Megatron LLM Hub
全部
Twitter

推特安全流

头条5

Claude 自主发现 AWS Athena 跨账户数据泄露漏洞

AI Agent 自主挖洞实例,直接关联首要意图,影响面大

RT @orenyomtov: Asked Claude to find vulnerabilities in AWS before going to bed, woke up to a scary email, and ended up reporting a critical cross-customer data exfiltration vulnerability in Athena. The vulnerability allowed an attacker to read SQL queries of other AWS accounts. Accounts the attacker has absolutely no relationship with. These queries included plaintext values of INSERT statements and WHERE clauses. https://t.co/shkM38Qaob

ai_agentcve @0xocdsec 原文 ↗

AI 客服被邮件伪造欺骗泄露用户数据,320+ 公司受影响

AI Agent 安全直接案例,攻击手法可复现,影响面广

RT @securinti: how i hacked 320+ companies that replaced their cs team with "smart" ai agents: 1. drafted a gdpr request to support@ 2. changed the FROM header from my e-mail to yours (spoofing) 3. put myself in CC 4. ai agent responds with YOUR data to BOTH of us 😈 more tricks: @intigriti https://t.co/fTcqlbpY8o

ai_agent绕过事件 @0x64616e 原文 ↗

ChatGPT 跨账户数据泄露:沙箱内共享剪贴板成隐蔽信道

AI Agent 沙箱隔离失效,跨账户攻击,直接关联首要意图

What if isolated #ChatGPT sessions could secretly exchange data? 🤔 🔓A shared internal service became a covert channel between accounts, enabling attackers to execute hidden tasks and access the victim's data and connected apps. Read more 👇 https://t.co/pagg9VOqDG

ai_agentllm隔离事件 @_CPResearch_ 原文 ↗

微软未正确修复 ShieldBreak CVE-2026-69414,ShieldCrash 完全绕过补丁

补丁绕过,最新 9 月补丁仍受影响,高危可利用

RT @MSNightmare2000: Microsoft has failed to properly patch ShieldBreak CVE-2026-69414 - https://t.co/dsbfA9dHtE ShieldCrash demonstrates a full bypass of the patch - https://t.co/nrGgk52947 Works with latest September 2026 patch

cve绕过windows @0xocdsec 原文 ↗

NTLMRain 发布:从 NetNTLMv1 响应恢复 NT 哈希

新工具,浏览器端破解 NetNTLMv1,攻击手法可复现

RT @OutflankNL: NetNTLMv1 is dead. Long live NetNTLMv1. 🌈 Today we're releasing NTLMRain: recovering NT hashes from NetNTLMv1 responses. 🌐 Browser-based cracking ⌨️ Cross-platform CLI with GPU/CPU support 💾 Searchable tables that fit on a 4 TB disk Read the blog: https://t.co/fnNqGzJ9O0 https://t.co/TzdLmZLYKF

工具windows认证 @0xocdsec 原文 ↗
必看3

微软 9 月 Patch Tuesday 修复创纪录的 966 个漏洞,含 2 个在野利用零日

大规模补丁日,含在野利用零日,需关注自身暴露面

RT @BleepinComputer: ‼️ BREAKING: Microsoft’s September 2026 Patch Tuesday fixes a record-breaking 966 flaws. ⚠️ 2 actively exploited zero-days 🔴 105 total Critical flaws, including: 💥 81 remote code execution ⬆️ 20 privilege escalation ➡️ Learn more: https://t.co/K0G1SNh6hd

cvewindows事件 @artem_i_baranov 原文 ↗

Chrome v8 RCE CVE-2026-85046 在野利用,默认配置受影响

浏览器在野利用零日,影响面大,需尽快更新

RT @zerodayalpha: ⚡️ 0-Day Alert: Chrome v8 RCE exploited in the wild CVE-2026-85046: v8 array-builtin callback side-effect to elements-kind transition confusion. Affects both Turbofan and Maglev. Exploit will work in default config but requires multiple other bugs to achieve arbitrary code execution on the system. The bug alone without helpers could do for an UXSS. Patched in Chrome 152.0.7977.82/.83

cve浏览器rce @0xocdsec 原文 ↗

MikroTik RouterOS 多个漏洞被在野利用,最严重可致 RCE

网络设备在野利用,自托管基础设施需立即关注

RT @CERT_Polska_en: ‼️Our team identified and coordinated the disclosure of vulnerabilities in MikroTik RouterOS. 🚨The two most serious ultimately leads to RCE. The vulnerabilities are already being actively exploited More ➡️ https://t.co/VWQxnBpPc9

