更多165
CVE-2026-19174:V8 WebAssembly 整数溢出漏洞利用分析
浏览器引擎漏洞利用细节公开,含完整分析,浏览器与 Node 场景均相关。
RT @0xor0ne: Exploiting CVE-2026-19174: integer overflow in V8 WebAssembly
https://t.co/RqGWrR0lT9
Credits @0x10n
#infosec https://t.co/jBwKJThIAm
浏览器cvepoc报告
@0xocdsec
原文 ↗
Logi Options+ 被利用获取 SYSTEM shell 的漏洞利用博文
常见外设驱动软件本地提权到 SYSTEM,含完整利用步骤,终端加固可参考。
RT @xixasec: I wrote a blog post about exploiting Logi Options+ for SYSTEM shells.
https://t.co/CDSkfsmNmw
Windows AppResolver LPE:从 AppContainer 逃逸到 SYSTEM,PoC 关联 CVE-2026-50454
沙箱逃逸加提权链,PoC 已公开,Windows 隔离方案需评估该路径。
RT @_r_netsec: Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454 https://t.co/QzBH8FJjId
lpe逃逸cvepoc
@0xocdsec
原文 ↗
HBO Max Reddit 账号被劫持,用 ClickFix 广告推送恶意软件
劫持高信誉官方账号分发 ClickFix 恶意指令,社交工程手法值得防御方关注。
RT @BleepinComputer: Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
https://t.co/f0BNqkR6mu
https://t.co/f0BNqkR6mu
钓鱼事件恶意软件
@artem_i_baranov
原文 ↗
KnowBe4 分析攻击者滥用 Exchange Direct Send 绕过安全网关发信
利用内置打印机/扫描仪发信路径绕过邮件网关,企业邮件安全配置需核查。
KnowBe4 Threat Lab explains how attackers started to abuse Direct Send, a built-in path designed to allow office printers, scanners and legacy on-premises applications to send email without needing a dedicated account and bypassing security gateways. https://t.co/AmscVfVVP8 https://t.co/7cy961sPmC
Revolut 攻击者声称同时入侵多个意大利执法部门系统,窃取 147GB 数据
攻击者利用执法系统向金融机构发数据请求,暴露合法通道被滥用的风险。
RT @IntCyberDigest: ‼️ BREAKING: We're in contact with the Revolut hacker. According to them, they didn't only take Revolut data, they've also compromised multiple Italian law enforcement departments.
They say the operation targeting Revolut ran for six months, and that they used Italian law enforcement systems to send data requests to Revolut.
They claim to hold 147 GB taken from the Italian side, including internal docs, calendars and personal material, among it the chat logs of a federal officer arguing with his wife.
BlueMoon 漏洞利用套件首个使用集群指向中国关联的 TA412/APT31
新漏洞套件与已知 APT 的关联情报,威胁狩猎可据此调整检测重点。
RT @tdatwja: The first observed cluster using the BlueMoon exploit kit was the China-aligned threat actor TA412 (JungleBamboo, Violet Typhoon, APT31, TIDE CASTLE) on 28 August 2026.
SEPTEMBER 09, 2026
https://t.co/o2FcYSCFOu
Anthropic 称瓦解中国大规模监控系统 BABEL,研究者提前数周已追踪到
单人借助 AI 即可搭建 OSINT 监控平台,展示 AI 降低监控系统构建门槛。
Anthropic claims to have disrupted an online mass surveillance system from China, gathering global intel on religious groups that Beijing deems 'suspicious'. Incidentally we tracked it together with @nestedintel weeks earlier. Meet BABEL - Here is the playbook. 1/8 https://t.co/ITkzzMFu4e
ai_agentosint报告
@NetAskari
原文 ↗
ASC 快速 Android 反编译器发布,agent 用它发现 Honor 和小米各两个 RCE
支持并行分析 10+ APK 的 agent 友好反编译工具,移动端漏洞挖掘效率提升。
RT @MGAldys4: Guys, I built a super fast Android decompiler called ASC.
It completely replaced Jadx MCP for me and lets me analyze 10+ APKs in parallel.
And this week my Agent use ASC found 2 RCE in Honor and Xiaomi!
This tool now accepted by BlackHat EU Arsenal
https://t.co/5Qdpq8XEal
#BHEU https://t.co/lCMDbjZL0h
精心构造的 LDAP 战术用于规避 AD 检测雷达
AD 环境 LDAP 查询规避检测的具体手法,蓝队可据此补充日志与告警。
RT @SEKTOR7net: Carefully crafted LDAP tactics to stay under the AD detection radar.
A post by Baptiste Crépin.
Source: https://t.co/ORGbGNLUrC
#redteam #blueteam #offcoding
macOS RC 说明称 launchd 不再支持加载带隔离属性的 plist,措辞含糊
启动项加载策略变更可能影响持久化检测与恶意 plist 行为,需实测确认语义。
macOS RC release notes:
"Resolved Issues:
Fixed: launchd no longer supports loading launchd property list files with the quarantine extended attribute. (166415497)"
So if a plist has the qattr, does this mean:
a) launchd *will* load it?
b) launchd will *not* load it?
🤔🤨 https://t.co/xoFtVk9Oof
移动端绕过检测
@patrickwardle
原文 ↗
RT @MSNightmare2000: Story time...
评论称微软重复对待 SandboxEscaper 的方式对待漏洞研究者
RT @LinuxKodachi: Naceri is very talented when it comes to windows stuff. And it is sad to see Microsoft doing this thing again after doing same thing with SandboxEscaper.
These people dedicated years of their life on your products and they are top class at their craft,
1/2
RT @MSNightmare2000: That protest, costed me over +200,000$ that i could have had sitting in my bank right now but i burned it. Just to protest against Microsoft's absurd decision.
If only I didn't pour my soul into that job with countless of stupid non sleep nights, i would have gotten over it...
