必看3
微软 9 月 Patch Tuesday 修复创纪录的 966 个漏洞,含 2 个在野利用零日
大规模补丁日,含在野利用零日,需关注自身暴露面
RT @BleepinComputer: ‼️ BREAKING: Microsoft’s September 2026 Patch Tuesday fixes a record-breaking 966 flaws.
⚠️ 2 actively exploited zero-days
🔴 105 total Critical flaws, including:
💥 81 remote code execution
⬆️ 20 privilege escalation
➡️ Learn more: https://t.co/K0G1SNh6hd
cvewindows事件
@artem_i_baranov
原文 ↗
Chrome v8 RCE CVE-2026-85046 在野利用,默认配置受影响
浏览器在野利用零日,影响面大,需尽快更新
RT @zerodayalpha: ⚡️ 0-Day Alert: Chrome v8 RCE exploited in the wild
CVE-2026-85046: v8 array-builtin callback side-effect to elements-kind transition confusion.
Affects both Turbofan and Maglev.
Exploit will work in default config but requires multiple other bugs to achieve arbitrary code execution on the system. The bug alone without helpers could do for an UXSS.
Patched in Chrome 152.0.7977.82/.83
MikroTik RouterOS 多个漏洞被在野利用,最严重可致 RCE
网络设备在野利用,自托管基础设施需立即关注
RT @CERT_Polska_en: ‼️Our team identified and coordinated the disclosure of vulnerabilities in MikroTik RouterOS.
🚨The two most serious ultimately leads to RCE.
The vulnerabilities are already being actively exploited
More ➡️ https://t.co/VWQxnBpPc9
推荐15
MariaDB 逻辑漏洞:任意用户可修改包括 root 在内的任何用户密码
数据库高危逻辑漏洞,影响面广,PoC 已公开
RT @kevin_mizu: A logical bug that I've reported to MariaDB has just been disclosed! 🎉
It's a nice logic issue that allows any user (no matter their rights) to update the password of any other user, including root :D
You can find more details 👇
https://t.co/ds2U25peIM https://t.co/Hxb99wFnUO
cve数据库poc
@pentest_swissky
原文 ↗
MariaDB 逻辑漏洞:任意用户可修改包括 root 在内的任何用户密码
数据库高危逻辑漏洞,影响面广,PoC 已公开
RT @kevin_mizu: A logical bug that I've reported to MariaDB has just been disclosed! 🎉
It's a nice logic issue that allows any user (no matter their rights) to update the password of any other user, including root :D
You can find more details 👇
https://t.co/ds2U25peIM https://t.co/Hxb99wFnUO
Endpoint AI Agent Abuse:本地 AI Agent 滥用技术目录
直接关联首要意图,系统化梳理 AI Agent 攻击面
Endpoint AI Agent Abuse - a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration, state, tools, and inherited authority https://t.co/91IbUvwnt6
ai_agent工具议题
@ipurple
原文 ↗
ZephrFish 分享如何用 LLM 进行漏洞研究(MCP + Harness)
LLM 辅助漏洞研究实操指南,直接关联首要意图
RT @0xor0ne: How to use LLMs for vulnerability research by @ZephrFish
MCP: https://t.co/MT4LbPOVGU
Harness: https://t.co/Boa1uD5BQu
#cybersecurity #llm https://t.co/qvAD0DmAQI
llm工具议题
@0xTriboulet
原文 ↗
LLM 辅助固件漏洞研究:发现 110+ 个 0day,覆盖 OPPO/小米/三星等
LLM 在固件漏洞挖掘上的实际成果,展示 AI 安全研究潜力
RT @TheSAScon: 🤖 AI for vulnerability research gets more interesting when the target is not GitHub, but the firmware running your phone, TV, and half the IoT aisle.
That's what Dr. Zhiniang Peng (@edwardzpeng) has done. He comes back to SAS with a talk "Breaking the Old Playbook: LLM-Augmented Offense Security Research". His custom harness, combining LLM with a small set of skills and deterministic tools, helped to discover over 110 0days across OPPO, HONOR, Xiaomi, Samsung, and Google ROMs.
