Discovered and exploit by NebuSec security pipeline. Exploit in our GitHub: https://t.co/siUO80WokE https://t.co/zjLfXfnLL1

cve内核poclpe @0xocdsec source ↗
Recommended15

NLIR:用 YARA 规则语法检测提示词恶意软件的 PoC。

AI 安全检测新思路,将提示注入视为编译器问题。

RT @eversinc33: I was thinking about how to hunt/detect prompt malware & once I started treating it like a compiler problem, the answer was clear. NLIR is a PoC IR for natural language, which enables one to hunt over prompts with a yara like rule syntax. See my blog: https://t.co/NXdaoEDUq4 https://t.co/bKdFjweEjg

ai_agentllm工具poc @felixm_pw source ↗

Patrick Wardle 公开 macOS 恶意软件样本 BotKing。

macOS 恶意软件分析样本,可供研究学习。

Have just added this sample to the @objective_see public macOS malware collection ...as 'BotKing' 👑 https://t.co/26BiADaeRu (pw: infect3d) #SharingIsCaring Read more: https://t.co/xYaRTHqCRP

macos恶意软件工具 @patrickwardle source ↗

SAP Commerce Cloud 关键漏洞在补丁后三天即遭利用。

企业级软件漏洞利用速度加快,需关注补丁优先级。

RT @SCMagazine: A critical SAP Commerce Cloud flaw was exploited just three days after patching, according to @DefusedCyber, highlighting how quickly attackers are moving against enterprise vulnerabilities. #cybersecurity #CISO #infosec https://t.co/ad5CWZXjLL

cve供应链事件 @DefusedCyber source ↗

微软签名 Defender 驱动被逆向,可提供任意文件与注册表操作。

无需漏洞的 Ring-0 原语,影响 Windows 安全模型。

RT @vinopaljiri: 🔥 This one is special! Honored to have shared it on the main stages at #BHUSA & #DEFCON. Now the full write-up, every detail, is finally public. 🥳 🤔 A signed Microsoft driver, used exactly as designed, turned into a Ring 0 primitive ➡️ no exploit, no CVE, no BYOVD... ☝️ Just reversing an undocumented protocol until a trusted #Defender driver hands you arbitrary file + registry ops from Ring 0 ➡️ 18 versions, one RC4 key, 15+ years unchanged. ⚒️ Then I wrote #BTR_CLI to prove it: https://t.co/EOxx5ioEWz #BTR #Reversing #OffensiveSecurity #KernelSecurity

windows驱动提权绕过 @0x64616e source ↗

AWSHound:将 AWS 组织转化为 BloodHound 攻击路径。

云安全新工具,可帮助发现 AWS 权限提升路径。

RT @SpecterOps: "Can this role read that bucket?" and "Can it decrypt that key?" aren't the same question. @n0pe_sled's latest blog post introduces AWSHound, free, self-hosted, turns AWS Orgs into real BloodHound CE attack paths. Check it out: https://t.co/jojzxphhx5

工具提权 @0x64616e source ↗

Kerberos 持久化:使用 Windows token 和 CS beacon。

红队持久化技术,有实操价值。

RT @SEKTOR7net: Kerberos persistence with Windows tokens and CS beacon. A post by Romain de Reydellet (@pentest_soka) Source: https://t.co/M4xnM22YGj #redteam #blueteam

windows提权工具 @J3rge source ↗

Mandatory User Profiles 持久化技术的检测数据源与 playbook。

蓝队检测新持久化技术,有实操价值。

🗨️ The data sources required to detect the persistence technique of Mandatory User Profiles (https://t.co/BTofHH5siv): ✅ Microsoft-Windows-User-Profile Service Provider (5 & 67 Event IDs) ✅ File Creation - https://t.co/BTofHH5siv ✅ Image Loading - Offreg.dll Playbook: 🖊️ https://t.co/1V0oUtQVf6

windows检测工具 @ipurple source ↗

NeedleStealer:Go 编写的窃密木马,C2 基础设施公开。

新型恶意软件情报,IOC 可查。

RT @abuse_ch: NeedleStealer 🪡🪝 written in Go ⤵️ 🔎 HTTP user agents observed: User-Agent: Loader-cli/v1 user-agent: Go-http-client/2.0 📡 Botnet C2s, all behind Cloudflare CDN: http://woolvilli .com/api/v2 http://allremdeskriki .com/api/v2 http://dubl1allremriki .com/api/v2 http://dubl2allremriki .com/api/v2 💡 Related C2 infrastructure at Vultr 🇳🇱: http://136.244.100 .54:8899/api/v1/agent/register http://136.244.100 .54:8899/api/v1/agent/ws ⚱️ Artifacts: \Sessions\1\BaseNamedObjects\Local\NeedleRemoteAgentSingle C:\Users\user\AppData\Local\Temp\needle-2fa 📄 Malware samples: https://t.co/re9St3VLwC 🦊 Relevant IOCs are on ThreatFox: https://t.co/vpsjVZG1Wq Stealer admin panel⤵️

恶意软件事件情报 @virusbtn source ↗

CISA 警告:攻击者使用互联网扫描和 AI 脚本针对西门子 PLC。

关键基础设施安全,AI 辅助攻击新趋势。

RT @CISACyber: Cyber threat actors are using internet scanning & AI-generated scripts to target Siemens S7 Series programmable logic controllers (PLCs) across #CriticalInfrastructure. Read our advisory for mitigations within the broader threat landscape of PLCs👉 https://t.co/cIHvUZgnGQ https://t.co/UX7hZvffTK

