Megatron LLM Hub
全部
Twitter

推特安全流

头条5

PowerShell 1-click RCE 新 0-day,CVE-2026-70337 已分配。

PowerShell 1-click RCE 影响面广,PoC 已公开,需立即评估。

RT @TheTeaToast: Just got a new 0-day CVE assigned: another PowerShell 1-click RCE Missed the mail and only found out about it late. CVE-2026-70337 https://t.co/tjeSBjT1nj

rcecvepocwindows @0xocdsec 原文 ↗

Fedora 44 io_uring 符号错误漏洞 CVE-2026-52933,EXP 已公开。

Linux 内核提权漏洞,EXP 公开,影响最新 Fedora 系统。

RT @nebusecurity: Today's exploit is for the latest Fedora 44, a signedness in io_uring, CVE-2026-52933. It was introduced in Nov 2022 and fixed upstream in Apr 2026. Discovered and exploited by the NebuSec security pipeline (RANDOM_KMALLOC_CACHES + SELinux) EXP source: https://t.co/OSkK67AFNE https://t.co/cLbP0GyJDK

lpecvepoc内核 @0xocdsec 原文 ↗

Windows 内核 LPE 1-day 漏洞被公开,细节已发布。

Windows 内核提权漏洞,可复现,影响面大。

RT @nhh9905: My second CVE 1-day Windows Kernel LPE. Feels amazing. https://t.co/S7zLpfyaqB

lpecvewindows内核 @0xocdsec 原文 ↗

KVM guest-to-host 堆破坏漏洞被发现,已有分析文章。

虚拟化逃逸漏洞,影响云环境安全,技术细节已公开。

RT @blackstormsecbr: I found a KVM guest-to-host heap corruption bug and someone else got there first: https://t.co/akHBTK8OT0 #vulnerability #hypervisor #kvm #exploitation #exploit https://t.co/c0drygdBqb

逃逸kvmcve @0xocdsec 原文 ↗

Claude-AD 开源:AD 渗透测试 playbook 作为 Claude Code skills。

AI Agent 驱动的 AD 攻击工具,与首要意图直接相关。

RT @yeraymd44: I've been pwning AD labs for months with a private toolkit I built. Worked every time. Today I'm opening it: Claude-AD. The AD engagement playbook as Claude Code skills. Kerberos, ADCS ESC1-17, ACL abuse, coercion. Drives your standard tools. https://t.co/ZMxGOVfl1u

ai_agent工具ad攻击 @0xocdsec 原文 ↗
必看3

YSoNet v2026.8.1 发布,新增 .NET Framework 2.0-3.5 支持。

.NET 反序列化利用工具更新,增强测试能力。

RT @irsdl: YSoNet v2026.8.1 is live. 50 to 62 gadgets, new .NET Framework 2.0 to 3.5 support, dedicated 4.0 coverage, stronger testing, and 508 archived references for researchers in the markdown format! 🔥 Thanks @cjm00n and @sinsinology! https://t.co/JgGRh1hbpG

工具rce.netpoc @_RastaMouse 原文 ↗

ditto 开源:PowerShell 与 JavaScript 混淆工具。

开源混淆工具,可用于红队和恶意软件分析。

ditto - Powershell & Javascript Obfuscator https://t.co/ZaSzZwqKJ7

工具混淆powershelljavascript @ipurple 原文 ↗

Atlas 发布:基于 Titanis 的 netexec 替代工具。

新的网络执行工具,支持多协议,值得上手。

RT @portbuster1337: releasing Atlas, basically netexec, but built on top of Titanis, shout out to @codewhisperer84 for the amazing lib still more protocols to come, atlas evolves as Titanis evolves https://t.co/lp9dAneduX

工具netexec攻击协议 @0xocdsec 原文 ↗
推荐7

发现浏览器执行 HTML 标签名中的 JavaScript URL 的漏洞。

跨浏览器执行漏洞,影响面广,技术细节已公开。

RT @garethheyes: I put a JavaScript URL inside an HTML tag name, and every browser executed it. Apparently, tag names are code now. Link & explanation below 👇 https://t.co/nQieo7pIw0

浏览器xsscvepoc @0x64616e 原文 ↗

博客系列第三部分:如何建立隧道。

隧道技术是渗透测试和红队的基础,有实用价值。

RT @_ar0x4: @x33fcon https://t.co/ZFt018HRPQ The third and probably final part of this blog series (for now), but who knows. 😅

工具隧道红队议题 @0x64616e 原文 ↗

视频演示:通过 MSBuild.exe 和 .tt 文件执行代码。

MSBuild 攻击手法,可用于绕过检测。

RT @ipurple: A quick video of how to use MSBuild.exe to target a .csproj file that has been tampered with multiple text template files and execute code embedded in .tt files.