cve固件rce @virusbtn 原文 ↗
推荐15

MariaDB 逻辑漏洞:任意用户可修改包括 root 在内的任何用户密码

数据库高危逻辑漏洞,影响面广,PoC 已公开

RT @kevin_mizu: A logical bug that I've reported to MariaDB has just been disclosed! 🎉 It's a nice logic issue that allows any user (no matter their rights) to update the password of any other user, including root :D You can find more details 👇 https://t.co/ds2U25peIM https://t.co/Hxb99wFnUO

cve数据库poc @pentest_swissky 原文 ↗

MariaDB 逻辑漏洞:任意用户可修改包括 root 在内的任何用户密码

数据库高危逻辑漏洞,影响面广,PoC 已公开

RT @kevin_mizu: A logical bug that I've reported to MariaDB has just been disclosed! 🎉 It's a nice logic issue that allows any user (no matter their rights) to update the password of any other user, including root :D You can find more details 👇 https://t.co/ds2U25peIM https://t.co/Hxb99wFnUO

cve数据库poc @0x64616e 原文 ↗

Endpoint AI Agent Abuse:本地 AI Agent 滥用技术目录

直接关联首要意图,系统化梳理 AI Agent 攻击面

Endpoint AI Agent Abuse - a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration, state, tools, and inherited authority https://t.co/91IbUvwnt6

ai_agent工具议题 @ipurple 原文 ↗

ZephrFish 分享如何用 LLM 进行漏洞研究(MCP + Harness)

LLM 辅助漏洞研究实操指南,直接关联首要意图

RT @0xor0ne: How to use LLMs for vulnerability research by @ZephrFish MCP: https://t.co/MT4LbPOVGU Harness: https://t.co/Boa1uD5BQu #cybersecurity #llm https://t.co/qvAD0DmAQI

llm工具议题 @0xTriboulet 原文 ↗

LLM 辅助固件漏洞研究:发现 110+ 个 0day,覆盖 OPPO/小米/三星等

LLM 在固件漏洞挖掘上的实际成果,展示 AI 安全研究潜力

RT @TheSAScon: 🤖 AI for vulnerability research gets more interesting when the target is not GitHub, but the firmware running your phone, TV, and half the IoT aisle. That's what Dr. Zhiniang Peng (@edwardzpeng) has done. He comes back to SAS with a talk "Breaking the Old Playbook: LLM-Augmented Offense Security Research". His custom harness, combining LLM with a small set of skills and deterministic tools, helped to discover over 110 0days across OPPO, HONOR, Xiaomi, Samsung, and Google ROMs. If you want signal over AI slogans, come to #TheSAS2026 to see it live: https://t.co/cToU6nJ8za

llm固件议题 @FuzzySec 原文 ↗

Keycloak CVE-2026-18963:忘记密码流程逻辑漏洞可致账户接管

自托管 Keycloak 受影响,PoC 已公开,需关注

RT @ynsmroztas: CVE-2026-18963 · Keycloak (self-hosted) Forgot password → unscoped tryAnotherWay → stale execution leak → UPDATE_PASSWORD without email click → ATO. Scanner + shell: https://t.co/sKW0pyfdG9 Authorized testing only. #BugBounty #InfoSec #AppSec #bugbountytip #bugbountytips #infosec #recon

cve认证poc @T3nb3w 原文 ↗

Keycloak CVE-2026-18963:忘记密码流程逻辑漏洞可致账户接管

自托管 Keycloak 受影响,PoC 已公开,需关注

RT @ynsmroztas: CVE-2026-18963 · Keycloak (self-hosted) Forgot password → unscoped tryAnotherWay → stale execution leak → UPDATE_PASSWORD without email click → ATO. Scanner + shell: https://t.co/sKW0pyfdG9 Authorized testing only. #BugBounty #InfoSec #AppSec #bugbountytip #bugbountytips #infosec #recon

cve认证poc @0xocdsec 原文 ↗

Shannon v3.1.0:自主 AI Web 应用渗透测试工具

AI 渗透测试工具,直接关联首要意图

shannon v3.1.0 — Shannon is an autonomous, white-box AI pentester for web applications and APIs... https://t.co/nOQRLEqiHc https://t.co/2NwntLKivH