固件事件ai_agent @virusbtn source ↗

Mythic C2 新 profile:通过 LLDP 协议进行 P2P 通信。

C2 隐蔽通信新方法,对红队有参考价值。

Mythic C2 profile for peer-to-peer communication over IEEE 802.1AB (LLDP). C2 data is carried inside Organizationally Specific TLVs (Type 127) with a configurable OUI so that frames blend with vendor-specific LLDP extensions on the wire. https://t.co/5PFoz7428y

工具c2绕过 @ipurple source ↗

NetSPI 发布 BOFScale:CDN 前置的 tailnet,用于 BOF-PE。

红队基础设施新思路,结合 overlay 网络与内存工具。

Red teamers: your BOF just got its own tailnet. Blue teamers: now ask what telemetry gives it away. NetSPI's BOFScale takes the BOF-PE concept and builds a CDN-fronted tailnet, combining modern overlay networking with in-memory red team tooling. This is the kind of infrastructure research both sides should study. By Ceri Coburn (@EthicalChaos) / @NetSPI: https://t.co/BL9pdOXZwX #RedTeam #DetectionEngineering #C2

工具c2绕过 @cr3ghost source ↗

Process Monitor 4.10 新增 IPC 监控,支持命名管道事件。

蓝队检测工具新功能,有实操价值。

RT @zeze7w: Just noticed that starting with Process Monitor 4.10, Procmon now supports IPC monitoring, including Named Pipe events. https://t.co/9EIvVQCnYN

工具检测 @0xTriboulet source ↗

mora-hwbp:基于硬件断点的函数 Hook PoC。

内存补丁替代方案,对红队有参考价值。

A security-research Proof-of-Concept (POC) demonstrating hardware-breakpoint (CPU debug register) based function hooking as an alternative to traditional in-memory code patching. https://t.co/Ds7XNYaB6C

工具poc绕过 @ipurple source ↗

Kuna 自优化反编译器 v1.160,支持 Ghidra GUI。

逆向工程新工具,有实操价值。

RT @mahal0z: Kuna, the self-refining decompiler project, is still going and is on v1.160. This week, we got some better support in the Ghidra GUI. You can use Kuna in Ghidra, hopefully with better decompilation, for free! The image shows the Kuna core and Sleigh core swapped in Ghidra 12.1.2. https://t.co/P9wHey9FnY

工具逆向 @alkalinesec source ↗

NebuSec 发布 Linux 内核漏洞利用,CVE 尚未分配。

0-day 漏洞利用公开,影响面大。

RT @spendergrsec: Vulns being exploited before a CVE even exists: https://t.co/BisfiHbICW https://t.co/vyyxxYXn1r

cve内核poclpe @0xocdsec source ↗
More57

Quarkslab 研究:如何防御 AI 辅助逆向工程。

AI 逆向对抗新思路,对软件保护有参考价值。

RT @quarkslab: "Software protection is futile, AI will break it", they said. But, does it? how? To shine some light read about Rémy Salim's experiments in "Defeating AI-Assisted Reverse Engineering" Where is the fair play, Claude? https://t.co/WiqzDEjCA8 https://t.co/UGuruFnX7j

ai_agent逆向议题 @_winterknife_ source ↗

使用 AI 辅助构建 LLVM 混淆器。

AI 辅助开发安全工具的新实践,有参考价值。

Building an in-tree LLVM obfuscator solo, with an AI pair - @und3ath1 https://t.co/8yEDYtgthT

工具ai_agent议题 @pentest_swissky source ↗

Linux 内核 CVE 被拒,CAP_NET_ADMIN 漏洞是否算漏洞引争议。

内核漏洞管理政策讨论,影响漏洞披露流程。

RT @spendergrsec: https://t.co/MHVO0KjRg1 https://t.co/8zaXgrHx7b CAP_NET_ADMIN vulns aren't vulns anymore? What happened to the cow milking machines? What happened to "we don't know your usage"? Do they have any idea how many currently active CVEs fall under this same case? https://t.co/xqWnYiK65T

内核cve议题 @0xocdsec source ↗

BSidesCbr 议题:构建自主 N-day 漏洞利用生成管道。

AI 自动化漏洞利用研究前沿,值得关注。

RT @BSidesCbr: We're excited to welcome @chompie1337 back to BSidesCbr After keynoting two years ago, she's back with: "Building an Autonomous N-day Exploit Generation Pipeline" Pwn2Own winner. Leader of IBM X-Force Offensive Research. https://t.co/WpX27UEFkz https://t.co/MQX8rvMiCX

ai_agentpoc议题 @Teach2Breach source ↗

GrapheneOS 称 Cellebrite 无法破解其锁定设备。

移动端安全对比,对设备选择有参考价值。

RT @GrapheneOS: @rhensing Cellebrite's documentation they've been consistently able to exploit iPhones for the past several years. Meanwhile, they still hadn't progressed past exploiting a locked GrapheneOS device updated in 2022 and even lost unlocked device extraction in 2024. https://t.co/DPJSQITAgi

移动端议题 @0xocdsec source ↗

公开沙箱扫描结果:经典进程注入技术。

恶意软件分析样本,可供研究。

Here a public scan result with the updates, a classic process injection https://t.co/AWCBgKcg3g

恶意软件工具 @Salsa12__ source ↗

Brute Ratel C4 集成虚拟机,badger 大小仅增 35kb。

C2 框架新特性,对红队有参考价值。

Virtual Machine integration for BRc4 is now complete. I have to agree that building the VM was the easy part. The hard part was the integration while keeping the size of badger low. Low-key happy that the final size of the VM interpreter embedded inside the badger is a total of around 35kb. Might bring it down a bit further if I could improve the inhouse compiler. 2.7 release is gonna be nuts!

