Posts
4509
Following
739
Followers
1657
"I'm interested in all kinds of astronomy."
repeated

OVERPASS is an unauth RCE in the SAP kernel (CVE-2026-44756) and S4GET is a preauth RCE in the SAP NetWeaver's Message Server (CVE-2026-58240).

Both have a very high CVSS and are likely to be exploited.

https://onapsis.com/blog/sap-overpass-remediation/

https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/

0
1
0
repeated

Hey everyone! ๐ŸŒน

> Lalu here: Openly sharing @entrypoint_fr 's open CFP & registration to help them kick-start nicely this new cool and red-focused event!
> Finding the right speakers and audience is hard, even more now that AI makes things feel "less special",. But some people are still making this happen, let's join forces! ๐Ÿ€

---

Join & Apply to Entrypoint by @synacktiv a conference entirely dedicated to **Red Teaming**, coming to Paris on March 19โ€“20, 2027 at Le Dernier ร‰tage.

Expecting 500 attendees from around the world, all talks will be delivered in **English** to bring together as many international profiles as possible ๐Ÿ‘Œ

๐Ÿ“ Venue & Details:
- Event page: https://entrypoint.fr/
- Location: https://ledernieretage.paris/

๐ŸŽค Call for Papers
If you have a compelling topic to share, we'd love to hear from you. Submissions are open on the following tracks:

- Advanced Pentesting & Red Teaming : ActiveDirectory, Cloud (AWS/Azure/GCP) exploitation, container escapes, lessons learned (full scenario analysis).
- Supply Chain Attacks : Attacks targeting dependency managers (npm, pip, composer), secrets leaked on public platforms (GitHub).
- CI/CD : Advanced pipeline exploitation, loot techniques.
- Physical Intrusion : Methodologies to reach internal networks / target companies physically.
- Malware & C2 : Evasion techniques, obfuscation, custom C2 infrastructure, implant development.
- Post-Mortem Analysis : Analysis of threat actor exploitation methodologies, complex compromise chains.
- AI-assisted offensive security : Offensive use of AI including agentic red teaming, model-assisted vulnerability research, and AI-driven exploitation in real operations.

๐ŸŽ“ Training Days

4 days of hands-on training (Monday, March 15 โ€“ Thursday, March 18) covering the same themes.

๐ŸŽ Speaker Perks

To make it as smooth as possible for speakers, here's what is covered:
- Travel expenses
- Accommodation : hotel booked for the duration of the conference
- Speaker dinner : a dedicated evening to hang out with fellow speakers

โ‰๏ธ Questions

Feel free to ping @_remsio_ on X/discord or official @entrypoint_fr accounts directly if you have any questions or need more details!

See you in Paris! ๐Ÿ‡ซ๐Ÿ‡ทโœŒ๏ธ

0
2
0
repeated

๐Ÿ‡ญ๐Ÿ‡บ has expelled 10 Russian diplomats who "were engaged in activities in Hungary that are unacceptable for diplomats under the Vienna Convention," Foreign Minister Anita Orbรกn said in a statement on Tuesday.

https://tvpworld.com/95280737/hungary-expels-10-russian-diplomats-foreign-minister-says

0
2
0
repeated

almost every idea iโ€™ve had in my life is better than this can i get a few million dollars of investment (also wtf is wrong with my instagram ads)

0
1
0
repeated
Edited 7 hours ago

Please boost this for as much reach as possible.

Parton Kirk, where genius James Clerk Maxwell is buried, is being put up for sale. The community is attempting a buy out to save this kirk for science and the local community. They have until 31st of October to secure the funds.
Here's the crowd funder link. You can help prevent this kirk from falling into private hands.

https://www.justgiving.com/crowdfunding/savepartonkirk

0
3
0
repeated

Hello London ๐Ÿ‡ฌ๐Ÿ‡ง

The Phrack team is here and we left our mark around the city.

If you can find any of these stickers, email us for a chance of getting a physical copy of Phrack 73 delivered to your doorstep.