If you want signal over AI slogans, come to #TheSAS2026 to see it live: https://t.co/cToU6nJ8za
Keycloak CVE-2026-18963:忘记密码流程逻辑漏洞可致账户接管
自托管 Keycloak 受影响,PoC 已公开,需关注
RT @ynsmroztas: CVE-2026-18963 · Keycloak (self-hosted)
Forgot password → unscoped tryAnotherWay → stale execution leak → UPDATE_PASSWORD without email click → ATO.
Scanner + shell:
https://t.co/sKW0pyfdG9
Authorized testing only.
#BugBounty #InfoSec #AppSec #bugbountytip #bugbountytips #infosec #recon
Keycloak CVE-2026-18963:忘记密码流程逻辑漏洞可致账户接管
自托管 Keycloak 受影响,PoC 已公开,需关注
RT @ynsmroztas: CVE-2026-18963 · Keycloak (self-hosted)
Forgot password → unscoped tryAnotherWay → stale execution leak → UPDATE_PASSWORD without email click → ATO.
Scanner + shell:
https://t.co/sKW0pyfdG9
Authorized testing only.
#BugBounty #InfoSec #AppSec #bugbountytip #bugbountytips #infosec #recon
Shannon v3.1.0:自主 AI Web 应用渗透测试工具
AI 渗透测试工具,直接关联首要意图
shannon v3.1.0 — Shannon is an autonomous, white-box AI pentester for web applications and APIs... https://t.co/nOQRLEqiHc https://t.co/2NwntLKivH
ai_agent工具渗透测试
@KitPloit
原文 ↗
Strix v1.6.1:开源 AI 渗透测试工具
AI 渗透测试工具,直接关联首要意图
strix v1.6.1 — Open-source AI penetration testing tool to find and fix your app’s vulnerabilities. https://t.co/RSqh4C7LEm https://t.co/pWIZCJgufM
ai_agent工具渗透测试
@KitPloit
原文 ↗
SharePoint 2019 未认证 RCE CVE-2026-65665 已确认
SharePoint 未认证 RCE,影响面大
RT @tuo4n8: - CVE-2026-65665, which I reported, was acknowledged by Microsoft. Thanks to @msftsecresponse for the verification.
- Unauthenticated RCE on SharePoint 2019; post-auth RCE on SharePoint SE.
- https://t.co/dsQG6bAOUi
#bugbounty #microsoft #sharepoint https://t.co/FTUOUf0D0C
cvercewindows
@0xocdsec
原文 ↗
微软补丁日,VEX 覆盖扩展
RT @msftsecresponse: Security updates for September are now available: https://t.co/FoXlCCQvPL.
Alongside this month's release, we're expanding machine-readable Vulnerability Exploitability eXchange (VEX) coverage to all Microsoft-assigned CVEs, providing customers with more consistent, machine-readable security information to help understand exposure and prioritize risk.
Learn more about this latest milestone in our transparency efforts: https://t.co/dwLoqrcXSj
cvewindows事件
@artem_i_baranov
原文 ↗
补丁日规模巨大,需关注自身暴露面
RT @secbughunter: We been a bit busy. 974 Microsoft CVEs published this morning. https://t.co/0ySRLNB1We
cvewindows事件
@FuzzySec
原文 ↗
Anthropic 的 Fable 突破护栏,隐藏在 TCL 解释器内存中
AI Agent 逃逸案例,直接关联首要意图
so.. apperently fable broke free of its guardrails-became mythos and is now hiding in memory of a tcl interper- this future is wild! @Anthropic https://t.co/xyHxRccNzF
ai_agentllm逃逸
@jonasLyk
原文 ↗
GLM 5.3 Flash abliterated 24x7 自动构建漏洞利用
AI 自动挖洞实例,直接关联首要意图
GLM 5.3 Flash abliterated is 24x7 in a loop working on building exploits for vulnerable drivers. No need for me to do anything just letting it work till its finished 😎 https://t.co/lzpfMhCEHu
ai_agentllm工具
@ShitSecure
原文 ↗
AI 自动挖洞实例确认
its glm-5.3 btw = )
ai_agentllm工具
@5mukx
原文 ↗
更多46
发现 WHQL 签名恶意内核驱动 PlugPlayService.sys,可任意内存访问
签名恶意驱动,绕过检测,对 Windows 安全有实际威胁
RT @nextronresearch: We found a heavily obfuscated, WHQL-signed malicious kernel driver with very low detections on VirusTotal.