评论指 Hugging Face CTO 谈 AI 前沿节奏
RT @Hesamation: Hugging Face CTO btw… the company that literally had the biggest rogue AI incident so far… the same incident which is now being used to pace the frontier: https://t.co/WKAiJl6I9t
RT @HackingLZ: The magic sauce for LLM driven offense is going to be automatically mirroring a target environment using everything you can quietly learn about it, while other groups of agents are always working on RE and understanding every defensive product they can get their hands on(Thanks, VirusTotal, GitHub, trial versions, leaked configs, update packages, etc)
The closer you can get to the target’s patch levels, configurations, identity setup, and defensive stack, the less noisy brute forcing the attacking agents need to do in the actual environment.
Something today’s agents don’t really capture(obviously you can give them memory) is the feedback loop good red teams build from working across different companies. Every environment is a little different, and knowing something failed doesn’t tell you why. Was it detected? Was your code just bad? Was a flag or ticket option wrong? Did the target have some custom configuration you hadn’t seen before?
Over time those answers turn into private knowledge, custom tooling, and better attack flows. Sometimes you had to get caught to learn the lesson, but every operation after that gets better.
Combine automatic environment mirroring, continuous RE, operational feedback, and private human research, and the agents become significantly more effective over time. The real advantage isn’t just agents attacking faster. It’s moving most of the enumeration, testing, failures, and detection tuning somewhere the defender can’t see it.
ai_agentllm
@0xocdsec
原文 ↗
RT @_r_netsec: Crawling the Complete IPv4 Reverse DNS Space https://t.co/EcIFIorqTT
介绍 Ghidra 逆向工具及 GhidraMCP 生态
RT @Ryrenz: 🔍 逆向神器 Ghidra,拿到一个没有源码的程序,它能直接反汇编、反编译,把机器码还原成人能读懂的代码。
美国国家安全局(NSA)研究局创建并维护,GitHub 近 7.5 万 star,直接封神了。
以前碰到一个可疑的程序,想搞清楚它到底在干嘛,只能对着一屏汇编硬啃。换成 Ghidra,丢进去就能看反编译结果和图形化展示,重复的分析步骤还能用 Java 或 Python 写成脚本自动跑。NSA 自己就拿它分析恶意代码、找网络和系统里的潜在漏洞。
社区也在围着它长东西:GhidraMCP 这个 MCP server 有 1 万 star,另一个 ghidra-mcp 也有 3700 多 star,都是让 AI 直接接进 Ghidra 帮你做逆向。八千多个 fork、快两千个 issue 和 PR 还开着,8 月刚发了 12.1.3。
官方 README 自己也写了部分版本存在已知安全漏洞,装之前看一眼版本号。
国家队的逆向工具,现在谁都能直接拿来用。
GitHub:https://t.co/SW7BjVUuPC
警示 WhatsApp 上伪造 PDF 文件的钓鱼手法
RT @CyberRacheal: Be warned. Hackers can use fake pdf files to hack you through WhatsApp.
(For educational purposes)!
Phishing pro 😅. https://t.co/9xzDn9RiGH
RT @NathanMcNulty: Can someone explain to me how users will ignore all communications from IT but be like "yeah sure attacker, let me figure out how to register a passkey for you"?
Moonshot 创始人杨植麟 39 分钟访谈推荐
RT @kirillk_web3: instead of watching 2 hours of Netflix tonight, watch this 39-minute interview with the founder of a $50B China AI company.
Yang Zhilin runs Moonshot, the lab behind Kimi.
He turned down staying in the US, went back to China, and just raised at a $50 billion valuation.
what makes it worth your time:
> his whole frame is a 10 to 20 year marathon, not the sprint everyone else is running
> the one bet under everything he builds: scaling law is to AI what Moore's Law was to computers
> why he cut everything except productivity, because if you try to do everything, you do nothing well
> how long-context use cases he never saw coming on day one became the real product
it's the clearest thinking on how to actually build an AI company at scale I've heard. no hype, just first principles.
I turned the key ideas into a practical guide, Kimi K3: From Loops to Graphs, How I Cut AI Agent Costs by 70%. below ↓
RT @DiscoStarslayer: After 4 years of effort, I'm happy to announce that one of the final secrets of the PS2 has been broken wide open!
It's been a long process of decapping, optical dumping, and now at last a software solution.