工具c2议题 @NinjaParanoid source ↗

Zombie Card 攻击:过期 Visa 卡可被复活用于真实购买。

支付安全新攻击手法,影响面广。

RT @TheHackersNews: ‼️ Warning - Expired Visa payment cards can be revived for real purchases. New “Zombie Card” attack rewrites the expiry date a contactless terminal reads over NFC, while the card’s cryptography still validates. See how it works - https://t.co/PCqmL8OKma

事件poc移动端 @0xocdsec source ↗

MS-Nightmare Un-defend v2:当签名无法落地时会发生什么。

EDR 绕过新思路,对红蓝双方有参考价值。

⤵️ MS-Nightmare Un-defend v2 — What Happens When Signatures Can’t Land https://t.co/03kljHlxqn

绕过工具议题 @ipurple source ↗

四川无声信息技术与无糖信息、i-SOON 数据泄露关联。

国内安全公司数据泄露关联分析,有情报价值。

RT @tdatwja: 四川无声信息技术(Sichuan Silence)は、无糖信息(NoSugarTech)やi-SOONのリークデータを調べている際につながりを見つけました。 「双螺旋攻防实验室」や「PKAV」がキーワードですかね... ↓ 无糖信息について調べた時のメモです。 https://t.co/WgWCmFcaxa

事件情报 @NetAskari source ↗

Ubuntu 服务器 deploy 账户被入侵,改密码无效。

真实入侵案例分析,对防御有参考价值。

RT @Officialwhyte22: We changed the Linux account password. The login still happened again. That was when I knew the password was no longer the real problem. This happened on one of our Ubuntu web servers. A deployment account called deploy was meant to be used only by our internal build system. Nobody was supposed to be logging into that account manually, especially not after midnight. But while checking the authentication logs, I noticed something strange. The deploy account had logged in several times from the same external IP address: 9:08 PM. 11:11 PM. 1:14 AM. At first, the assumption was simple. Somebody had the password. So the password was changed. Later that night, another login appeared. That did not make sense. I went back to the SSH logs and checked the authentication method properly. The log did not say: Accepted password It said: Accepted publickey Now we had something. Whoever was accessing the server did not need the password anymore. I checked the account’s SSH configuration and opened: /home/deploy/.ssh/authorized_keys There were two keys inside. The first belonged to our legitimate build server. Nobody recognised the second one. Even more interesting, the authorized_keys file had been modified at 8:54 PM. The first suspicious login happened about fourteen minutes later. I generated the fingerprint of the unknown key and compared it with the fingerprint recorded in the SSH logs. Exact match. That second key was what had been used for all three suspicious logins. So changing the password was never going to stop the access. The attacker already had their own SSH key sitting inside the account. We disabled the deployment account, preserved the authentication logs and SSH files, removed the unauthorized key, rotated the affected credentials and started reviewing what had happened on the server during those sessions. What made this incident interesting was how easy it would have been to misunderstand it. If we had only seen repeated logins after a password reset, we might have assumed the new password had somehow been compromised again. But Linux had already told us exactly what was happening. Accepted publickey Sometimes one word in a log changes the whole investigation.

事件linux恶意软件 @Officialwhyte22 source ↗

Bitdefender 分析 SilkParasite 网络间谍行动,发现 5 个新 RAT。

APT 行动分析,新恶意软件情报。

Bitdefender Labs researchers analyse SilkParasite, a cyberespionage operation, assessed with medium confidence as China-nexus, that targeted government bodies across Central Asia. They found 7 RAT families in use, 5 of which were previously undocumented. https://t.co/415zUnSPs4 https://t.co/YVUKPGhdA5

事件恶意软件情报 @virusbtn source ↗

Grandoreiro 银行木马新活动,墨西哥成为主要目标。

银行木马活动分析,有情报价值。

Acronis researcher Santiago Pontiroli looks into recent Grandoreiro campaigns. Grandoreiro activity remains concentrated in Latin America, with Mexico accounting for the largest share of observed samples. https://t.co/Q3fS5DCTbE https://t.co/KDBhi5f8UV

恶意软件事件情报 @virusbtn source ↗

ToxicPanda 安卓银行木马新变种,支持 167 条远程命令。

移动端恶意软件新变种,影响面扩大。

Zimperium's Vishnu Pratapagiri writes about a new variant of the ToxicPanda Android banking trojan. This version introduces significant enhancements, including a comprehensive set of 167 remote commands, and substantially expands its targets globally. https://t.co/6o0tVupWjR https://t.co/5vWeuyi12N

移动端恶意软件事件 @virusbtn source ↗

Margin Research 提出新术语:half-day,AI 时代的 0-day。

AI 时代漏洞利用新概念,值得关注。

RT @Margin_Research: New terminology alert! Welcome to the multiverse of the half-day: https://t.co/LkAm7ncJ9I

ai_agent议题poc @_winterknife_ source ↗

AMD CPU DRAM 加扰研究:解锁 PSP、C6、微码、SMM。

硬件安全研究,影响 AMD 平台安全模型。

Unlocking everything on the AMD CPU with DRAM scrambling: PSP, C6, microcode, SMM, etc (@xoreaxeaxeax) https://t.co/6dJhLeBHcU #infosec