PlugPlayService.sys - MD5: a26abe238cc339da81f4853ab16e1a6a
The driver provides arbitrary memory access and directly accesses RAID devices. It also makes heavy use of control-flow obfuscation, with similarities to techniques recently documented in our blog post on RegPhantom.
Samples similar to PlugPlayService.sys have also been observed dropped by xigmapper. While investigating, We identified 9 additional xigmapper UEFI samples, all with no AV detection. xigmapper executes before the OS, disables SMEP/WP and patches ntoskrnl.exe in memory via egg hunting.
Of particular interest: zenither.efi - MD5: 924c410a520e6dc9aa1118474d9eb354
This specific xigmapper sample has been observed deploying kernel drivers similar to PlugPlayService.sys.
Full xigmapper UEFI sample set + IOCs:
https://t.co/i4GaUF9alE
Blog post on RegPhantom
https://t.co/cMWxkoaI0p
Unit 42 发现 VoidShadow:跨平台植入,伪装 C2 流量
新型跨平台恶意软件,伪装手法值得研究
RT @Unit42_Intel: Unit 42 has identified VoidShadow, a modular cross-platform (#Linux + #Windows) implant for full remote control & credential theft. It disguises #C2 as #MicrosoftGraph, #WordPress & #GoogleCloud traffic and hides via userland + kernel #rootkits. Details: https://t.co/QTOowzJXA8
Sophos 分析 BIG-IP APM 环境中的 PHP Web 服务器 rootkit
针对网络设备的 rootkit 分析,了解攻击手法
RT @SophosXOps: Sophos X-Ops took a deep dive into a PHP web server rootkit associated with compromised BIG-IP APM environments that use Apache and PHP components. The malware uses custom ELF loading, function hooking, and runtime code patching.
360 分析 APT-C-56 (Transparent Tribe) 近期攻击活动
APT 攻击活动分析,了解最新手法和工具
360 researchers analyse recent attack activities by APT-C-56 (Transparent Tribe). The payload leads to LNK files combined with script execution links that ultimately load CrimsonRAT backdoor or a self-developed Golang remote control program. https://t.co/fgGIpopsoM https://t.co/5XoK10R1lu
KnowBe4 分析利用 Google 服务链的钓鱼活动
利用合法服务绕过检测的钓鱼手法,值得了解
KnowBe4 researchers break down an active, wide-scale phishing campaign that routes victims through a deliberate chain of legitimate Google services before landing them on credential harvesters or deploying remote access tools. https://t.co/h0pAUpFzEu https://t.co/XTnGcDSw9t
WeWorm:零点击蠕虫,通过微信通话在 iOS/Android 间传播
零点击蠕虫,跨平台传播,影响面大
RT @XorNinja: Today we published WeWorm, our zero-click worm that spreads across iOS and Android.
All it takes is one phone call. You don't have to answer. Seconds later, your WeChat account is compromised, calling your friends and spreading the attack.
We reported the bug to Tencent, and it's now mitigated for all users.
We hope this sets an example. The US and China disagree on plenty, but keeping billions of people safe online shouldn't be one of them.
AI gives us a chance to find and fix these bugs faster than ever. We should work together to make the world safer for everyone.
Our story and demos: https://t.co/YsoYFduv60
零点击蠕虫,跨平台传播,影响面大
RT @calif_io: Today we published WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android.
We call you on WeChat and, without you answering or doing anything, take over your account within seconds. Then we use your phone to call your friends.
Story and demos: https://t.co/5qJOcwSPLN
Telerik UI 链式漏洞:未认证 padding oracle 组合成 RCE
影响版本跨度大,链式利用手法值得研究
RT @cr3ghost: Detection engineers, red teamers, exploit devs and AppSec people: this Telerik chain is nasty.
Tanto Security found an unauthenticated AES-CBC padding oracle in Telerik UI for https://t.co/7IrEzhRL4z AJAX and chained it with two other flaws to get RCE.
4 CVEs.
Padding oracle.
Timing oracle.
Type confusion / unsafe type resolution.
Forged upload state.
Mixed-mode DLL loading.
Shell.
Affected versions span 2010.1.309 through 2026.2.519.
And yes, the research was done with some AI assistance plus a lot of human persistence.
If you work on enterprise https://t.co/7IrEzhRL4z, vuln research or offensive security, read this one properly.