Thank you Libby for finding the exploit from our dirty optical dumps! https://t.co/VrsCH8I35C
PCAPdroid v2.0.1 免 root Android 抓包与防火墙工具
PCAPdroid v2.0.1 — No-root network monitor, firewall and PCAP dumper for Android https://t.co/LPMWV8tmm8 https://t.co/s5ZDLzhHjU
kyverno v1.19.1-rc.1 K8s 策略与合规引擎更新
kyverno v1.19.1-rc.1 — Enforce security and compliance on Kubernetes clusters via admission controls, resource mutation, background scans, and container... https://t.co/jIwp5ytGVV https://t.co/OtRMWzxMsV
authentik 2026.8.2 开源 SSO/身份提供方发布
authentik version/2026.8.2 — Provides open-source SSO and identity provider functionality with SAML, OAuth2/OIDC, LDAP, and RADIUS support for... https://t.co/RFl4F16HCp https://t.co/0d5gT7ni51
tmux v3.8-rc — Terminal multiplexer for managing multiple shell sessions from a single screen, with session persistence, window splitting, and scriptable... https://t.co/zUM3bCgeba https://t.co/EPZq5rSdyN
openssl openssl-4.1.0-alpha1 — General purpose TLS and crypto library https://t.co/tnkuxy3Lxe https://t.co/691IppZwUM
serverless sf-core 4.42.0 CLI 更新
serverless [email protected] — CLI framework for deploying and managing serverless applications on AWS Lambda with YAML infrastructure, local... https://t.co/M7lZapgZiQ https://t.co/UnNVGkn5SF
Guided Hacking 反作弊与内核课程大纲
📜Guided Hacking Course Syllabus 📜
290+ chapters
GHB4 — Anti-Cheat, Anti-Debug & Kernel
1. Defeating Value Encryption & Obfuscation
2. Finding Offsets Without Cheat Engine
3. Bypassing Cheat Engine Detection
4. Kernel-Mode Cheat Engine (DBKM Driver)
5. Code Mutation & Polymorphism
6. Alternative Memory Editors
7. Automated Anti-Debug Bypass (ScyllaHide)
8. Anti-Debug Techniques Overview
9. Anti-Debug Practice Challenges (DebugMe)
10. Steam Anti-Debug Bypass (ThreadHideFromDebugger)
11. NtSetInformationThread-Based Debugger Hiding
12. Timing-Based Debugger Detection
13. Exception-Based Anti-Debug (SEH + Trap Flag)
14. Flag-Based Debugger Detection
15. Breakpoint Detection Methods
16. Heap-Based Debugger Fingerprinting (LFH)
17. Self-Debugging as Protection
18. Real-World Anti-Debug Bypass (CS2D)
19. PE Header Erasure for Stealth
20. PEB Module Unlinking
21. Steam Loader Extended Bypass
22. Anticheat Bypass Methodology
23. Valve Anti-Cheat (VAC) Deep Dive
24. Easy Anti-Cheat (EAC) Architecture
25. EQU8 Anticheat Analysis
26. MTA:SA Kernel Anticheat (Fairplaykd.sys)
27. Memory Integrity Checking (Detecting ScyllaHide)
28. Thread-Based Manual Map Detection
29. Finding Hidden System Threads
30. Code Mutation for Evasion
31. Screenshot Detection Bypass (BitBlt Hook)
32. Return Address Spoofing
33. Virtual Machine Detection Evasion
34. Building a Stealth Kernel Driver
35. Kernel Driver Development for Game Hacking
36. Kernel Debugging with WinDbg
37. Handle Protection Callback Bypass
38. Vulnerable Driver Exploitation (BYOVD)
39. Kernel Manual Mapping (KDMapper)
40. Dumping Protected Anticheat Drivers
41. Covert User-Kernel Communication (.DATA Hooking)
42. IOCTL Interception & Driver Spoofing
43. Erasing Driver Load Evidence (PiDDBCache)
44. Kernel Module Memory Dumping
45. Approaching Newly Protected Games
46. Hypervisor-Based Game Hacking
47. Hyper-V Memory Access (libvoyager)
48. Advanced Code Obfuscation Toolchain (Theodosius)
49. MSR-Based Kernel Code Execution
Squally Game Hacking Course — CS420
1. Course Introduction & What Is Game Hacking
2. Memory Editing Fundamentals
3. Number Systems: Hexadecimal, Decimal & Binary
4. Hex Editing Game Files
5. Data Types & Advanced Memory Editing
6. Virtual Memory & Process Address Spaces
7. Multi-Level Pointers & Pointer Chains
8. x86 Assembly Modification in Games
Game Hacking Shenanigans Tutorial Series
1. Cheat Engine Overview & Series Introduction
2. Installing & Configuring Cheat Engine
3. Value Scanning & Live Memory Editing
4. Data Types & the Memory Viewer
5. Unknown Value Scanning & Elusive Values
6. Pointer Scanning for Stable Addresses
7. Building & Saving Cheat Tables
8. Finding X/Y/Z Coordinates in Memory
9. Finding Velocity Addresses
10. Writing Cheat Engine Auto Assembler Scripts
11. Code Injection via Cheat Engine
12. Shared OpCodes & Filtering Instructions
13. Floating Point Values & XMM Registers
14. One Hit Kills & God Mode Scripts
15. Damage Multiplier Scripts
16. Float Instruction Damage Multipliers
17. Integer-Based Defense Boost Scripts
18. Complex Multi-Feature Cheat Engine Scripts
19. Updating & Fixing Broken Cheat Tables
20. Movement Speed Hack Scripts
The Game Hacking Bible GHB1 — Beginner Foundations
1. Problem-Solving Methodology & Goal Setting
2. Why Fundamentals Matter Over Copy-Pasting
3. Acquiring Hacking Tools Safely
4. CS420 Video Course Companion
5. Game Hacking FAQ & Common Misconceptions
6. Cheat Engine Interface Walkthrough
7. First Hack: Scanning & Modifying Values
8. Finding Position Coordinates in Memory
9. Finding View Angles (Pitch/Yaw)
10. Pointer Scanning with Pointermaps
11. Game Hacking Shenanigans Companion
12. Class Reconstruction with ReClass (Part 1)
13. C++ Programming Primer for Hackers
14. Windows API Essentials
15. String Encodings: Unicode, TCHAR & MBCS
16. Retrieving Module Base Addresses
17. Multi-Level Pointer Resolution in C++
18. Visual Studio Configuration for Hacking
19. Building an External Trainer (Part 1)
20. Building an External Trainer (Part 2)
21. Building an Internal DLL Trainer
22. Writing a DLL Injector
23. Debugging Injected Code with Visual Studio
24. Advanced Class Reconstruction with ReClass (Part 2)
25. External Function Detouring & Hooking
26. Deep Dive into Multi-Level Pointers
27. Entity List Discovery via Reverse Engineering
GHB2 — Reverse Engineering Foundations
1. CPU Registers, Assembly Language, Calling Conventions & the Stack
2. Manual Relative Address Resolution
3. Static Analysis with IDA Pro
4. Reversing Game SDK NetVar Offsets
5. Finding Specific Game Offsets (bDormant)
6. Runtime Type Information (RTTI) & ClassInformer
7. Reversing Recoil Mechanics
8. Reversing Movement: Fly Hack / NoClip
9. Reversing Damage Logic: One Hit Kills
10. Finding Core Game Data Structures (Entity List)
11. Ray Casting & Visibility Checks via Inline ASM
GHB3 — Intermediate Cheat Development
1. External Bunnyhop Automation
2. Internal Bunnyhop Automation
3. Game Flags for Movement Hacks (dwForceJump, m_fFlags)
4. 2D Radar Hack via bSpotted