Send proof to hunt@phrack.org and have fun!

0
4
0
repeated

Iโ€™ve factored the RSA keys of a Certificate Authority...

โ€ฆ from the 90s.

https://mcpherrin.ca/2026/09/07/rsa.html

1
3
0
repeated

docker compose up up down down left right left right b a start

4
12
2
repeated

Someone recreated the Windows 98 Disk Defragmenter in your browser.

Multiple drives, different speeds, mechanical HDD sounds, moving colored blocks...

And a Realistic mode where "Windows" occasionally touches the disk, forcing a rescan and losing some progress.

It's not true nostalgia unless you recreate the suffering too.

https://defrag98.com

0
3
0
@abrasive How about grouping people in Lists?
0
0
1
repeated

You have until the 8th at 23:59 to submit to unprompted! What are you waiting for?

https://unpromptedcon.org/

0
1
0
repeated
Tonight!
I hack an Artifactory,
James vandalizes a German wiki,
and Richard steals $13 billion from NVidia
2
1
0
repeated

This affects the Fediverse.

This affects the Internet.

This is the equivalent of the "rubber hose method" of decryption.

All technical solutions (read: all technology) is subject to politics. To political power. To political interactions.

You cannot rely on purely technical approaches. You have to have social approaches, too. Like. Actual policy and procedure geared around social and political group dynamics.

Like. How will we react when the US Govt requires that @jerry to shut off infosec.exchange servers.

Or how we'll react when a specific Mastodon server is declared part of a terrorist infrastructure. Will federating with it mean any other Mastodon server is now part of the officially designated terrorist network (what then of people that federate with a server that federates with a server that is classified as part of a terrorist network. And so on)

You cannot carry the conceit that tech alone or a purely technical approach will save you.

https://sabot.media/post/ai-shuts-down

6
22
0
repeated

I regret to inform everyone that my copy of QBittorrent escaped its sandbox last night and downloaded a whole bunch of content owned by major corporations, and then my copy of Jellyfin broke containment and added those unfortunately-downloaded media files to its various libraries. I'm conducting an internal investigation to figure out how this happened, which will involve consuming these media files until the answers become apparent. Thank you for your cooperation during this trying time.

5
68
2
@Edent

"I can understand why .bid and .loan are popular with scammers. But why .mobi?!" -> because the avg user has 0 clue about what a domain name is, what its parts are and what they signify. Not to mention URLs...

"What can be done?" -> So far I could only think of enforcing a strict domain allow list for users (at the endpoint/browser) who don't know better.
0
0
0
repeated

It was brought to my attention that Real Hack History, a youtube channel, has been uploading documents, audio and video related to hacking history to the Internet Archive and they deserve a little collection. I'm making them for them now but you can look at their excellent uploads immediately.

Really good stuff. Really well sourced.

https://archive.org/details/@realhackhistory

1
6
1
repeated

Fi ๐Ÿณ๏ธโ€โšง๏ธ

Hot take:

a 20 kloc PR - even if it fixes the problem or adds the feature perfectly - is spam.

it is spam because it overwhelms the reviewer, who is then unable to reasonably perform their duty of actually comprehending and checking the code to make sure it does what it's supposed to.

0
6
0
repeated

Micropatches released for "ResetNightmare" Windows Kerberos Elevation of Privilege (CVE-2026-27912) https://0patch.com/blog/micropatches-released-for-resetnightmare-windows-kerberos-elevation-of-privilege

1
2
0
repeated

I'm launching a series of short posts about the tools I've built to automate
reverse-engineering workflows. I've used them to analyze protections such as
SafetyNet, DexProtector, iXGuard, and Arxan.

First up: MCStone, a clean & efficient assembler and disassembler built on LLVM's MC layer.

https://www.romainthomas.fr/project/mcstone/

0
2
0
repeated

An interesting paper: Frontier Modelsโ€™ Vulnerability Patches are Often
F.L.A.W.E.D.

https://1password.com/files/resources/frontier-models-vulnerability-patches-flawed.pdf

0
1
0
Show older