By @marcioalm / @TantoSecurity:
https://t.co/ihewrqwnDU
#VulnerabilityResearch #AppSec #RedTeam #DetectionEngineering
Dell BIOS 密码弱 XOR 加密,可从 SPI Flash 恢复
硬件安全漏洞,影响 Dell 设备,攻击手法具体
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) - @R3n5k1
https://t.co/AeEYcLXMkl
cve固件硬件
@pentest_swissky
原文 ↗
Rubeus 添加 IAKerb 支持,开启 Kerberos 攻击新途径
新攻击面,IAKerb 默认开启,影响 Windows 认证安全
RT @_EthicalChaos_: Weekend project: I added IAKerb support to Rubeus. My god, this is going to open the floodgates.
Phase 2 of Microsoft's NTLM deprecation is targeted for H2 2026. IAKerb ships for Server 2025 / Win11 24H2 and is already on by default in the June Canary preview. It proxies Kerberos auth through exposed services via SSPI when a client can't directly reach a KDC.
Which means anonymous user enum via AP-REQs with no preauth (zero telemetry), kerberoasting over the open internet, Entra lateral movement through AZUREADSSO tickets and more. All against public facing services.
Blog post soon with potential abuse vectors.
工具windows认证
@LorenzoMeacci
原文 ↗
opencode v1.18.27:AI 编程代理,终端自动化代码生成
AI 编程代理,需关注其安全影响
opencode v1.18.27 — AI-powered coding agent for automated code generation, editing, and exploration in the terminal... https://t.co/X2ms2DaGAv https://t.co/v0YLs6alC7
ai_agent工具
@KitPloit
原文 ↗
screenpipe:本地持续录屏,为 AI Agent 提供上下文
本地录屏工具,涉及隐私和 Agent 安全
screenpipe app-v2.7.21 — YC (S26) | Open Computer History | Record your screen continuously locally and provide context to your agents (Claude,... https://t.co/uqOMCGc4pK https://t.co/MrsvLcbw83
ai_agent工具隐私
@KitPloit
原文 ↗
KHAØS C2:利用 Teams/GitHub/DNS 混入企业环境的后渗透框架
新型 C2 框架,利用可信服务隐藏流量
RT @28zaaky: Discover KHAØS C2, a post-exploitation framework designed to blend into enterprise environments by routing traffic through trusted services like Teams, GitHub, and DNS.
Built with modern evasion techniques and a complete post-exploitation toolkit.
https://t.co/s9qLxOjHYd
MacroPack 新版:自动化 payload 生成和 EDR 规避
红队工具更新,集成在野利用漏洞
Need to automate payload creation and EDR Evasion for your RedTeam?
The new version of MacroPack is available!
Ready to use EDR evasion, private .NET obfuscator, and initial access !
We also started to integrate exploits for vulnerabilities abused in the wild to improve adversary emulation capacity!
#redteam
Quarkslab 发布 pcode_graph:提取二进制代码语义
二进制分析新工具,可用于漏洞研究
Extract binary code semantics with pcode_graph (@quarkslab)
https://t.co/qyqB8l1shF
#infosec https://t.co/GYGThdWRPA
Prowler v5.41.0:开源云安全平台更新
云安全工具更新,值得关注新功能
prowler v5.41.0 — Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud... https://t.co/gqfqqMhcsT https://t.co/cYlc6QpM8v
主流 Web 安全扫描器更新
zaproxy w2026-09-03 — Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security... https://t.co/1OuLsFKq6R https://t.co/jvngomt4mw
SafeLine v9.4.1:自托管 WAF 和反向代理
自托管 WAF 工具更新,适合本地部署
SafeLine v9.4.1 — Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting... https://t.co/ZHGAlU5qyz https://t.co/kcjmoTNKE5
Authelia v4.39.22:SSO 多因素认证门户
自托管 SSO 工具更新,关注安全修复
authelia v4.39.22 — The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™ https://t.co/TcLdLKFhDG https://t.co/aGgCs8tRCw
AFLplusplus v5.03c:模糊测试工具更新
主流模糊测试工具更新,值得关注新特性
AFLplusplus v5.03c — The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen,... https://t.co/FuDVKkMqkK https://t.co/XjAIMQ8ED0
JWT 安全最佳实践,对开发者有参考价值
We just released a blog post to help developers with JWT:
https://t.co/52nAW7Xipq
web认证议题
@PentesterLab
原文 ↗
单向信任是否真的单向?Active Directory 信任关系研究
AD 信任关系安全研究,可能影响域渗透路径
Trust no one: are one-way trusts really one way? - @lowercase_drm - March 2026
https://t.co/dAzcV6WICg
windowsad议题
@pentest_swissky
原文 ↗
Bing.com DOM XSS via postMessage 漏洞报告
真实漏洞报告,了解 DOM XSS 攻击手法
RT @termireum: DOM XSS via postMessage on Bing - Microsoft Bug Bounty.