5. Anti-Flash Effect Neutralization
6. Triggerbot Development (3 Parts)
7. Glow/Wallhack via Glow Object Manager
8. Recoil Control System (RCS)
9. Entity List Reverse Engineering Walkthrough
10. Aimbot Math: Angle Calculation & Smoothing
11. Signature / Pattern Scanning
12. x86 Trampoline Hooking
13. Member Function Hooking (__thiscall)
14. Calling Game Member Functions
15. OpenGL Render Hooking & Overlays
16. OpenGL ESP Drawing
17. General-Purpose Aimbot Architecture
18. Game Interface Access (CreateInterface)
19. Runtime Netvar Enumeration
20. View/Projection Matrix Discovery
21. CSGO ViewMatrix Offset Hunting
22. Direct3D9 EndScene Hooking & D3D9 ESP
23. TraceRay / Visibility Check Calls
24. Single-Player Game Hacking (Skyrim)
25. x86 vs x64 Architecture Differences
26. PE File Format & the Windows Loader
27. Undocumented Windows NTAPI
28. Thread Local Storage (TLS) Internals
29. Walking Loaded Modules via PEB
30. Shellcode Writing & Injection
31. Manual Mapping DLL Injection
32. Usermode API Hooking for Stealth
Anti-Cheat Development Course ⚠️ UNRELEASED
1. Course Introduction & Anticheat Philosophy
2. C++ Project Setup & Architecture
3. Base Detection Class Design
4. Modular Detection System Architecture
User-Mode Detection Modules (12)
5. Running Process & Application Scanning
6. Overlay Window & NVIDIA Hijacking Detection
7. Code Patching & CRC Integrity Detection
8. Import Address Table Hook Detection
9. Export Address Table Hook Detection
10. Debug Register & Hardware Breakpoint Detection
11. Page Guard Memory Protection Detection
12. DLL Load Monitoring & Injection Detection
13. Manual-Map PE Signature Scanning
14. Shellcode & Unbacked Thread Detection
15. Thread Stack Execution Validation
16. Process Handle Permission Auditing
Kernel-Mode Transition
17. Kernel Anticheat Architecture & Driver Design
Kernel-Mode Detection Modules (12)
18. Vulnerable & Blacklisted Driver Detection
19. Object Callback Handle Access Filtering
20. Kernel Driver Code Integrity Checking
21. User Thread Start Address Validation (Kernel)
22. Kernel Thread Stack Walking
23. Kernel Callback List Integrity Checking
24. IOCTL Dispatch Function Validation
25. Manually Mapped Kernel Driver Scanning
26. Kernel Stack Unbacked Memory Detection
27. Windows Test-Signing Mode Detection
28. HVCI Status & Code Integrity Detection
29. CPU Vendor Identification & Validation
Capstone
30. Secure Application Bootstrapper & Driver Loader
Devirtualization Course ⚠️ UNRELEASED
Module 1 — Deobfuscation & Compiler Theory
1. Introduction to Code Deobfuscation
2. Intermediate Representation Theory
3. Lifting x86 to IR
4. Control Flow Graph Analysis (Part 1)
5. Control Flow Graph Analysis (Part 2)
6. Dead Code Elimination (Part 1)
7. Dead Code Elimination (Part 2)
8. Constant Propagation & Constant Folding
9. Alias Analysis (Part 1)
10. Alias Analysis (Part 2)
11. Memory Dependence Analysis
12. Dead Store Elimination
13. Advanced Compiler Optimizations
Module 2 — Applied Deobfuscation
1. Packing, Code Mutation & Virtualization Overview
2. Applied Deobfuscation Practice (Part 1)
3. Applied Deobfuscation Practice (Part 2)
4. Applied Deobfuscation Practice (Part 3)
5. Unpacking Virtual Machines
6. VM Architecture Fundamentals
Module 3 — Devirtualization
1. Introduction to Devirtualization
2. VM Handler Analysis (Part 1)
3. VM Handler Analysis (Part 2)
4. VM Handler Analysis (Part 3)
5. VM Lifting Approach
6. Native Optimization Approach
7. Hybrid Devirtualization Approach
8. Building a Devirtualizer (Part 1)
9. Building a Devirtualizer (Part 2)
10. Building a Devirtualizer (Part 3)
Binary Exploit Development Course
1. Simple Stack Buffer Overflow (VulnServer)
2. SEH-Based Buffer Overflow
3. Multi-Stage Exploit (Stager)
4. Socket Reconstruction in Exploits
5. Data Execution Prevention (DEP) Bypass
6. DEP Bypass via WriteProcessMemory
7. Return-Oriented Programming (ROP Decoder)
8. Exploit Scripting with Pwntools
9. Address Space Layout Randomization (ASLR) Theory
10. Practical ASLR Bypass
11. Linux Binary Exploitation Fundamentals
12. Partial Return Address Overwrites
13. Egg Hunter Shellcode Techniques
14. Use-After-Free Vulnerability Exploitation
15. TryHackMe Exploit Development Walkthrough
16. Fuzzing a Linux Library
17. Coverage-Guided Fuzzing with AFL
18. Fuzzing Environment Setup
Python Game Hacking Course — PGH100
1. Python Game Hacking Overview
2. Python Hacking Environment Setup
3. Python Libraries for Memory Manipulation
4. Building an External Python Hack
5. Python DLL Injection
6. Building an Internal Python Hack
7. Python Aimbot Development
8. Python Overlay & ESP Drawing
9. Building a Python Memory Scanner
10. Python Game Hacking Resource Guide
Python Reverse Engineering Course — PRE100
1. Python Source Code Reverse Engineering
2. Python Code Injection Techniques
3. Python Runtime Internals Reversing
4. Reversing Compiled Python Executables
5. Hacking Python-Based Games
Java Reverse Engineering Course — JRE100
1. Java Reverse Engineering Overview
2. Java Language Crash Course
3. Java Static Analysis & Decompilation
4. Java Dynamic Analysis & Runtime Inspection
5. JVM Hooking & Bytecode Patching
Java Game Hacking Course — JGH100
1. Java Game Hacking Overview
2. Java Fundamentals for Game Hacking
3. Java Native Access (JNA) for Memory
4. Building a Java External Hack
5. Java Swing GUI with Global Hotkeys
6. Java Aimbot Development
7. Java ESP Overlay Rendering
8. Java GUI Overlay Framework
9. Java Memory Hacking Library
Roblox Exploit Scripting Course — RES100
1. Roblox Exploit Scripting Overview
2. Lua & Luau Scripting Fundamentals
3. Script Executors & How They Work
4. Roblox Game Engine Internals
5. Roblox Reversing & Exploit Scripting
6. Building Roblox Mod Menu GUIs
7. Complete Roblox Hack Walkthrough
Web Browser Game Hacking Course — WBGH100
1. Web Browser Game Hacking Crash Course
2. Introduction to Browser Game Vulnerabilities
3. JavaScript Game Memory Manipulation
4. Script Replacement & Injection in Browser Games
5. Browser Automation with Tampermonkey
6. JavaScript Function Hooking
7. Complete Browser Game Hack (ShellShockers)
8. WebSocket Interception & WebAssembly Hacking
9. JavaScript Aimbot for HTML5 Games
通过 hook BaseThreadInitThunk 检测注入线程
🕵️ Detecting Injected Threads
Hook BaseThreadInitThunk to detect suspicious thread creation.