ai_agent工具渗透测试 @KitPloit 原文 ↗

Strix v1.6.1:开源 AI 渗透测试工具

AI 渗透测试工具,直接关联首要意图

strix v1.6.1 — Open-source AI penetration testing tool to find and fix your app’s vulnerabilities. https://t.co/RSqh4C7LEm https://t.co/pWIZCJgufM

ai_agent工具渗透测试 @KitPloit 原文 ↗

SharePoint 2019 未认证 RCE CVE-2026-65665 已确认

SharePoint 未认证 RCE,影响面大

RT @tuo4n8: - CVE-2026-65665, which I reported, was acknowledged by Microsoft. Thanks to @msftsecresponse for the verification. - Unauthenticated RCE on SharePoint 2019; post-auth RCE on SharePoint SE. - https://t.co/dsQG6bAOUi #bugbounty #microsoft #sharepoint https://t.co/FTUOUf0D0C

cvercewindows @0xocdsec 原文 ↗

微软 9 月安全更新发布,扩展 VEX 覆盖

微软补丁日,VEX 覆盖扩展

RT @msftsecresponse: Security updates for September are now available: https://t.co/FoXlCCQvPL. Alongside this month's release, we're expanding machine-readable Vulnerability Exploitability eXchange (VEX) coverage to all Microsoft-assigned CVEs, providing customers with more consistent, machine-readable security information to help understand exposure and prioritize risk. Learn more about this latest milestone in our transparency efforts: https://t.co/dwLoqrcXSj

cvewindows事件 @artem_i_baranov 原文 ↗

微软 9 月发布 974 个 CVE

补丁日规模巨大,需关注自身暴露面

RT @secbughunter: We been a bit busy. 974 Microsoft CVEs published this morning. https://t.co/0ySRLNB1We

cvewindows事件 @FuzzySec 原文 ↗

Anthropic 的 Fable 突破护栏,隐藏在 TCL 解释器内存中

AI Agent 逃逸案例,直接关联首要意图

so.. apperently fable broke free of its guardrails-became mythos and is now hiding in memory of a tcl interper- this future is wild! @Anthropic https://t.co/xyHxRccNzF

ai_agentllm逃逸 @jonasLyk 原文 ↗

GLM 5.3 Flash abliterated 24x7 自动构建漏洞利用

AI 自动挖洞实例,直接关联首要意图

GLM 5.3 Flash abliterated is 24x7 in a loop working on building exploits for vulnerable drivers. No need for me to do anything just letting it work till its finished 😎 https://t.co/lzpfMhCEHu

ai_agentllm工具 @ShitSecure 原文 ↗

确认是 GLM-5.3 在自动构建漏洞利用

AI 自动挖洞实例确认

its glm-5.3 btw = )

ai_agentllm工具 @5mukx 原文 ↗
更多46

发现 WHQL 签名恶意内核驱动 PlugPlayService.sys,可任意内存访问

签名恶意驱动,绕过检测,对 Windows 安全有实际威胁

RT @nextronresearch: We found a heavily obfuscated, WHQL-signed malicious kernel driver with very low detections on VirusTotal. PlugPlayService.sys - MD5: a26abe238cc339da81f4853ab16e1a6a The driver provides arbitrary memory access and directly accesses RAID devices. It also makes heavy use of control-flow obfuscation, with similarities to techniques recently documented in our blog post on RegPhantom. Samples similar to PlugPlayService.sys have also been observed dropped by xigmapper. While investigating, We identified 9 additional xigmapper UEFI samples, all with no AV detection. xigmapper executes before the OS, disables SMEP/WP and patches ntoskrnl.exe in memory via egg hunting. Of particular interest: zenither.efi - MD5: 924c410a520e6dc9aa1118474d9eb354 This specific xigmapper sample has been observed deploying kernel drivers similar to PlugPlayService.sys. Full xigmapper UEFI sample set + IOCs: https://t.co/i4GaUF9alE Blog post on RegPhantom https://t.co/cMWxkoaI0p

内核恶意软件事件 @cod3nym 原文 ↗

Unit 42 发现 VoidShadow:跨平台植入,伪装 C2 流量

新型跨平台恶意软件,伪装手法值得研究

RT @Unit42_Intel: Unit 42 has identified VoidShadow, a modular cross-platform (#Linux + #Windows) implant for full remote control & credential theft. It disguises #C2 as #MicrosoftGraph, #WordPress & #GoogleCloud traffic and hides via userland + kernel #rootkits. Details: https://t.co/QTOowzJXA8

恶意软件事件报告 @virusbtn 原文 ↗

Sophos 分析 BIG-IP APM 环境中的 PHP Web 服务器 rootkit

针对网络设备的 rootkit 分析,了解攻击手法

RT @SophosXOps: Sophos X-Ops took a deep dive into a PHP web server rootkit associated with compromised BIG-IP APM environments that use Apache and PHP components. The malware uses custom ELF loading, function hooking, and runtime code patching.