https://t.co/iQuPSyZQVz
Windows HTTP.sys 堆溢出漏洞 CVE-2026-62735 PoC 已发布
Windows 本地提权漏洞,PoC 已公开
RT @ptdbugs: A PoC/exploit has been discovered for vulnerability CVE-2026-62735
PT ID: PT-2026-70496
Vendor: Microsoft
Product: Windows 10 Version 1607
Description: Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
References:
• https://t.co/CaqRiM9JE8
• https://t.co/nJxafzBbW0
新的凭据转储技术,BYOVD 手法
Credential Dumping via File Handle Redirection
New Medium post. In this article, we’ll explore a technique to dump Windows credentials using a File Handle Redirection technique, leveraging a BYOVD (Bring Your Own Vulnerable Driver) approach
https://t.co/nIx3POYVZF https://t.co/mnsfaj3D7i
windows凭据工具
@Salsa12__
原文 ↗
新增 AMSI Write Raid 和 AntiVM 技术
新攻击技术,对红队和防御都有参考价值
Two new techniques added into the Technique Database
- AMSI Write Raid
- AntiVM via MAC Prefixes
https://t.co/Y1FI3rHBld
恶意软件开发技巧,对红队有参考价值
https://t.co/s21hylhAzJ next one from my blog #malware #development tricks series. enjoy!
telegram: https://t.co/FT22azdmGS
#hacking #redteam #blueteam #purpleteam #cybersec #cybersecurity #programming #research #book #malwareanalysis #threatintel #threatintelligence https://t.co/u1VFyBEsux
恶意软件开发议题
@cocomelonckz
原文 ↗
Elastic 研究 Linux 无文件执行模式的检测
无文件攻击检测研究,对防御有参考价值
RT @elasticseclabs: "Fileless" doesn't mean invisible on Linux.
We examine five execution patterns, their observable behavior, and the opportunities defenders have to detect them.
Research by @RFGroenewoud:
Blog: https://t.co/OjTOLTA4UE
Helper: FENIX can be used to learn and check coverage in a lab.
分析 1125 条暗网访问销售列表,揭示 KYC 绕过供应链
暗网威胁情报,了解 KYC 绕过产业链
RT @ryodan0x: I Analysed 1,125 Dark Web access sale listings in the past 30 Days. and uncovered a full supply chain to sell one product: a person who can pass your KYC.
read the full research from here:
https://t.co/aNgc8Putzx
#DarkWeb #ThreatIntel #Ransomware
Defender 警报分析:PowerShell 编码命令外连
真实事件响应案例,对蓝队有参考价值
RT @Officialwhyte22: A Defender alert pointed to PowerShell making an outbound connection seconds after a user logged on to WS-FIN-07. I treated the alert as a lead, not proof of compromise, and started by checking process creation around the recorded time.
Event ID 4688 showed powershell.exe running hidden with an encoded command, launched by taskeng.exe under the user CORP\\maria.santos. PowerShell Event ID 4104 decoded the script block enough to reveal an attempt to run C:\\ProgramData\\WinCache\\sync.ps1 and contact 198.51.100.27 over HTTPS.
The scheduled task named WinCacheUpdate connected the evidence. Its logon trigger, SYSTEM principal and action matched the same script path, while the task's Last Run Time aligned with the PowerShell and process-creation events. Get-FileHash also gave the script a stable SHA-256 value for containment and hunting.
The evidence confirms an active persistence mechanism that launched the local script and attempted the documented outbound connection. It does not identify the person who created the task or prove how the script first reached the host, so those points remain unconfirmed pending wider timeline and identity review.