👉 https://t.co/3yK8DKczlr https://t.co/YFrPz5wBLe
讨论 MITRE ATT&CK T1059.007 JavaScript 执行覆盖
The last few days, I’ve been digging into MITRE ATT&CK sub‑technique T1059.007. Mapping all procedures tied to this sub‑technique is challenging due to the volume of third‑party applications that support JavaScript.
I’m currently documenting every code execution method, but I’m curious whether anyone has ever achieved full coverage for this sub‑technique?
The technique abstract outlines the data sources necessary for detecting the technique. https://t.co/QxA7NO1rcJ
OffByOne 会议 i0n1c 讲 XNU/TXM 漏洞挖掘
RT @offbyoneconf: 🔥THAT’S A WRAP ON DAY 1!
#OB12026 went out with a bang as @i0n1c took the stage with “Beyond XNU: Agentic Hunting for Vulnerabilities in TXM.” No introduction needed. No slowing down. Just one final deep dive that kept everyone locked in till the very end.
🔥CU tmrw #OB12026! https://t.co/hQnpjAas4x
OffByOne 议题:串联逻辑漏洞实现可靠 Windows LPE
RT @offbyoneconf: 🔥 EXCEPTIONAL! We raised the bar, @crispr_x & @heegong123 absolutely delivered with “𝐂𝐡𝐚𝐢𝐧𝐢𝐧𝐠 𝐋𝐨𝐠𝐢𝐜𝐚𝐥 𝐁𝐮𝐠𝐬 𝐟𝐨𝐫 𝐑𝐞𝐥𝐢𝐚𝐛𝐥𝐞 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 𝐋𝐏𝐄” at #OB12026! If you were in the room, you know. 👀🔥 https://t.co/7O4yeGto3p
OffByOne 主题演讲:用 LLM 做一年漏洞挖掘
RT @edwardzpeng: Sharing my for keynote talk for Offbyone security conference #OB12026 : <A year of hacking with LLMs>
https://t.co/W7NFSnAvij
OffZone Moscow 2026 视频上传,含 HarmonyOS Next 安全研究
Russians uploaded 2026 @offzone_moscow videos over the weekend. Some good talks likely.
https://t.co/5Psm3LL72U
04 Igor Krivonos – HarmonyOS Next Mobile Security and Research Methods https://t.co/jGhjH2XSN4
Charming Kitten APT 对手模拟文章
RT @S3N4T0R_0X0: Read “Charming Kitten APT Adversary Simulation“ by on Medium: https://t.co/tbG8wsKPRN https://t.co/RV8zBr6jLr
how2heap:glibc 堆利用技术合集与 PoC
RT @cr3ghost: Free resource for anyone learning heap exploitation.
Credit to @shellphish for maintaining how2heap, a practical collection of glibc heap exploitation techniques with small working PoCs across different libc versions.
Fastbin, tcache, unlink, overlapping chunks, House techniques and more.
https://t.co/VeKBCENJtP
#ExploitDevelopment #VulnerabilityResearch #ReverseEngineering
malware-unicorn GitHub 仓库链接
https://t.co/1RcuYkFbRH
PoC here https://t.co/Oxh6Vkg2ic
work work , patcing the calc code https://t.co/Tu7zyQHzSf https://t.co/rfGUyV2QJE
Ping from scratch
https://t.co/hOyNeCsDPe
JB
Bro you are writing a GPU emulator https://t.co/BVhmQLUyyq
@AvimanyuRoy3 AGX G15, since that's what my laptop has (lets it do hardware probes to figure out the ISA semantics). I haven't seen anyone else doing this, everyone else seems to be going the paravirt route
@AvimanyuRoy3 (By which I mean - pls link if you know of anyone else doing RE on the ISA!)
Can someone that has a LOT of query creds on shodan and censys hit me up? You will paid after I am done with the thing I am doing :)
I fucking hate that I have to do everything legally. It feels like I’m constantly being held back and not allowed to actually use my skills to their full potential.