固件cpu议题 @0xor0ne source ↗

T-Mobile 发现并切断 Salt Typhoon 利用的第三方路由器。

APT 行动实例,展示供应链攻击风险。

RT @Joel_P_Atkinson: T-Mobile found unusual (Chinese government-backed hacking Salt Typhoon) behavior coming from a router belonging to a different telecom company. Staff drove there and snipped the cable connecting the box https://t.co/JmJc5umior

事件供应链情报 @NetAskari source ↗

GitHub 发布昨日事故完整根因报告。

大型平台故障根因分析,有参考价值。

RT @acolombiadev: I work at GitHub. yesterday was rough and i'm not pretending otherwise. full root cause report is up if you want the timeline and numbers, and what we are doing to prevent this from happening again. https://t.co/05do2WFoMa

事件报告 @0xocdsec source ↗

Tradecraft-Garden 发布 PIC 开发速成课程视频。

PIC 开发教学资源,对红队有参考价值。

RT @MalwareBibleJP: 読み込まれる場所が変わっても動くコード、いわゆるPIC(Position-Independent-Code)の書き方を、どのツールを使う場合にも通じる基礎として体系立てた、Tradecraft-Gardenの教材動画「PIC-Development-Crash-Course」。回避技法をC2から切り離して部品化する研究プロジェクト自身が公開したもの。 ただし収録後に操作コマンドが一本化されたため、動画に映るコマンドの書き方が現行版と食い違うという注記あり。手元で同じ手順を試すなら収録当時の古いアーカイブを使うように、という案内も添付。 プロジェクト側はこれらの成果物を、検知エンジニアリングやEDRの試験、攻撃を模した演習に使える素材として位置づけています。実際に出回るPICローダーがどう組み立てられるかを、攻撃者の実装を待たずに防御側が追える教材でもあります。 【要点の整理】 ・想定する環境として名前が挙がるのは、PIC向けのリンカであるCrystal-PalaceとStardustの2つ。それ以外で書く人に向けては、公開資料集へのリンクを1本置くという扱い ・2026年6月29日のリリースでlink、piclinkなど5つのコマンドが廃止され、cpl [command] という単一の入り口へ統合。視聴案内では、linkがcpl link、piclinkがcpl buildに当たるとの明記 ・同じ手順を試す際に使うよう示されているのは2025年9月10日リリースのアーカイブ(tcg20250910-bsd[.]tgz)で、動画が参照するファイル群はこの版に含まれるとの記載 詳細は以下を参照: 動画本体: https://t.co/gTB1oWsSvx 視聴案内と注記: https://t.co/UOOZdvhFM0 公開時の告知: https://t.co/sXTjLGI3Zv コマンド統合の記載: https://t.co/g7OnTuaieN (※可能な範囲でファクトチェックは実施済なものの、元記事の精度依存や速報・要約の性質上漏れもありうるため、正確な情報は一次情報を直接参照のこと)

工具议题绕过 @0xocdsec source ↗

x33fcon 2026 议题:EDR 内省。

EDR 内部机制研究,对红蓝双方有参考价值。

RT @x33fcon: #x33fcon 2026 talks: Levi Cailleret - EDR Introspection > https://t.co/VZfMs6nPvx https://t.co/8nEUHyBtfE

议题检测绕过 @0xocdsec source ↗

CISA:Medusa 勒索软件攻击超 500 家关键基础设施组织。

勒索软件大规模攻击,影响面广。

RT @slashdot: CISA: Medusa Ransomware Hit Over 500 Critical Infrastructure Orgs https://t.co/THhZ0uzTqa

事件勒索软件 @0xocdsec source ↗

沙箱逃逸时 DNS 的奇怪行为分析。

沙箱逃逸技术分析,有参考价值。

RT @_r_netsec: The Curious Incidents with DNS in the Sandbox at Escape-Time https://t.co/6esURa29OH

逃逸议题 @0xocdsec source ↗

PortSwigger 研究:CRLF 驱动的 HTTP 流去同步攻击。

HTTP 请求走私新变体,影响 Web 安全。

RT @_r_netsec: CRLF-Powered Desync Attacks: Beheading HTTP Streams https://t.co/HYy81sByHS

pocweb绕过 @0xocdsec source ↗

WebAssembly 沙箱逃逸,实现宿主机任意 shell 执行。

沙箱逃逸新案例,影响 WebAssembly 安全。

RT @_r_netsec: I escaped the WebAssembly's sandbox and got arbitrary shell execution on the host. https://t.co/SkCXMmkFuB

逃逸poc浏览器 @0xocdsec source ↗

SpecterOps 研究:Chromium 扩展作为 C2 和持久化机制。

浏览器成为红蓝对抗新战场,检测难度大。

RT @cr3ghost: How much visibility does your EDR really have when persistence and C2 live inside Chromium? New research from @SpecterOps explores Chromium extensions as a C2 + persistence mechanism, turning the browser itself into an interesting red vs blue battleground. Red teamers will love this. Detection engineers should read it twice. https://t.co/kb6hxq7cLg #RedTeam #DetectionEngineering #EDR