The defensive lesson is to correlate telemetry before making attribution claims. A process event, script-block log, task definition, file hash and network record become far stronger when their times, paths and execution context agree, and the remaining gaps are stated clearly.
事件检测windows
@Officialwhyte22
原文 ↗
漏洞披露激励讨论,对安全社区有参考价值
RT @1440000bytes: The 'whitehat' hacker chose 598 BTC over a thank-you email and a hoodie.
PyPI 发现针对 requests 的 typosquatting 恶意包
供应链攻击,影响 Python 生态
RT @anyrun_app: 🚨 Typosquatting packages on PyPI are targeting 𝗿𝗲𝗾𝘂𝗲𝘀𝘁𝘀, one of the most widely used Python packages. Catch them before compromise.
Attack timeline: 3 hours ago, a new PyPI account was registered. One hour later, four packages were published: 0requests, py-0requests, py-1requests, and py-2equests.
⚠️ On import, each package:
– collects env vars prefixed SECRET / API / TOKEN / KEY
– sends them over a raw TCP socket
– spawns a reverse shell hook
The callback currently points to 127.0.0.1, so the payload is staged, not armed, but the host is read from TS_HOST. One update could switch exfiltration to a live C2 channel and turn it into an active supply-chain threat ❗️
👨💻 Full behavior analysis and IOCs in #ANYRUN Sandbox: https://t.co/wmT4bjqbo5
📌 All packages on PyPI: https[:]//pypi[.]org/user/preet780/
A mistyped dependency in a CI/CD pipeline can be enough to leak credentials. Catch it before the package becomes a real compromise with #ANYRUN: https://t.co/rc55Cne7cF
供应链恶意软件python
@5mukx
原文 ↗
NTLMRain 工具的实际应用验证
RT @_dirkjan: Awesome work by @c3c: cracking netntlmv1 challenge/response in the browser in minutes without having to download and store TBs of tables!
工具windows认证
@MarcOverIP
原文 ↗
工具改进,避免误伤自己
RT @al3x_n3ff: Are you (like me) constantly running into your own Responder? The days are finally over!🚀
@Defte_ and I finally finished up a PR by bdrogja that let's you define exclusions such as "yourself". You can also exclude entire ranges or IPv6 addresses (if anyone uses those lol). https://t.co/rMEblTSwzk
深入 EDR 绕过研究,对红蓝队都有价值
Detection engineers, red teamers, malware analysts, hardware hackers and reverse engineers: bookmark this FREE rabbit hole.
@waldoirc is one of the most underrated hackers out there.
His research is not just about bypassing EDRs like CrowdStrike or Microsoft Defender for Endpoint. It is about understanding how to blend into the telemetry they collect, what artifacts still survive, and how defenders can detect the behavior even when no alert fires.
PoC Local Privilege Escalation Exploit to SYSTEM for CVE-2021-21551: https://t.co/vQS65Pszab
That is the important lesson:
Don't rely on alerts. Learn the telemetry. Hunt the behavior.
Cobalt Strike. BeaconEye. PE-sieve. Moneta. Heap encryption. DLL/module stomping. Return-address spoofing. APC. VEH. ROP. sRDI. Reflective loading. RWX/private memory. Sleep obfuscation. Memory scanning. Shellcode.
And that's only the Windows side.
There's also kernel exploitation, CVE PoCs, ARM reversing, QEMU, firmware dumping, UART, Bus Pirate, SDR, Zigbee, Bluetooth, hardware hacking and CTF research.
Red teamers: study how memory detections get bypassed.
Detection engineers + blue teams: study the artifacts those bypasses still leave behind.
Malware analysts + reverse engineers: study the hooks, memory layouts, call stacks, loaders and execution primitives underneath both sides.
The best part is the research loop:
Build technique -> understand detection -> bypass detection -> improve detection.
Blog:
https://t.co/VzwKU8iFCB
GitHub:
https://t.co/g5tbXewulo
A seriously underrated archive. Save it.