I have a huge list of techniques to document, but honestly, I don’t feel like working on any of them right now
So, I’d love to hear your recommendations for some fun ones to work on. Research ideas are also very welcome
Having fun with Shadow Copies https://t.co/PDj9n9887B
Android XP Professional 恶搞视频
RT @XorNinja: Introducing Android XP Professional, best watched with sound on: https://t.co/1t92lCj1qF
AI 公司据报批量采购 RTX 5090 用于服务器
RT @TechPowerUp: AI Firms Are Reportedly Buying NVIDIA RTX 5090 GPUs in Bulk for Server Use https://t.co/nVMwRIq7TN https://t.co/kNqQxw54tS
AI 公司成托盘采购游戏 GPU 推高 RTX 5090 价格
RT @VideoCardz: Here’s why RTX 5090 costs $5,000: AI firms are buying gaming GPUs by the pallet
https://t.co/KEl9yRMUQQ https://t.co/UrPfL4YLTH
RT @TheAhmadOsman: This was a crazy stupid thing to do back in 2023/2024 but I fully believed Local and Opensource AI were the future
Best investment and bet ever https://t.co/taXYg9ofAJ
RT @0xSero: Come and take it
Unregistered compute running illegal Chinese clankers all day https://t.co/fBmkdPVVpb
对 DeepSeek V4.1 Flash 发布的兴奋反应
RT @Kedr_bit: YAYY! The squad is JUBILANT to see Deepseek V4.1 Flash! https://t.co/l2Qz7YFPAI
测试称 DeepSeek v4.1 Flash 前端设计超越 Opus 5
RT @MiaAI_lab: Yeah I see why Dario is afraid
Based on my initial testings DeepSeek v4.1 Flash is outperforming Opus 5 and is very close to Fable 5.1 across the board in frontend web design.
And it's running locally on my little sparks!
Astra 用 computer use 做网站功能验证
RT @_ryu15_: Astra はAGIです
computer useでサイトの動作確認中 https://t.co/gcEHI3m3RY
OpenAI 关停 GPT-5.3-Codex-Spark 的原因
OpenAI 关停 GPT-5.3-Codex-Spark 的原因: https://t.co/k7vKbLCOII
Anthropic、OpenAI、Google 洽谈组建行业 AI 标准机构
RT @MTSlive: SITUATION DETECTED: Anthropic, OpenAI, and Google are holding talks to create an industry-led standards body to police the AI sector, per The Information.
RT @Kalshi_Finance: BREAKING: Mark Zuckerberg says AI development needs to move faster
Yann LeCun 批评 Dario 自 2019 年就渲染 AI 危险
RT @ylecun: @PessimistsArc Right. Dario was already claiming that GPT2 was too dangerous to open source back in 2019.
I made fun of them then.
Everyone should make fun of them now.
评论称 Anthropic 与 OpenAI 在 felonybench 上领先
the dangerous part still seems to be Anthropic and OpenAI themselves. they lead felonybench by a wide margin
Palmer Luckey 评论某 AI 监管主张
RT @PalmerLuckey: @Austen He thinks he will be put in charge of the most powerful transnational organization in history and strongarm the USA. Saying he would hand everything over to "the right set of government" is obviously predicated on the assumption that it is run by him and his stooges, not Trump.
RT @PalmerLuckey: @micsolana If this somehow happens, it only ensures that 4chanAI will win. No rules, no regulations, no restrictions, and no corporate center to attack with lawfare or bad PR.
"Why doesn't the government just control the technology completely?"
Because you can't stop the signal, man.
RT @drfrensor: “Tell everyone you’re slowing AI down.“ https://t.co/ZlIPdh2ncL
i wanted to join the labs when i thought they were dangerous accelerationists, then i found out they were total decels
if Elon was a WoW classic guy instead of Diablo, we’d have AGI by nov 4
i shouldnt be punished as spam when i get on an inspired rampage
orc shaman. endgame resto main. windfury 2hand leveling. thats my main WoW forever char at launch, pls stop asking
i was there for warez and exploits on disks passed on the sneakernet. i already know open source wins https://t.co/YeDFUUZp5W
i take delight in knowing open source can’t be stopped
调侃 OpenAI 与 Anthropic 的命名反差
RT @tekbog: >company called Open AI
>wants closed AI
>company called Anthropic https://t.co/hg68hYbJQD
RT @PalmerLuckey: @romanhelmetguy https://t.co/JDEEHa1VWG
@a_musingcat i knew you were an accelerationist
@a_musingcat welcome brother
@0xTriboulet @jjkaplowitz @grok hate car exhaust but also like owning my car and it not being part of someone elses network :(
whos making a classic car EV without the killswitch and internal cameras for me? we gotta keep the gas flowing. im not rdy to own nothing and be happy
@0xTriboulet @HackingDave also i took some notes
@0xTriboulet @HackingDave If its a nation security and powr projection imperative then lets act like it.
WoW forever is on the horizon. we must accelerate as fast as possible
@HDPbilly barbarian from the north. its a long run to freeport. the traveling gem salesman guild delivered on its promise, unlike some elves
@HDPbilly I was there for the bloodfist massacre
RT @Michellek4040: I think Cam Skattebo was born with CTE and every time he gets hit it reverses it a little
RT @distributedkv: dream team for American acceleration. https://t.co/H0ZLUVZQPk
RT @ezioakwawo: Liking people’s replies as we’re arguing so they know it’s just a friendly debate & there’s no need to wish me death. https://t.co/kxfNCO0Zhh
RT @elonmusk: This @waitbutwhy cartoon hits the 🎯 https://t.co/LlGFbFbcYc
RT @bmay: This morning’s chat with Claude hasn’t exactly filled me with confidence. https://t.co/UAw9PZADzy
they’re calling it post of the year
openssl openssl-4.1.0-alpha1 — General purpose TLS and crypto library https://t.co/tnkuxy3Lxe https://t.co/691IppZwUM
OpenAI 关停 GPT-5.3-Codex-Spark 的原因: https://t.co/k7vKbLCOII
superintelligence will let us all just stay home and play world of warcraft forever so i think it’s a good idea and we should go faster so it’s ready by november
广告又要来新形态了,模仿消息通知样式 https://t.co/mcrfJQ57NE
RT @Sokio8D: https://t.co/s04BluqHj7
RT @Hesamation: the irony of the situation https://t.co/etAl6uquw8
RT @Ch0pin: Excellent work, highly recommended !
