g3n3r4l10
-
Dom-Explorer (yeswehack.github.io)
A handy interactive tool to inspect DOM-based XSS vectors with practical exploration examples.
-
Puny-Code Vulnerabilities & Account Takeover (blog.voorivex.team)
A fascinating case of 0-click account takeover using puny-code encoding abuse.
-
Offensive Threat Intelligence (blog.zsec.uk)
Discussing how to leverage offensive capabilities for enhanced CTI operations.
-
Remote Prompt Injection in GitLab Duo (legitsecurity.com)
An attack method leading to source code exfiltration via LLM prompt injection.
-
BadSuccessor (dMSA Abuse in AD) (akamai.com)
Escalating privileges in Active Directory via delegation misconfigurations.
-
Commit Stomping (blog.zsec.uk)
A clever way to manipulate Git history for stealthy backdoors.
-
Persistent WeChat Client-Side Attack (darknavy.org)
Exploiting a single WeChat message for long-term client-side compromise.
-
GitHub MCP Exploited (invariantlabs.ai)
Critical vulnerability allowing access to private GitHub repos via MCP.
-
XSSing TypeErrors in Safari (thespanner.co.uk)
A deep dive into an unusual XSS vector using TypeErrors in Safari.
-
Preventing AI Hallucinations (thecloudcast.net)
The Cloudcast podcast explores strategies to reduce LLM hallucinations. Listen Here
X3
-
Gareth Heyes on Safari XSS Vector (@garethheyes)
Can you spot the Safari-only XSS vector before checking the solution? Watch Here
-
Today In Infosec – "Realm of the Hackers" Documentary (2003) (@todayininfosec)
The story of Australian teen hackers Electron & Phoenix. Watch Here
-
Today In Infosec – "Hackers: Heroes" Book Anniversary (2010) (@todayininfosec)
Throwback to the iconic 1984 hacker culture publication.
y0utube1
-
Abusing Historical DNS Records (youtube.com)
Mustafa walks through how DNS history can be weaponized in red teaming. Watch Here
g1thub3
-
OperantAI/woodpecker (github.com)
A red teaming toolkit focusing on AI and cloud environments. Explore on GitHub
-
silverhack/monkey365 (github.com)
All-in-one security auditing for Microsoft 365, Azure, and Entra ID. Explore on GitHub
-
macalbert/envilder (github.com)
A secure CLI for managing environment variables via AWS SSM. Explore on GitHub