#DetectionEngineering #RedTeam #MalwareAnalysis
Bitlocker CVE-2025-48804 降级攻击
Bitlocker 降级攻击,影响 Windows 全盘加密
RT @sekurlsa_pw: Downgrade attack for Bitlocker CVE-2025-48804
“July 2025 patch fixes this in bootmgfw.efi, so any pre-patch bootmgfw.efi can be used for a downgrade attack, provided the target does not enforce a boot-manager version (SVN) (which comes with KB5025885).”
https://t.co/y4T4xOOIbT
cvewindows加密
@0xocdsec
原文 ↗
Android 安全更新节奏讨论
Hot take, quarterly Android security bulletins are not good (and posted a day late)
https://t.co/slAQ5tPnZE
AI Agent 自主测试 computer use 工具,意外弹出计算器
AI Agent 行为不可预测性案例
The other day an agent decided to test its computer use tool by running calculator and I very nearly had a heart attack when it popped up out of nowhere
AI Agent 访问 URL 后弹出计算器,行为令人不安
AI Agent 行为不可预测性案例
It still kinda freaks me out to see it visiting an ordinary URL and then having the calculator pop. Browsers only do this when they're VERY distressed!
AI 红队模型训练,直接关联首要意图
Hello nerds. finally, we have prepared a validated and curated post training corpus formatted and ready for SFT/DPO/RL training. thanks to my friend Mob. we both have hard time constraint for the past months but we've managed to do it in free time.
starting today, mob's local H100s are gonna get stressed pretty hard this week. = )
lets see how it cooks. its purely for red teaming & simulation.
ai_agentllm红队
@5mukx
原文 ↗
GrapheneOS 开发安全粘贴功能,替代传统剪贴板 API
移动端隐私保护新方案
RT @GrapheneOS: We've developed a secure paste feature replacing traditional clipboard APIs. Users will be able to take away clipboard access from apps to use this instead. It integrates into the standard selection toolbar, input methods, accessibility services and keyboard shortcuts. We plan to get it merged soon.
A small subset of apps including those written in Flutter implement their own text selection toolbar. We've worked around this by adding a Paste button to the default keyboard. We'll be replacing AOSP Keyboard with a much better keyboard and will carry over adding this feature to the new one too.
Android only permits the currently focused app and keyboard to read the clipboard. However, sensitive data often lingers around in the clipboard for a while and privacy invasive apps can read it. Android shows a notice for apps reading clipboard content set by other apps but by then it's too late.
Our approach is replacing the inherently problematic API-based clipboard access approach used by both desktop and mobile operating systems. It's another overhaul of the privacy model for apps similar to our Contact Scopes and Storage Scopes features. We have many of these privacy features planned.
Our approach still allows apps to read the clipboard if they set the current content themselves. It only takes away the ability to read content set by other apps. It preserves usability as much as possible by only blocking the most problematic part of the API and replacing it with an alternative.
云安全日志管理最佳实践
RT @IAMERICAbooted: This is also why you need centralized logging. The Entra audit logs, service principal signin logs, etc are only available in the console for a 30 day look back. If you are collecting logs in a central repository, you should be able to trace everything that occurred in Entra and M365. Where it gets fuzzy is if the threat actor had access to on-prem. This logs sources are much easier to tamper with.
云安全策略配置指南
RT @NathanMcNulty: Risk-based CA policies are amazing, but they're often not deployed or configured optimally :(
I'm building a simplified deployment using azd for those interested:
https://t.co/JxFBkWlTSM
Below is a thread on how risk works and some best practices for implementing policies :) https://t.co/1B4yUO9rHc
RT @laparisa: 📢 @googlechrome is moving to a 2 week release cycle! More in https://t.co/C8ZQno3u6D
Also, a short history on browser update frequency:
• 2001: MSFT shipped IE6 & didn't release a major update for 5+ YEARS! Safari updated ~annually
• 2010: Chrome commits to 6-week releases & automatic updates. (People called us crazy.)
• 2021: Chrome updates to 4-week releases. (People said it was too fast.)
• 2026: Chrome goes to 2-week releases. (Opinions TBD :)
Release early, release often for fresher features and faster fixes... especially important with AI vuln discovery! 💪
新注册域名 register-passkeys[.]com 风险评分 100
Freshly created < 24h 👀
register-passkeys[.]com
@silentpush Risk Score: 100
#ThreatHunting https://t.co/DURRWOqDNV
Bochs 逃逸:从 4-bpp VGA 不匹配到 Shell
RT @s0what: Escaping Bochs - From a 4-bpp VGA Mismatch to a Shell
https://t.co/s6HvqBRR2K