浏览器c2持久化 @cr3ghost source ↗

Wavlink 路由器多个型号存在未认证栈溢出漏洞 CVE-2026-74843。

物联网设备漏洞,无需认证即可利用。

RT @SecAlertsCo: 📡 Wavlink WN531P3/WN535M1: critical stack overflow via strcpy in export_pingortrace.cgi, CVSS 9.3, no auth required, network-exploitable. CVE-2026-74843 — check your firmware. #cybersecurity #ciso #cto #vulnerabilities #msp https://t.co/Yxj7ezLXab https://t.co/iWm8VJWm4F

cve固件rce @0xocdsec source ↗

Synack 研究:存储型 HTML 注入配合 DNS 技巧实现零点击 NTLM 认证。

零点击攻击链,影响 Windows 域环境。

RT @SynackRedTeam: A Domain Admin didn't click a phishing link. They just opened a meeting invite, and that was enough to hand over their domain account. SRT researcher Metin Yunus Kandemir found how a stored HTML injection on an internal web app, paired with a DNS trick that lands an attacker's server in Windows' "Local Intranet" zone, triggers automatic NTLM authentication with zero user input. Metin Yunus breaks down the full attack path, proof of concept and fixes in his Exploits Explained Blog: https://t.co/oiKXCnfqme #ExploitsExplained #ActiveDirectory #NTLMRelay #OffensiveSecurity #SynackRedTeam

pocwindows提权 @0xocdsec source ↗

Teach2Breach 新平台将教授如何用 AI 构建高质量植入体。

AI 辅助恶意软件开发教学,有参考价值。

my new platform will teach users how to build extremely high quality implants with AI. not slop. I'll show how to setup a workflow to maintain granular control over code and logic, and gain the benefits of AI dev speed, while not sacrificing design and OPSEC

ai_agent工具议题 @Teach2Breach source ↗

GrapheneOS 澄清与摩托罗拉合作,首批设备 2027 年推出。

移动端安全 OS 发展动态,有参考价值。

RT @Sans_Google: GrapheneOS clarifies their Motorola partnership. The first devices with GrapheneOS support should arrive in 2027. They will start with flagships (higher-end hardware than current Pixels, so more expensive). Lower-end devices will take more time to meet their requirements because the updates and security features aren’t as good, mostly due to how Qualcomm handles it. Useful extra details for anyone following the project. Official clarification here 👇 https://t.co/9Vz4uTp3sU Are you waiting for these Motorola GrapheneOS devices… or sticking with Pixel for now? #GrapheneOS #Privacy #OpenSource #DeGoogling #Motorola

移动端议题 @0xocdsec source ↗

Smukx 改进植入体会话与 QUIC 协议,支持 TCP 和 SMB 横向。

红队工具新特性,有实操价值。

Made a lot of improvements in implants session & QUIC Protocols. Making some cool BoFs and some of the cool features like plugin system will be coming up. correction: yesterday i was disclosing smb pivoting. today it's tcp pivoting. https://t.co/uuaZlKLxkc

工具c2议题 @5mukx source ↗

Water Gamayun 是唯一使用 provisioning packages 的威胁行为者。

APT 攻击手法分析,有情报价值。

Earlier this month, I wrote about .ppkg packages and how to use them for code execution, including a detailed detection strategy. It looks like the only threat actor that used provisioning packages was Water Gamayun 🇷🇺 🖊️ https://t.co/9ug5FGt5vh https://t.co/ES3asGqS5E

事件情报windows @ipurple source ↗

API Hashing 技术文章,编译时计算哈希避免字符串。

恶意软件开发技术,有参考价值。

API Hashing New Medium post, in this one we will see how to resolve Windows API addresses by hash computed entirely at compile time, leaving no function name strings in the binary https://t.co/Vsz61kuKn8 https://t.co/YtDhn4Hpb3

工具绕过 @Salsa12__ source ↗

Pixel 11 内核 LPE 漏洞已发现并负责任披露。

移动端内核漏洞,影响 Pixel 设备。

RT @pkqzy888: Pixel 11 just arrived. Such a great phone. Naturally, we had to see how long it would take to get a kernel LPE working on it. 😄 Here is one. Responsible disclosure already made a few weeks ago. https://t.co/hIziAi1TMP

移动端内核lpe @0xocdsec source ↗

讨论手机文件删除后是否可恢复的取证问题。

移动端取证知识,有参考价值。

The idea behind this post is important, but saying “everything on your phone is forever” is technically too broad. Deleting a file does not automatically mean a forensic examiner can recover that exact file forever. What happens after deletion depends heavily on the phone, operating system, file system, encryption, application involved, backups, cloud synchronization and what happens to the storage afterwards. On older storage systems, deleting a file could simply remove the reference pointing to that file while the underlying data remained on the storage until something overwrote it. That made traditional deleted-file recovery much more straightforward. Modern smartphones are different. iPhones and Android devices use flash storage, strong encryption and storage-management mechanisms that can make direct recovery of deleted data significantly more difficult. Once encryption keys are destroyed, storage blocks are reclaimed, or the device performs operations such as garbage collection/TRIM, recovering the original deleted content may become impossible. But this is where digital forensics becomes interesting. Investigators are not always looking for the original file itself. A deleted photograph might still leave behind a thumbnail, timestamp, filename, database entry or cloud copy. A deleted message might still appear in an application database, notification history, synced device, backup or another participant’s phone. A deleted browser search might leave traces in browser databases, cached content, DNS records, account activity or cloud-synchronized history. A deleted application may still leave configuration files, logs, databases or references showing that it previously existed. Even when the content itself is gone, metadata can sometimes prove that something happened, when a file existed, when an application was opened, when a device connected to Wi-Fi, when a USB device was attached, or when an account communicated with another account. Investigators may also obtain evidence from places outside the physical phone entirely: iCloud or Google backups, application providers, synced laptops or tablets, email servers, cellular-provider records and other devices involved in the communication. So the better way to explain this is: Deleting something from a phone does not guarantee that every trace of it disappears. Sometimes the original data is recoverable. Sometimes only fragments or metadata survive. Sometimes another system still has a complete copy. And sometimes the data really is gone. That distinction is exactly why mobile forensics is much deeper than simply pressing “recover deleted files.” A forensic examiner reconstructs activity by correlating artifacts from the device, applications, accounts, backups and surrounding infrastructure until those individual traces begin to tell the full story.

