Posts
4384
Following
737
Followers
1650
"I'm interested in all kinds of astronomy."
repeated
Edited 1 year ago

Finally a paper on malware fuzzing! PFUZZER: Practical, Sound, and Effective Multi-path Analysis of
Environment-sensitive Malware with Coverage-guided Fuzzing https://www.diag.uniroma1.it/~delia/papers/eurosp25-pfuzzer.pdf

0
1
0
To join the recent series of great Windows Defender content (defendnot, EvilentCoerce) I published a status report on mpclient development:

Fuzzing Windows Defender with loadlibrary in 2025

https://scrapco.de/blog/fuzzing-windows-defender-with-loadlibrary-in-2025.html

#Fuzzing #ReverseEngineering #Antivirus
0
3
3
repeated

kimapr ☭ 🇺🇿 ⚧ ⚢ ❤️🧡🤍🩷💜

I think it’s really funny that in windows the standard libraries serve to abstract away incompatibilities between the kernel of different windows releases while this funny thing:

  • GLibc

in the lunix world does the exact opposite

0
3
1
repeated

A practical NTLM relay attack using the MS-EVEN RPC protocol and antivirus-assisted coercion https://github.com/Thunter-HackTeam/EvilentCoerce

0
2
0
repeated

FYI if you’re willing to link with ntdll or dynamically resolve it there’s a ton of APIs that return TEB/PEB or leave them in one of the registers.
(Don’t believe official return values. MSDN is a liar!)

https://bird.makeup/@vxunderground/1920208595808821334

2
1
0
repeated

Today 80 years ago Nazi Germany declared its unconditional surrender, ending the World War II.

0
2
0
How I ruined my vacation by reverse engineering [Windows Security Center]

https://blog.es3n1n.eu/posts/how-i-ruined-my-vacation/

Defender disabler tool:

https://github.com/es3n1n/defendnot
0
7
12
repeated

Recon training prices go up beginning of May! If Linux binary analysis and malware are down your alley, check out my 4-day training on the topic 🤓
https://recon.cx/2025/trainingLinuxMalwareReverseEngineering.html

0
4
0
[RSS] CVE-2024-11477- 7-Zip ZSTD Buffer Overflow Vulnerability - Crowdfense

https://www.crowdfense.com/cve-2024-11477-7zip-zstd-buffer-overflow
0
0
2
[RSS] exploits.club Weekly Newsletter 71 - Lots Of Linux, MacOS OOB Writes, Enterprise Pre-Auth RCEs, and More

https://blog.exploits.club/exploits-club-weekly-newsletter-71-lots-of-linux-macos-oob-writes-enterprise-pre-auth-rces-and-more/
0
0
4
repeated

Project Zero Bot

New Project Zero issue:

XNU VM_BEHAVIOR_ZERO_WIRED_PAGES behavior allows writing to read-only pages

https://project-zero.issues.chromium.org/issues/391518636

CVE-2025-24203
0
1
2
repeated

It makes me super uncomfortable that globbing in Bash can turn into code execution. The fact that the name of a file can change the behavior of ls is scary. This also works for other commands that you tend to glob with, such as rm.

16
9
0
repeated
repeated

with offensivecon around the corner, i figured id write another post on linux kernel exploitation techniques - this time i cover the world of page table exploitation! enjoy 🤓

https://sam4k.com/page-table-kernel-exploitation/

0
5
0
Edited 1 year ago
0
0
2
repeated

While we wait, here's a quick look at the web traffic currently hitting Wikimedia projects — can you perhaps guess when the reports of white smoke from the Vatican first started?

3
6
0
repeated

Tariffs just got real: our first $36K bill with 125% + 20% + 25% markup hits hard 💸. These are upfront costs - due before selling a single unit - causing serious cash flow strain, price increases, read more! 📦 http://adafruit.com/tariffbill

7
25
0
repeated

Wikipedia @wikimediauk are going to court over the UK Online Safety Act!

Saddling platforms with hefty duties and penalties under the new regime will cause many safe sites to fold.

We can't lose the best of the web due to laws that were meant to tackle the worst of it.

https://www.bbc.co.uk/news/articles/c62j2gr8866o

1
11
0
This post by @algernon is a surprising confirmation of one of my theories about why many of "us" aren't really impressed by #LLM's:

https://chronicles.mad-scientist.club/tales/conversations-with-an-artificial-intelligence/

Thing is, we've seen this before, played with it, found its limits and got bored. Of course LLM's provide much better results, but I still don't think the underlying principle is that much different.

Same with shitcoins: we designed a proof-of-work system as teenagers for password cracking, so the principle is not magical to us and this goes against the marketing.
2
2
4
repeated

Microsoft Copilot for SharePoint just made recon a whole lot easier. 🚨
 
One of our Red Teamers came across a massive SharePoint, too much to explore manually. So, with some careful prompting, they asked Copilot to do the heavy lifting...
 
It opened the door to credentials, internal docs, and more.
 
All without triggering access logs or alerts.
 
Copilot is being rolled out across Microsoft 365 environments, often without teams realising Default Agents are already active.
 
That’s a problem.
 
Jack, our Head of Red Team, breaks it down in our latest blog post, including what you can do to prevent it from happening in your environment.
 
📌Read it here: https://www.pentestpartners.com/security-blog/exploiting-copilot-ai-for-sharepoint/

5
15
0
Show older