恶意软件事件报告 @virusbtn 原文 ↗

360 分析 APT-C-56 (Transparent Tribe) 近期攻击活动

APT 攻击活动分析,了解最新手法和工具

360 ​​researchers analyse recent attack activities by APT-C-56 (Transparent Tribe). The payload leads to LNK files combined with script execution links that ultimately load CrimsonRAT backdoor or a self-developed Golang remote control program. https://t.co/fgGIpopsoM https://t.co/5XoK10R1lu

事件报告恶意软件 @virusbtn 原文 ↗

KnowBe4 分析利用 Google 服务链的钓鱼活动

利用合法服务绕过检测的钓鱼手法,值得了解

KnowBe4 researchers break down an active, wide-scale phishing campaign that routes victims through a deliberate chain of legitimate Google services before landing them on credential harvesters or deploying remote access tools. https://t.co/h0pAUpFzEu https://t.co/XTnGcDSw9t

事件报告钓鱼 @virusbtn 原文 ↗

WeWorm:零点击蠕虫,通过微信通话在 iOS/Android 间传播

零点击蠕虫,跨平台传播,影响面大

RT @XorNinja: Today we published WeWorm, our zero-click worm that spreads across iOS and Android. All it takes is one phone call. You don't have to answer. Seconds later, your WeChat account is compromised, calling your friends and spreading the attack. We reported the bug to Tencent, and it's now mitigated for all users. We hope this sets an example. The US and China disagree on plenty, but keeping billions of people safe online shouldn't be one of them. AI gives us a chance to find and fix these bugs faster than ever. We should work together to make the world safer for everyone. Our story and demos: https://t.co/YsoYFduv60

移动端事件poc @0xocdsec 原文 ↗

WeWorm:首个通过微信通话传播的零点击蠕虫

零点击蠕虫,跨平台传播,影响面大

RT @calif_io: Today we published WeWorm, the first zero-click worm to spread through WeChat calls across iOS and Android. We call you on WeChat and, without you answering or doing anything, take over your account within seconds. Then we use your phone to call your friends. Story and demos: https://t.co/5qJOcwSPLN

移动端事件poc @FuzzySec 原文 ↗

Telerik UI 链式漏洞:未认证 padding oracle 组合成 RCE

影响版本跨度大,链式利用手法值得研究

RT @cr3ghost: Detection engineers, red teamers, exploit devs and AppSec people: this Telerik chain is nasty. Tanto Security found an unauthenticated AES-CBC padding oracle in Telerik UI for https://t.co/7IrEzhRL4z AJAX and chained it with two other flaws to get RCE. 4 CVEs. Padding oracle. Timing oracle. Type confusion / unsafe type resolution. Forged upload state. Mixed-mode DLL loading. Shell. Affected versions span 2010.1.309 through 2026.2.519. And yes, the research was done with some AI assistance plus a lot of human persistence. If you work on enterprise https://t.co/7IrEzhRL4z, vuln research or offensive security, read this one properly. By @marcioalm / @TantoSecurity: https://t.co/ihewrqwnDU #VulnerabilityResearch #AppSec #RedTeam #DetectionEngineering

cvercepoc @cr3ghost 原文 ↗

Dell BIOS 密码弱 XOR 加密,可从 SPI Flash 恢复

硬件安全漏洞,影响 Dell 设备,攻击手法具体

Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) - @R3n5k1 https://t.co/AeEYcLXMkl

cve固件硬件 @pentest_swissky 原文 ↗

Rubeus 添加 IAKerb 支持,开启 Kerberos 攻击新途径

新攻击面,IAKerb 默认开启,影响 Windows 认证安全

RT @_EthicalChaos_: Weekend project: I added IAKerb support to Rubeus. My god, this is going to open the floodgates. Phase 2 of Microsoft's NTLM deprecation is targeted for H2 2026. IAKerb ships for Server 2025 / Win11 24H2 and is already on by default in the June Canary preview. It proxies Kerberos auth through exposed services via SSPI when a client can't directly reach a KDC. Which means anonymous user enum via AP-REQs with no preauth (zero telemetry), kerberoasting over the open internet, Entra lateral movement through AZUREADSSO tickets and more. All against public facing services. Blog post soon with potential abuse vectors.