移动端议题 @Officialwhyte22 source ↗

智能恒温器内部结构科普。

物联网设备安全基础知识。

A smart thermostat may look like a simple temperature controller, but inside it is actually a small network-connected computer managing one of the most important systems in your home. At the centre is the main processor. This is the part that handles the thermostat’s logic, processes sensor readings, runs the device firmware, communicates with the network and decides when the heating or cooling system should turn on or off. The temperature and humidity sensors continuously measure the environment around the device. Some models also use occupancy, motion or ambient-light sensors to understand whether someone is home and adjust the temperature automatically. That is how smart thermostats can build schedules and reduce unnecessary energy usage. The Wi-Fi module and antenna connect the thermostat to your home network. Once connected, the device can communicate with a mobile app, cloud services, smart-home platforms and sometimes voice assistants. This allows you to change the temperature remotely, view energy reports, receive alerts and manage schedules even when you are not at home. Inside the device, flash memory stores the firmware and configuration data, while RAM gives the processor temporary working memory while the system is running. Some devices may also include a secure element or cryptographic chip to help protect sensitive keys used for authentication and encrypted communication. The HVAC interface and relays are where the digital side of the thermostat meets the physical heating and cooling system. When the processor decides that the room needs more heat or cooling, it activates the correct control circuit, which then tells the HVAC equipment what to do. This is also where cybersecurity becomes important. A smart thermostat does not operate alone. It can be connected to your router, cloud account, mobile app, smart-home platform, voice assistant and other IoT devices. That means the attack surface is much larger than the thermostat sitting on the wall. Weak passwords, outdated firmware, poor Wi-Fi security, exposed cloud accounts or excessive app permissions can all create problems. A compromised account could potentially allow someone to view device information, change settings or interact with connected smart-home services. Even the data produced by the thermostat can be sensitive. Temperature schedules, occupancy patterns and usage history may reveal when people are normally home or away. That is why protecting the account and network matters just as much as protecting the physical device. Good security starts with strong unique passwords, multi-factor authentication where available, updated firmware, WPA2 or WPA3 Wi-Fi, limited app permissions and regular monitoring of account activity. The diagram is a simplified educational representation, so exact internal components and layouts will vary between manufacturers and models. The main lesson is simple: A smart thermostat is not just a thermostat. It is a sensor platform, computer, network device, cloud-connected service and physical controller all working together. When you secure IoT devices, you are not protecting only the hardware. You are protecting the entire ecosystem around it.

固件议题 @Officialwhyte22 source ↗

推荐 Everdox 的 Windows 内核与逆向工程博客。

Windows 内核研究资源,有参考价值。

Chad Everdox appreciation post. Nick ‘Everdox’ Peterson (@nickeverdox) is genuinely one of the most underrated reverse engineers and Windows researchers in the industry. A lot of people know Riot Vanguard. Far fewer know the depth of Windows internals, kernel, anti-debugging, hypervisor and reverse engineering work behind one of the engineers who helped build and advance it. His old blog is an absolute gold mine. Some of this research is more than a decade old and still covers concepts people are learning and rediscovering today. Old but gold: Easy anti-trace with SYSCALL: https://t.co/cWpMDBIHzX Debugger detection with GetProcessIoCounters: https://t.co/NlQUlZQyVO BTF + LBR anti-tracing: https://t.co/ugj2T4VdPL Paged virtual memory as an anti-debug / anti-dumping primitive: https://t.co/R8fVpHinQC Kernel/user shared page kernel-debugger detection: https://t.co/SOgN6v0AHt RTL_USER_PROCESS_PARAMETERS anti-debugging: https://t.co/YggdAETOTW Full archive: https://t.co/Qbg8ScFxIt Then there is InfinityHook, another Everdox contribution that became a reference point for Windows kernel instrumentation: https://t.co/iSEJpIvye4 And his own article on https://t.co/SLm7Vlyd93: PatchGuard: Detection of Hypervisor Based Introspection [P1] https://t.co/pJNWLBE2Gu If you are interested in reverse engineering, Windows internals, Windows kernel research, anti-debugging, anti-cheat engineering, hypervisor internals or obscure tricks buried deep inside the OS, his work is invaluable. Also bookmark the wider https://t.co/SLm7Vlyd93 archive: https://t.co/oGY1wYHPFw That site is multi-author and contains excellent work from @daaximus , @aidankhoury across reverse engineering, kernel internals, virtualization and EPT. People spend a lot of time chasing the newest research. Sometimes the real gold has been sitting online for 10+ years. #ReverseEngineering #WindowsInternals #Infosec

windows内核逆向 @cr3ghost source ↗

PussyBlocker-UndefendV2:安全更新破坏工具。

EDR 绕过工具,有参考价值。

PussyBlocker-UndefendV2 - Security Update Disruption tool: Targets: ✅ Windows Defender ✅ Windows Update ✅ Kaspersky ✅ ESET https://t.co/0wP8hNhYvS

