g3n3r4l14
-
Cloud-Attack Techniques (threats.wiz.io)
Interactive matrix of cloud-attack techniques and mitigations.
-
Every UUID V4 (everyuuid.com)
Generate, decode, and validate version-4 UUIDs in one click.
-
BloodHound Query Library (queries.specterops.io)
Curated Cypher queries for BloodHound neo4j graphs.
-
InfoPêxwas: How They Pick Your Digital Pockets Without You Noticing (happyhackingspace.blog)
Modern info-stealing tactics in the wild.
-
SugarCRM Vulnerability (karmainsecurity.com)
SugarCRM <= 6.5.23 (SugarRestSerialize.php) PHP Object Injection Vulnerability allows unauthenticated attackers to execute arbitrary PHP code via specially crafted serialized objects.
-
A Bit More on Twitter/X’s New Encrypted Messaging (blog.cryptographyengineering.com)
Deeper cryptographic analysis of X’s E2EE beta.
-
Ghidra Is Best: Android Reverse Engineering (remyhax.xyz)
Hands-on guide to reversing Android apps with Ghidra.
-
Escaping ‘<’ and ‘>’ in Attributes (bughunters.google.com)
How tiny escapes thwart mutation-XSS.
-
CVE-2025-34508: Path Traversal in ZendTo (horizon3.ai)
End-to-end exploit walk-through and detection tips.
-
Is b for Backdoor? Pre-Auth RCE Chain in Sitecore XP (labs.watchtowr.com)
WatchTowr’s deep dive into a sneaky exploit chain.
-
Defending the Internet: Cloudflare Blocks a 7.3 Tbps DDoS (blog.cloudflare.com)
Behind the scenes of record-breaking mitigation.
-
Cloud Hash Cracking Economics (brunoteixeira1996.github.io)
Combines Hashtopolis and Cloudflare Tunnel for cost-effective distributed cracking without hardware investments.
-
Go Parser Security Footguns (blog.trailofbits.com)
Highlights unexpected risks in Go’s JSON/XML/YAML parsers, including data exposure and format confusion exploits.
-
Insomnia API Client Template Injection (tantosec.com)
Uncovers vulnerabilities in developer tools used during offensive security assessments.
X2
-
Zoom Phishing via App Absence (@hosseeb)
Warns that victims fall for impersonators directing to fake Zoom links (e.g., Z0om.com) partly due to lacking the native app, which should trigger suspicion. Watch Here
-
Prompt Injection Mimicry Tactics (@ctbbpodcast)
Effective prompt injection mimics the model’s training data format for higher success rates. Watch Here
y0utube2
-
OffensiveCon 25 talk by Joernchen. Watch Here
-
Phil Venables on AI-driven defense. Watch Here
g1thub5
-
nuryslyrt/AISecTips-Tricks (github.com)
Handy AI-powered security tips & scripts. Explore on GitHub
-
Ghostcrew (github.com)
Ghostcrew is an all-in-one offensive security toolbox with AI agent and MCP architecture, integrating tools like Nmap, Metasploit, and FFUF. Explore on GitHub
-
Fakjs (github.com)
Fakjs is a fast Go-based tool to uncover sensitive information in JavaScript files, playing a crucial role in reconnaissance during security assessments. Explore on GitHub
-
Threat Designer (github.com)
Threat Designer is a GenerativeAI application designed to automate and streamline the threat modeling process for secure system design. Explore on GitHub
-
Paragon (github.com)
Paragon is a web-based checklist-driven note-taking app following bug bounty and web app pentest methodology. Explore on GitHub