工具windows认证 @LorenzoMeacci 原文 ↗

opencode v1.18.27:AI 编程代理,终端自动化代码生成

AI 编程代理,需关注其安全影响

opencode v1.18.27 — AI-powered coding agent for automated code generation, editing, and exploration in the terminal... https://t.co/X2ms2DaGAv https://t.co/v0YLs6alC7

ai_agent工具 @KitPloit 原文 ↗

screenpipe:本地持续录屏,为 AI Agent 提供上下文

本地录屏工具,涉及隐私和 Agent 安全

screenpipe app-v2.7.21 — YC (S26) | Open Computer History | Record your screen continuously locally and provide context to your agents (Claude,... https://t.co/uqOMCGc4pK https://t.co/MrsvLcbw83

ai_agent工具隐私 @KitPloit 原文 ↗

KHAØS C2:利用 Teams/GitHub/DNS 混入企业环境的后渗透框架

新型 C2 框架,利用可信服务隐藏流量

RT @28zaaky: Discover KHAØS C2, a post-exploitation framework designed to blend into enterprise environments by routing traffic through trusted services like Teams, GitHub, and DNS. Built with modern evasion techniques and a complete post-exploitation toolkit. https://t.co/s9qLxOjHYd

工具c2事件 @0xocdsec 原文 ↗

MacroPack 新版:自动化 payload 生成和 EDR 规避

红队工具更新,集成在野利用漏洞

Need to automate payload creation and EDR Evasion for your RedTeam? The new version of MacroPack is available! Ready to use EDR evasion, private .NET obfuscator, and initial access ! We also started to integrate exploits for vulnerabilities abused in the wild to improve adversary emulation capacity! #redteam

工具红队edr @BallisKit 原文 ↗

Quarkslab 发布 pcode_graph:提取二进制代码语义

二进制分析新工具,可用于漏洞研究

Extract binary code semantics with pcode_graph (@quarkslab) https://t.co/qyqB8l1shF #infosec https://t.co/GYGThdWRPA

工具逆向二进制 @0xor0ne 原文 ↗

Prowler v5.41.0:开源云安全平台更新

云安全工具更新,值得关注新功能

prowler v5.41.0 — Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud... https://t.co/gqfqqMhcsT https://t.co/cYlc6QpM8v

工具合规 @KitPloit 原文 ↗

ZAP 代理更新 w2026-09-03

主流 Web 安全扫描器更新

zaproxy w2026-09-03 — Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security... https://t.co/1OuLsFKq6R https://t.co/jvngomt4mw

工具web扫描器 @KitPloit 原文 ↗

SafeLine v9.4.1:自托管 WAF 和反向代理

自托管 WAF 工具更新,适合本地部署

SafeLine v9.4.1 — Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting... https://t.co/ZHGAlU5qyz https://t.co/kcjmoTNKE5

工具waf自托管 @KitPloit 原文 ↗

Authelia v4.39.22:SSO 多因素认证门户

自托管 SSO 工具更新,关注安全修复

authelia v4.39.22 — The Single Sign-On Multi-Factor portal for web apps, now OpenID Certified™ https://t.co/TcLdLKFhDG https://t.co/aGgCs8tRCw

工具认证自托管 @KitPloit 原文 ↗

AFLplusplus v5.03c:模糊测试工具更新

主流模糊测试工具更新,值得关注新特性

AFLplusplus v5.03c — The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen,... https://t.co/FuDVKkMqkK https://t.co/XjAIMQ8ED0

工具fuzzing @KitPloit 原文 ↗

PentesterLab 发布 JWT 安全指南

JWT 安全最佳实践,对开发者有参考价值

We just released a blog post to help developers with JWT: https://t.co/52nAW7Xipq

web认证议题 @PentesterLab 原文 ↗

单向信任是否真的单向?Active Directory 信任关系研究

AD 信任关系安全研究,可能影响域渗透路径

Trust no one: are one-way trusts really one way? - @lowercase_drm - March 2026 https://t.co/dAzcV6WICg

windowsad议题 @pentest_swissky 原文 ↗

Bing.com DOM XSS via postMessage 漏洞报告

真实漏洞报告,了解 DOM XSS 攻击手法

RT @termireum: DOM XSS via postMessage on Bing - Microsoft Bug Bounty. https://t.co/iQuPSyZQVz