工具绕过 @ipurple source ↗

微软任务管理器新增 AI 工作负载监控功能。

AI 监控新功能,有参考价值。

RT @TheRegister: Microsoft gives Task Manager another task: Watching AI workloads https://t.co/FZqduunZdn

ai_agent议题 @artem_i_baranov source ↗

GrapheneOS 批评其他厂商 fork 时禁用其安全功能。

移动端安全 OS 生态讨论。

RT @GrapheneOS: @IntCyberDigest The devices from sold by these companies mostly use their own fork of AOSP or GrapheneOS. The companies forking GrapheneOS often make insecure changes such as disabling our USB-C port protection and locked device auto-reboot timer. They market these changes as being improvements.

移动端议题 @NetAskari source ↗

macOS 文件 quarantine 扩展属性科普。

macOS 取证知识,有参考价值。

A Mac user downloaded an application, moved it to another folder and renamed it. The file looked completely normal, but macOS still remembered where it came from. That memory was stored inside an extended attribute called com(.)apple(.)quarantine. When Safari downloads a file, macOS can attach hidden metadata containing the downloading application, a timestamp and a unique identifier. Finder does not normally show this information. In the image below, the @ beside the application’s permissions reveals that extended attributes exist. The xattr command then exposes the quarantine record, while spctl shows that Gatekeeper rejected the unsigned application. This is why macOS may warn you about an application even after it has been renamed or moved. The warning is not based only on the filename, the file is carrying its download history with it. For forensic investigators, that invisible tag can help connect a suspicious file to the browser or application that introduced it. Useful inspection command: xattr -l ~/Downloads/QuickNote.app

macos议题 @Officialwhyte22 source ↗

Malwarebytes 提醒:回复陌生短信会确认号码活跃。

社会工程学提醒,有参考价值。

RT @Malwarebytes: Ever receive a random text like "what's for dinner?" from a number you don't recognize? Replying confirms your number is active and responsive, making you a valuable target for scammers. Here’s why a polite response is worth money to cybercriminals. https://t.co/7H5itEEWx8

事件社会工程 @virusbtn source ↗

关于某安全配置应设为默认的讨论。

安全配置讨论,有参考价值。

This should be the default

议题 @0xTriboulet source ↗

Linux 内核 7.2 初步支持 Apple M3 芯片。

Linux 硬件支持进展,有参考价值。

RT @twtayaan: Apple's newest MacBooks can now boot Linux. Linus Torvalds just released Linux kernel 7.2, and buried inside the changelog is initial support for Apple's M3 chip. There is no official driver, no documentation, no cooperation from Apple at all. The Asahi Linux team spent months reverse-engineering Apple Silicon from scratch, with zero help from the company that built it. Right now it only boots to a serial console. Full graphics acceleration is still a work in progress. But the hardest part is done. The M3, one of Apple's most locked-down chips, now runs code Apple never signed off on. Back in 2020, Torvalds himself said getting Linux running on Apple Silicon looked like too much work for him personally to take on. A small team of volunteers started the project anyway in early 2021. Five years later, one MacBook at a time, they are quietly proving that a locked platform is not the same thing as an impossible one. Source: https://t.co/0zjIQi0Uor

内核议题 @0xocdsec source ↗

Btrfs 在 Linux 7.3 中性能提升 3-5 倍。

文件系统性能改进,有参考价值。

RT @phoronix: Btrfs Ready With More Performance Improvements For Linux 7.3: Some ~3x To ~5x Wins https://t.co/vZ82aEzCwW

linux议题 @0xocdsec source ↗

攻击者更多利用合法功能、身份和信任关系而非软件漏洞。

攻击趋势观察,有参考价值。

RT @HackingLZ: There is an entire follow on novel here about how attackers, once inside network and often even for initial access largely go after abuse of legitimate functionality, identity, configuration, and trust relationships rather than traditional software bugs. A lot of what actually gets people owned has never required a novel memory corruption vulnerability in the first place.

议题事件 @0xTriboulet source ↗

Citizen Lab 谈苹果用户收到间谍软件攻击通知数量空前。

移动端间谍软件威胁,有参考价值。

RT @citizenlab: Senior researcher @jsrailton spoke to @techcrunch about the “unprecedented” number of Apple users who recently received notifications alerting them to suspected spyware attacks against their devices. Read: https://t.co/EvAH1SjqBc

移动端事件 @0xocdsec source ↗

勒索软件犯罪分子冒充恢复公司诈骗同行。

勒索软件生态趣闻,有参考价值。

RT @TheRegister: Ransomware crook poses as recovery firm to steal payments from fellow extortionists https://t.co/SBXJW4cXC2

事件勒索软件 @artem_i_baranov source ↗

荷兰法医研究所称已破解 Google Pixel 手机。

移动端取证进展,有参考价值。

RT @IntCyberDigest: ‼️ BREAKING: The Netherlands Forensic Institute has found a way to crack Google Pixel phones, though it did not say which OS the phone was running. There is a high chance they were using an OS like GrapheneOS, since all three suspects were using Google Pixel phones. Or perhaps they are just fans of Google products. They have already cracked one of the suspects' phones — that of Swedish national Veronica K., a suspect in a triple murder — prosecutors told the high-security court at Schiphol today. The phone held images of weapons and stacks of cash, plus chats investigators can now read. The Forensic Institute expects to crack the two co-defendants' Pixels too.