工具绕过windows攻击 @0xocdsec 原文 ↗

开源维护者抱怨 AI 生成的垃圾邮件攻击,QEMU 项目被刷 132 个 bug。

AI 垃圾邮件攻击开源项目,影响维护者工作。

RT @Itsfoss: Open source maintainers are complaining about a new kind of harassment: AI-generated spam at scale. The QEMU virtualization project was hit hard when a single user filed 132 bug reports in under 10 minutes. Many were created seconds apart, none followed the bug report template, and not one showed any sign of human analysis or a proposed fix. Just raw AI output dumped into the tracker. Red Hat's Daniel Berrangé, who maintains QEMU, called it "a denial-of-service attack on maintainers". "Reports ignored the bug template and showed no sign of any human analysis," he wrote, pushing him to call on GitLab to implement rate limiting for non-members. This is not an isolated event. Maintainers across GitHub and GitLab are describing the same pattern: AI tools make it so cheap to generate and submit that bad-faith or careless users can flood a project with junk in minutes. The people on the receiving end are mostly unpaid volunteers working to maintain open source projects in their spare time. Some projects are now shutting down outside contributions entirely. Others are updating their contributor agreements to require human-written attestations. GitHub is reportedly building emergency tools to help. In the meantime, maintainers can do nothing but complain.

议题ai开源供应链 @0xocdsec 原文 ↗

x33fcon 演讲:Credential Relay Phishing 视频已发布。

凭证中继钓鱼攻击手法,有实际演示。

My @x33fcon talk about Credential Relay Phishing is finally out! Watch me struggle through the live Google phishing demo, a day after the pirate ship party, which deprived me of my last few brain cells. 😜 Wrath of demo gods and AI lulz included. 🥳 https://t.co/5M9UwkljZm

议题钓鱼攻击凭证 @mrgretzky 原文 ↗

x33fcon 演讲:用 AI Slop 降级 FIDO MFA。

AI 攻击手法,绕过 MFA,有实际演示。

RT @x33fcon: #x33fcon 2026 talks: @mrgretzky - Downgrading FIDO MFA With AI Slop > https://t.co/g6xc4SDP61 https://t.co/LRtdldfIl7

议题ai绕过mfa @0xocdsec 原文 ↗

计划发布 Elastic 检测绕过和 Singularity rootkit loader 的 writeup。

Linux rootkit 和检测绕过技术,有研究价值。

RT @MatheuzSecurity: Maybe i do a writeup for the new Elastic detection. Bypassing this and presenting the new Singularity rootkit loader #linux #rootkits #malware https://t.co/GykGmP1MeE

工具rootkitlinux绕过 @0xocdsec 原文 ↗
更多4

展示 C2/rootkit 的 Web 界面。

My c2\rootkit web interface (ops fake info in the panel) https://t.co/fWpP6lzT4Q

工具c2rootkit @J3rge 原文 ↗

正在开发 C2/rootkit 的 Web 界面。

working on the web interface for my c2/rootkit. https://t.co/2UlDvziMzo

工具c2rootkit @J3rge 原文 ↗

正在开发自定义 CS BOF loader。

still working on my custom cs bof loader. .. https://t.co/uuRJEjOA07

工具c2loader @J3rge 原文 ↗

Combat Theater 工具展示视频发布。

We've put together a new showcase video! Combat Theater makes executing and testing malware techniques fast, easy and accessible. In this video we demonstrate the core usage of the tool, how our customization engine works, generating reports, etc. https://t.co/NUz5O6IeIg

工具恶意软件测试 @felixm_pw 原文 ↗