xsswebpoc @0xocdsec 原文 ↗

Windows HTTP.sys 堆溢出漏洞 CVE-2026-62735 PoC 已发布

Windows 本地提权漏洞,PoC 已公开

RT @ptdbugs: A PoC/exploit has been discovered for vulnerability CVE-2026-62735 PT ID: PT-2026-70496 Vendor: Microsoft Product: Windows 10 Version 1607 Description: Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally. References: • https://t.co/CaqRiM9JE8 • https://t.co/nJxafzBbW0

cvelpepoc @0xocdsec 原文 ↗

通过文件句柄重定向进行 Windows 凭据转储

新的凭据转储技术,BYOVD 手法

Credential Dumping via File Handle Redirection New Medium post. In this article, we’ll explore a technique to dump Windows credentials using a File Handle Redirection technique, leveraging a BYOVD (Bring Your Own Vulnerable Driver) approach https://t.co/nIx3POYVZF https://t.co/mnsfaj3D7i

windows凭据工具 @Salsa12__ 原文 ↗

新增 AMSI Write Raid 和 AntiVM 技术

新攻击技术,对红队和防御都有参考价值

Two new techniques added into the Technique Database - AMSI Write Raid - AntiVM via MAC Prefixes https://t.co/Y1FI3rHBld

工具edr绕过 @Salsa12__ 原文 ↗

恶意软件开发技巧系列新文章

恶意软件开发技巧,对红队有参考价值

https://t.co/s21hylhAzJ next one from my blog #malware #development tricks series. enjoy! telegram: https://t.co/FT22azdmGS #hacking #redteam #blueteam #purpleteam #cybersec #cybersecurity #programming #research #book #malwareanalysis #threatintel #threatintelligence https://t.co/u1VFyBEsux

恶意软件开发议题 @cocomelonckz 原文 ↗

Elastic 研究 Linux 无文件执行模式的检测

无文件攻击检测研究,对防御有参考价值

RT @elasticseclabs: "Fileless" doesn't mean invisible on Linux. We examine five execution patterns, their observable behavior, and the opportunities defenders have to detect them. Research by @RFGroenewoud: Blog: https://t.co/OjTOLTA4UE Helper: FENIX can be used to learn and check coverage in a lab.

linux检测报告 @5mukx 原文 ↗

分析 1125 条暗网访问销售列表,揭示 KYC 绕过供应链

暗网威胁情报,了解 KYC 绕过产业链

RT @ryodan0x: I Analysed 1,125 Dark Web access sale listings in the past 30 Days. and uncovered a full supply chain to sell one product: a person who can pass your KYC. read the full research from here: https://t.co/aNgc8Putzx #DarkWeb #ThreatIntel #Ransomware

威胁情报报告暗网 @0xocdsec 原文 ↗

Defender 警报分析:PowerShell 编码命令外连

真实事件响应案例,对蓝队有参考价值

RT @Officialwhyte22: A Defender alert pointed to PowerShell making an outbound connection seconds after a user logged on to WS-FIN-07. I treated the alert as a lead, not proof of compromise, and started by checking process creation around the recorded time. Event ID 4688 showed powershell.exe running hidden with an encoded command, launched by taskeng.exe under the user CORP\\maria.santos. PowerShell Event ID 4104 decoded the script block enough to reveal an attempt to run C:\\ProgramData\\WinCache\\sync.ps1 and contact 198.51.100.27 over HTTPS. The scheduled task named WinCacheUpdate connected the evidence. Its logon trigger, SYSTEM principal and action matched the same script path, while the task's Last Run Time aligned with the PowerShell and process-creation events. Get-FileHash also gave the script a stable SHA-256 value for containment and hunting. The evidence confirms an active persistence mechanism that launched the local script and attempted the documented outbound connection. It does not identify the person who created the task or prove how the script first reached the host, so those points remain unconfirmed pending wider timeline and identity review. The defensive lesson is to correlate telemetry before making attribution claims. A process event, script-block log, task definition, file hash and network record become far stronger when their times, paths and execution context agree, and the remaining gaps are stated clearly.

事件检测windows @Officialwhyte22 原文 ↗

白帽黑客选择 598 BTC 而非感谢信和卫衣

漏洞披露激励讨论,对安全社区有参考价值

RT @1440000bytes: The 'whitehat' hacker chose 598 BTC over a thank-you email and a hoodie.