移动端事件 @0xocdsec source ↗

HVCI 与 VBS 安全机制科普。

Windows 安全机制基础知识。

HVCI, or Hypervisor-protected Code Integrity, is one of the important security features built on top of VBS. Normally, Code Integrity runs as part of the normal Windows environment. With HVCI, kernel-mode Code Integrity runs in the isolated VBS environment, while the hypervisor helps protect that security boundary from the normal OS. Why does this matter? The Windows kernel has extremely high privilege. If an attacker exploits a kernel vulnerability, they may gain powerful memory read/write capabilities. One possible next step is modifying kernel code or creating executable kernel memory. HVCI makes this much harder. With HVCI enabled, kernel executable memory is subject to stronger Code Integrity rules. Code must pass Code Integrity validation before it can execute, and HVCI prevents memory from being both writable and executable. So an attacker cannot simply do: Get kernel memory write -> modify executable code -> execute it HVCI also affects kernel drivers. Drivers execute in kernel mode, so they need to follow these memory and code-integrity rules. For example, HVCI-compatible drivers should not: Create writable + executable memory Generate executable code dynamically Modify executable system memory Treat arbitrary data as executable code The important part is the trust boundary. HVCI does not prevent kernel vulnerabilities from existing. It makes it harder to turn a successful kernel compromise into arbitrary modified kernel code execution. The simplified model is: Normal Windows kernel -> VTL0 Code Integrity -> isolated VBS environment Hypervisor -> protects the isolation Kernel code -> must satisfy Code Integrity before execution So HVCI is not a replacement for fixing kernel vulnerabilities. It is a mitigation that makes the post-exploitation path much harder, especially attacks that depend on modifying or creating executable kernel code.

windows议题 @OSdev_ source ↗

评论:AI 将影响网络安全。

行业观点,有参考价值。

CVEs everywhere 0days everywhere RCEs everywhere And yet I still see some posts say AI won't affect cybersecurity 🤡

ai_agent议题 @h4x0r_dz source ↗

预测漏洞利用将增加 2-3 年直到新安全基线普及。

行业趋势预测,有参考价值。

RT @fr0gger_: My guess is that we will see an increase of vulnerabilities exploitation for 2-3 years until we get an inflection point where most software are running with new security baselines.

议题 @_xpn_ source ↗

NSA 发布 PLC 防御指南,应对 AI 辅助攻击。

关键基础设施安全指南,有参考价值。

RT @NSACyber: NSA and others releases guidance on applying prevention tactics to strengthen defense of U.S-based programmable logic controllers being targeted by cyber actors using AI. Learn more: https://t.co/HO99aak50Y #cybersecurity #AI

固件议题 @0xocdsec source ↗

Linux 内核漏洞已修复并 backport 到 6.12.103。

内核漏洞修复进展,有参考价值。

RT @FrankOverF1ow: Fixed upstream and backported to 6.12.103 while the latest Debian 13 is 6.12.101 so....

内核cve @0xocdsec source ↗

0xpwnie 分享图片。

无实质内容。

https://t.co/SEdzxdEVBT

议题 @0xpwnie source ↗

0xpwnie 分享图片。

无实质内容。

https://t.co/RH8Ka3FpHG

议题 @0xpwnie source ↗

Smukx 分享进入企业红队的故事。

个人经历,有参考价值。

Sharing my Small Journey about how i got into corporate Red Teaming.... i found these screenshots while moving my files across my old NAS. This was a special moment for me when i was 20. this was the last part of my interview, where i had to bypass a live environment within 24 hours, with an edr installed and set to maximum protection mode. this was my first job lol. At that time i was mentally not alright. i had just gone through a breakup at that time lol. it was the first time i had faced this kind of shitty situation, so i wasn't in a good mood and i got stuck. i still attended the interview because i felt like i wanted to give it a try, cuz red teaming & malware development is my passion & obsession. i was able to get a callback by using adaptixc2 with some minimal modifications and a fresh loader written in rust at the movement, all within 4 hours of constant coding, debugging, and testing. i still had 20 hours left and didn't know what to do, so i just added the initial phase with filefix, chained everything together, and ended up framing a full ttp cycle, which they really didn't ask me to do. this was just an extra part from my side because i thought it would be nice to add. I was happy throughout the whole challenge because i wasn't thinking about anything else, just the goal. just one callback. After preparing the documents for 3 hrs. i was able to submit it within the challenge time. Later after sometime i realized that everything happens for an reason. If you are kind and helpful, the kindness will return to you someday. If you are good, god will always leads an good way even when the situation is bad. After an year passed (Present):- conducting engagements against edrs became my normal routine lol. Things learned from past and mistakes :- - your passion & goals comes first, then everything else. - if you really work hard, you will get results. - if it doesn't work, take an break and try again until you succeed. - love but don't attach :) After the report submission, they reached out to me within 2 days, and after that, the quoted post says it all😀

议题 @5mukx source ↗

Smukx 回复评论。

无实质内容。

@_EthicalChaos_ Nicee !!

议题 @5mukx source ↗