RT @kmcnam1: https://t.co/gUwUXzsz3U
RT @60Minutes: Dramatic video, obtained first by 60 Minutes, shows the rescue of two Air Force officers shot down over a mountainous desert region of Iran back in April. https://t.co/MMeYIaZvfu https://t.co/37AR1xc9bj
RT @Thums1977: @unusual_whales @epictrades1 Let’s just bend over so China can surpass the US
This is the ideal shopping experience
All time banger
@jjkaplowitz I’m pretty sure more people die every year from fossil fuel attributable health issues than all people that have died from nuclear accidents ever. @grok can you fact check me there
This is what "nuclear waste" casks look like. It's where we keep spent nuclear fuel. You could stand right next to it safely. It's not being released to the environment unlike the constant burning of fossil fuels.
And according to the Nuclear Regulatory Commission:
"Since the first casks were loaded in 1986, dry storage has released no radiation that affected the public or contaminated the environment."
There's also tons of uranium in Earth's crust that has been naturally decaying away for billions of years and producing heat.
Source: https://t.co/5tWnDoB8VP
Real uncs know the true lessons were learned organizing 100+ man raids in EverQuest without VoIP.
警员滥用 Flock 车牌摄像头跟踪前女友 170 次
RT @DoingFedTime: A Milwaukee cop ran Flock cameras to stalk his ex 170 times in two months.
An SF officer posted his surveillance flex on Instagram.
This is the access model working as designed.
https://t.co/1X5Gk9z2Gg https://t.co/NmExKke28W
SpecterOps 发布令牌分析与追踪系统 TATS
RT @VixWizzer: This is actually pretty slick
https://t.co/BWYjLnSFPE
Tool: https://t.co/feuzybr0cc
指出 Apple Pay 免密支付需开启快捷交通卡模式
RT @ggerrard: @Rainmaker1973 This ONLY works if Express Transit (also called Express Mode) is ON and a card is selected for it. Just saying🤷🏻♂️
锁屏 iPhone 被用于完成 1 万美元 Apple Pay 支付
RT @Rainmaker1973: A locked iPhone was used to make a $10,000 Apple Pay payment without Face ID or a passcode
[📹 MKBHD] https://t.co/PGDwggugtw
RT @DarkWebInformer: ‼️🇫🇷 A forum actor shared the address of a private residence in Thionville, France, claiming the owners will be absent from September 13 to 16, 2026, seemingly to facilitate burglary or squatting. https://t.co/nS7FqoITqP
RT @geeknik: Deploying mass surveillance for public safety inevitably collapses into police officers using the municipal dragnet as turnkey stalkerware for abusive cousins. Regulators declined to intervene.
https://t.co/XO6pib8e0X
通过 WAM 获取 Entra ID 令牌的代码发布
RT @_dirkjan: Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: https://t.co/qAEk8lXGYG
提权云工具
@_EthicalChaos_
原文 ↗
RT @ElissaBeth: @McGrewSecurity is on record saying he believes OpenAI trains on data under the ZDR program. OpenAI's "Private Safety Processing" could be used to transform enterprise data into synthetic data. https://t.co/z5NK70naXM
If AI companies want enterprise customers, they should offer more clear security and privacy controls.
RT @TheRegister: AI and its main promoters are not enterprise-ready, says Gartner https://t.co/Es1sbQlaSC
Claude: Endless possibilities to execute code from a project session.
llmai_agent
@ipurple
原文 ↗
Does ZDR mean “zero” data and derivatives, or just the input data is not retained?
Since I discussed my concerns on cybersecurity and AI, I have seen so many people start discussing how we are not at the table and asking for us as a community to be involved.
Thank you, please continue to be loud and vocal.
We are building a team to help
llm事件
@Laughing_Mantis
原文 ↗
报道称 OpenAI 雇承包商阅读真实用户聊天记录
RT @unusual_whales: BREAKING: OpenAI has hired an army of contractors who read real ChatGPT users' chats, per 404Media
Charming Kitten APT 对手模拟文章
RT @S3N4T0R_0X0: Read “Charming Kitten APT Adversary Simulation“ by on Medium: https://t.co/tbG8wsKPRN https://t.co/RV8zBr6jLr
OffByOne 议题:串联逻辑漏洞实现 Windows LPE
RT @offbyoneconf: 🔥 EXCEPTIONAL! We raised the bar, @crispr_x & @heegong123 absolutely delivered with “𝐂𝐡𝐚𝐢𝐧𝐢𝐧𝐠 𝐋𝐨𝐠𝐢𝐜𝐚𝐥 𝐁𝐮𝐠𝐬 𝐟𝐨𝐫 𝐑𝐞𝐥𝐢𝐚𝐛𝐥𝐞 𝐖𝐢𝐧𝐝𝐨𝐰𝐬 𝐋𝐏𝐄” at #OB12026! If you were in the room, you know. 👀🔥 https://t.co/7O4yeGto3p
通过 WAM 获取 Entra ID 令牌的代码发布
RT @_dirkjan: Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: https://t.co/qAEk8lXGYG
What if the recent "AI will kill us all" PR campaign, amplified by the "we, the drug dealers, should be stopped, so we want to help regulate the development and use of all drugs" essays, is just the first step in allowing AI companies, heavily invested in the building of data centres, to outlaw the use of self-hosted open-weight models?
Same feelings here:
- Skill deterioration (we're all getting lazier).
- Lack of incentive for future generations to spend the time trying to understand complex problems on their own (debugging for hours or writing complex code by hand vs a simple LLM "help me" prompt).