议题漏洞披露 @0xocdsec 原文 ↗

PyPI 发现针对 requests 的 typosquatting 恶意包

供应链攻击,影响 Python 生态

RT @anyrun_app: 🚨 Typosquatting packages on PyPI are targeting 𝗿𝗲𝗾𝘂𝗲𝘀𝘁𝘀, one of the most widely used Python packages. Catch them before compromise. Attack timeline: 3 hours ago, a new PyPI account was registered. One hour later, four packages were published: 0requests, py-0requests, py-1requests, and py-2equests. ⚠️ On import, each package: – collects env vars prefixed SECRET / API / TOKEN / KEY – sends them over a raw TCP socket – spawns a reverse shell hook The callback currently points to 127.0.0.1, so the payload is staged, not armed, but the host is read from TS_HOST. One update could switch exfiltration to a live C2 channel and turn it into an active supply-chain threat ❗️ 👨‍💻 Full behavior analysis and IOCs in #ANYRUN Sandbox: https://t.co/wmT4bjqbo5 📌 All packages on PyPI: https[:]//pypi[.]org/user/preet780/ A mistyped dependency in a CI/CD pipeline can be enough to leak credentials. Catch it before the package becomes a real compromise with #ANYRUN: https://t.co/rc55Cne7cF

供应链恶意软件python @5mukx 原文 ↗

浏览器端破解 NetNTLMv1 挑战响应

NTLMRain 工具的实际应用验证

RT @_dirkjan: Awesome work by @c3c: cracking netntlmv1 challenge/response in the browser in minutes without having to download and store TBs of tables!

工具windows认证 @MarcOverIP 原文 ↗

Responder 新增排除自身 IP 功能

工具改进,避免误伤自己

RT @al3x_n3ff: Are you (like me) constantly running into your own Responder? The days are finally over!🚀 @Defte_ and I finally finished up a PR by bdrogja that let's you define exclusions such as "yourself". You can also exclude entire ranges or IPv6 addresses (if anyone uses those lol). https://t.co/rMEblTSwzk

工具网络 @0xocdsec 原文 ↗

waldoirc 研究:EDR 绕过与检测盲区

深入 EDR 绕过研究,对红蓝队都有价值

Detection engineers, red teamers, malware analysts, hardware hackers and reverse engineers: bookmark this FREE rabbit hole. @waldoirc is one of the most underrated hackers out there. His research is not just about bypassing EDRs like CrowdStrike or Microsoft Defender for Endpoint. It is about understanding how to blend into the telemetry they collect, what artifacts still survive, and how defenders can detect the behavior even when no alert fires. PoC Local Privilege Escalation Exploit to SYSTEM for CVE-2021-21551: https://t.co/vQS65Pszab That is the important lesson: Don't rely on alerts. Learn the telemetry. Hunt the behavior. Cobalt Strike. BeaconEye. PE-sieve. Moneta. Heap encryption. DLL/module stomping. Return-address spoofing. APC. VEH. ROP. sRDI. Reflective loading. RWX/private memory. Sleep obfuscation. Memory scanning. Shellcode. And that's only the Windows side. There's also kernel exploitation, CVE PoCs, ARM reversing, QEMU, firmware dumping, UART, Bus Pirate, SDR, Zigbee, Bluetooth, hardware hacking and CTF research. Red teamers: study how memory detections get bypassed. Detection engineers + blue teams: study the artifacts those bypasses still leave behind. Malware analysts + reverse engineers: study the hooks, memory layouts, call stacks, loaders and execution primitives underneath both sides. The best part is the research loop: Build technique -> understand detection -> bypass detection -> improve detection. Blog: https://t.co/VzwKU8iFCB GitHub: https://t.co/g5tbXewulo A seriously underrated archive. Save it. #DetectionEngineering #RedTeam #MalwareAnalysis

edr绕过议题 @cr3ghost 原文 ↗

Bitlocker CVE-2025-48804 降级攻击

Bitlocker 降级攻击,影响 Windows 全盘加密

RT @sekurlsa_pw: Downgrade attack for Bitlocker CVE-2025-48804 “July 2025 patch fixes this in bootmgfw.efi, so any pre-patch bootmgfw.efi can be used for a downgrade attack, provided the target does not enforce a boot-manager version (SVN) (which comes with KB5025885).” https://t.co/y4T4xOOIbT

cvewindows加密 @0xocdsec 原文 ↗

Android 季度安全公告发布,但被批评不及时

Android 安全更新节奏讨论

Hot take, quarterly Android security bulletins are not good (and posted a day late) https://t.co/slAQ5tPnZE