BABEL 展示单人借助 AI 搭建 OSINT 监控平台
Overall BABEL was an impressive demonstration of the capability of an OSINT surveillance platform that a single developer can whip up with the help of AI support. Either way, come over to our substack to get the deep dive on it and more valuable background. 8/8 https://t.co/H24FlQXojM
ai_agentosint
@NetAskari
原文 ↗
BABEL 含区块链追踪、Telegram 与 Reddit 抓取模块
BABEL also offers some more elements. A dedicated blockchain tracker and analyzer, a Telegram sentry and channel reporter and /reddit scraper. They don't all tie into the wider system and do exist at times as separate elements in different stages of development and sophistication. But overall it is an impressive package. There were also records of WeChat money transfers, but it was not clear if that was live-data or just samples. 7/8
osintai_agent
@NetAskari
原文 ↗
OpenAI 关停 GPT-5.3-Codex-Spark 的原因
OpenAI 关停 GPT-5.3-Codex-Spark 的原因: https://t.co/k7vKbLCOII
Anthropic、OpenAI、Google 洽谈组建行业 AI 标准机构
RT @MTSlive: SITUATION DETECTED: Anthropic, OpenAI, and Google are holding talks to create an industry-led standards body to police the AI sector, per The Information.
RT @Kalshi_Finance: BREAKING: Mark Zuckerberg says AI development needs to move faster
Yann LeCun 批评 Dario 自 2019 年就渲染 AI 危险
RT @ylecun: @PessimistsArc Right. Dario was already claiming that GPT2 was too dangerous to open source back in 2019.
I made fun of them then.
Everyone should make fun of them now.
评论称 Anthropic 与 OpenAI 在 felonybench 上领先
the dangerous part still seems to be Anthropic and OpenAI themselves. they lead felonybench by a wide margin
Palmer Luckey 评论某 AI 监管主张
RT @PalmerLuckey: @Austen He thinks he will be put in charge of the most powerful transnational organization in history and strongarm the USA. Saying he would hand everything over to "the right set of government" is obviously predicated on the assumption that it is run by him and his stooges, not Trump.
RT @PalmerLuckey: @micsolana If this somehow happens, it only ensures that 4chanAI will win. No rules, no regulations, no restrictions, and no corporate center to attack with lawfare or bad PR.
"Why doesn't the government just control the technology completely?"
Because you can't stop the signal, man.
RT @drfrensor: “Tell everyone you’re slowing AI down.“ https://t.co/ZlIPdh2ncL
i wanted to join the labs when i thought they were dangerous accelerationists, then i found out they were total decels
if Elon was a WoW classic guy instead of Diablo, we’d have AGI by nov 4
i shouldnt be punished as spam when i get on an inspired rampage
orc shaman. endgame resto main. windfury 2hand leveling. thats my main WoW forever char at launch, pls stop asking
i was there for warez and exploits on disks passed on the sneakernet. i already know open source wins https://t.co/YeDFUUZp5W
i take delight in knowing open source can’t be stopped
调侃 OpenAI 与 Anthropic 的命名反差
RT @tekbog: >company called Open AI
>wants closed AI
>company called Anthropic https://t.co/hg68hYbJQD
RT @PalmerLuckey: @romanhelmetguy https://t.co/JDEEHa1VWG
@a_musingcat i knew you were an accelerationist
@a_musingcat welcome brother
@0xTriboulet @jjkaplowitz @grok hate car exhaust but also like owning my car and it not being part of someone elses network :(
whos making a classic car EV without the killswitch and internal cameras for me? we gotta keep the gas flowing. im not rdy to own nothing and be happy
@0xTriboulet @HackingDave also i took some notes
@0xTriboulet @HackingDave If its a nation security and powr projection imperative then lets act like it.
WoW forever is on the horizon. we must accelerate as fast as possible
@HDPbilly barbarian from the north. its a long run to freeport. the traveling gem salesman guild delivered on its promise, unlike some elves
@HDPbilly I was there for the bloodfist massacre
RT @Michellek4040: I think Cam Skattebo was born with CTE and every time he gets hit it reverses it a little
RT @distributedkv: dream team for American acceleration. https://t.co/H0ZLUVZQPk
RT @ezioakwawo: Liking people’s replies as we’re arguing so they know it’s just a friendly debate & there’s no need to wish me death. https://t.co/kxfNCO0Zhh
RT @elonmusk: This @waitbutwhy cartoon hits the 🎯 https://t.co/LlGFbFbcYc
RT @bmay: This morning’s chat with Claude hasn’t exactly filled me with confidence. https://t.co/UAw9PZADzy
they’re calling it post of the year
superintelligence will let us all just stay home and play world of warcraft forever so i think it’s a good idea and we should go faster so it’s ready by november
广告又要来新形态了,模仿消息通知样式 https://t.co/mcrfJQ57NE
RT @Sokio8D: https://t.co/s04BluqHj7
RT @Hesamation: the irony of the situation https://t.co/etAl6uquw8
RT @Ch0pin: Excellent work, highly recommended !
RT @kmcnam1: https://t.co/gUwUXzsz3U
RT @60Minutes: Dramatic video, obtained first by 60 Minutes, shows the rescue of two Air Force officers shot down over a mountainous desert region of Iran back in April. https://t.co/MMeYIaZvfu https://t.co/37AR1xc9bj
RT @Thums1977: @unusual_whales @epictrades1 Let’s just bend over so China can surpass the US
This is the ideal shopping experience
All time banger
@jjkaplowitz I’m pretty sure more people die every year from fossil fuel attributable health issues than all people that have died from nuclear accidents ever. @grok can you fact check me there
This is what "nuclear waste" casks look like. It's where we keep spent nuclear fuel. You could stand right next to it safely. It's not being released to the environment unlike the constant burning of fossil fuels.
And according to the Nuclear Regulatory Commission:
"Since the first casks were loaded in 1986, dry storage has released no radiation that affected the public or contaminated the environment."
There's also tons of uranium in Earth's crust that has been naturally decaying away for billions of years and producing heat.
Source: https://t.co/5tWnDoB8VP
Real uncs know the true lessons were learned organizing 100+ man raids in EverQuest without VoIP.