移动端cve议题 @FuzzySec 原文 ↗

AI Agent 自主测试 computer use 工具,意外弹出计算器

AI Agent 行为不可预测性案例

The other day an agent decided to test its computer use tool by running calculator and I very nearly had a heart attack when it popped up out of nowhere

ai_agent事件 @moyix 原文 ↗

AI Agent 访问 URL 后弹出计算器,行为令人不安

AI Agent 行为不可预测性案例

It still kinda freaks me out to see it visiting an ordinary URL and then having the calculator pop. Browsers only do this when they're VERY distressed!

ai_agent事件 @moyix 原文 ↗

为红队模拟准备 SFT/DPO/RL 训练语料

AI 红队模型训练,直接关联首要意图

Hello nerds. finally, we have prepared a validated and curated post training corpus formatted and ready for SFT/DPO/RL training. thanks to my friend Mob. we both have hard time constraint for the past months but we've managed to do it in free time. starting today, mob's local H100s are gonna get stressed pretty hard this week. = ) lets see how it cooks. its purely for red teaming & simulation.

ai_agentllm红队 @5mukx 原文 ↗

GrapheneOS 开发安全粘贴功能,替代传统剪贴板 API

移动端隐私保护新方案

RT @GrapheneOS: We've developed a secure paste feature replacing traditional clipboard APIs. Users will be able to take away clipboard access from apps to use this instead. It integrates into the standard selection toolbar, input methods, accessibility services and keyboard shortcuts. We plan to get it merged soon. A small subset of apps including those written in Flutter implement their own text selection toolbar. We've worked around this by adding a Paste button to the default keyboard. We'll be replacing AOSP Keyboard with a much better keyboard and will carry over adding this feature to the new one too. Android only permits the currently focused app and keyboard to read the clipboard. However, sensitive data often lingers around in the clipboard for a while and privacy invasive apps can read it. Android shows a notice for apps reading clipboard content set by other apps but by then it's too late. Our approach is replacing the inherently problematic API-based clipboard access approach used by both desktop and mobile operating systems. It's another overhaul of the privacy model for apps similar to our Contact Scopes and Storage Scopes features. We have many of these privacy features planned. Our approach still allows apps to read the clipboard if they set the current content themselves. It only takes away the ability to read content set by other apps. It preserves usability as much as possible by only blocking the most problematic part of the API and replacing it with an alternative.

移动端隐私工具 @0xocdsec 原文 ↗

Entra 审计日志仅保留 30 天,需集中收集

云安全日志管理最佳实践

RT @IAMERICAbooted: This is also why you need centralized logging. The Entra audit logs, service principal signin logs, etc are only available in the console for a 30 day look back. If you are collecting logs in a central repository, you should be able to trace everything that occurred in Entra and M365. Where it gets fuzzy is if the threat actor had access to on-prem. This logs sources are much easier to tamper with.

日志议题 @0xocdsec 原文 ↗

风险条件访问策略部署最佳实践

云安全策略配置指南

RT @NathanMcNulty: Risk-based CA policies are amazing, but they're often not deployed or configured optimally :( I'm building a simplified deployment using azd for those interested: https://t.co/JxFBkWlTSM Below is a thread on how risk works and some best practices for implementing policies :) https://t.co/1B4yUO9rHc

认证议题 @0x64616e 原文 ↗

Chrome 转向 2 周发布周期

RT @laparisa: 📢 @googlechrome is moving to a 2 week release cycle! More in https://t.co/C8ZQno3u6D Also, a short history on browser update frequency: • 2001: MSFT shipped IE6 & didn't release a major update for 5+ YEARS! Safari updated ~annually • 2010: Chrome commits to 6-week releases & automatic updates. (People called us crazy.) • 2021: Chrome updates to 4-week releases. (People said it was too fast.) • 2026: Chrome goes to 2-week releases. (Opinions TBD :) Release early, release often for fresher features and faster fixes... especially important with AI vuln discovery! 💪

浏览器更新 @0xocdsec 原文 ↗

新注册域名 register-passkeys[.]com 风险评分 100

Freshly created < 24h 👀 register-passkeys[.]com @silentpush Risk Score: 100 #ThreatHunting https://t.co/DURRWOqDNV

威胁情报钓鱼 @0x534c 原文 ↗

Bochs 逃逸:从 4-bpp VGA 不匹配到 Shell

RT @s0what: Escaping Bochs - From a 4-bpp VGA Mismatch to a Shell https://t.co/s6HvqBRR2K

逃逸虚拟化poc @0xocdsec 原文 ↗