CEO and Co-Founder of Octopwn

Joined June 2014
SkelSec retweeted
Meet Octoagent, Octopwn's on-prem, model agnostic internal network pentesting agent, boosted by local or cloud LLMs. Fully onprem, controlled, customizable, transparent and logged. youtu.be/f_HqEnIe1zM
2
10
1,579
SkelSec retweeted
We're very proud to have been featured on the front page of the Hungarian news site 444.hu, with Tamás Jós (@SkelSec), Tamás Mihalovits and Anna Bátki pictured standing at our #defcon booth. :) Article in Hungarian: 444.hu/2026/09/15/mestersege…
2
4
493
New gowitness, 3.20! github.com/sensepost/gowitne…
1
3
17
997
SkelSec retweeted
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/askWAM
7
75
3
233
18,389
Microsoft Coreutils (version 2026.9.3 and earlier) tail.exe 🤭
1
3
623
Повну емуляцію апаратної платформи Nokia 6600 (NHL-10) у QEMU завершено. GSM-зв’язок працює end-to-end: Відправка та прийом СМС ARM → DSP → IQ → Osmocom → IQ → DSP → ARM
80
387
24
3,850
173,794
I've published UniBLEed, a fully wormable proximity Bluetooth RCE affecting Unitree's G1 humanoids. Blog spans cloud, mobile, firmware, Bluetooth & hardware. Two multi-bug RCE chains. 3 months into ~80 minutes, $6,700 in bounties. Go jailbreak your G1s!! boschko.ca/g1-ble-rce/
10
83
10
225
24,095
My @x33fcon talk about Credential Relay Phishing is finally out! Watch me struggle through the live Google phishing demo, a day after the pirate ship party, which deprived me of my last few brain cells. 😜 Wrath of demo gods and AI lulz included. 🥳 youtu.be/dNtqZJmtIpw
4
36
120
10,358
SkelSec retweeted
📢 The next edition of my offensive Entra ID security class just opened up for registration! November 16-19 in The Hague, Netherlands. In this 4 day class we deep dive into Entra ID security, tokens, oauth2 and Conditional Access. More info and reg: events.outsidersecurity.nl/e…
2
17
1
109
7,664
THIS HAS HAPPENED TO ME AS WELL! Even worse some notifications popped up randomly then when I check there are no new messages then weeks later it shows up????
I just discovered that I have loads of unread message 'requests' in my X DMs, some of them 30+ weeks old. Was never served a notification for them, so had no idea they were there. I'm very sorry if I've ignored you as a result 🙈
2
6
2,049
hmmm... Given: user has energy Assume: user has energy Therefore: user has energy like user has energy
1
966
hey peeps who are using my aiosmb module. I've been thinking on adding compression support to the library but to do it properly the algo would be implemented in rust. so the options are:
30%mandatory rust
30%make it separate package
0%no compression at all
40%yolo it in C
10 votes • Final results
1
1
1
1,273
I have finally started working on the official Evilginx cookie manager extension for Chrome. 🍪 Over the years, I recommended either EditThisCookie, CookieEditor or StorageAce for importing your captured session cookies. It always felt wrong to endorse a third-party extension I am not affiliated with, especially since extensions can eventually be sold to shady companies by their authors. Soon, you will be able to enjoy an official, completely free Evilginx extension for cookie management, fully compatible with both Evilginx 3.0 and Evilginx Pro. Considering that now I can make the cookie manager extension as I want it, it will be packed with extra features to help with phishlets development. Here is the list of ideas I have, which may change during development: ▫️ Real-time cookie monitoring to pinpoint exactly which cookies may hold session tokens. ▫️ Automated detection of relevant cookie combinations to find the ones holding the session tokens. ▫️ Export identified session cookies to both Phishlets V1 and V2 formats. ▫️ Integration with Evilginx Pro client's REST API to view captured session tokens and import them in one click. ▫️ Proxying traffic through the local Evilginx Pro client SOCKS5 proxy to aid with additional HTTP packet interception, which cannot be done with Manifest V3 extensions. This may be used as a companion for phishlet development. As for the GenAI slop concerns: AI was used for bootstrapping the project. I am fairly capable in Vue.js, so I handle that part by hand to ensure the user experience is exactly what I would expect from the product I can vouch for personally. Quality and usability are still my highest priority. You can expect no slop. 💩🚫 I may release the extension soon as a simple cookie manager and add the new features later in iterative updates. Stay tuned for more news! 🔥
7
19
2
164
8,872
Letters of Marque 2.0
Who doesn't want to add a whole new level of fun when traveling abroad? nitter.cf/WeldPond/status/208771…
1,046
SkelSec retweeted
We're back from Hacker Summer Camp (Black Hat and DEFCON) from Las Vegas. Thank you for all the great meetings, fun discussions and great memories! If you're thinking about booking a demo to get set up w/ Octopwn, you can do it at demo dot octopwn dot com See you soon!
1
4
4,020
They forgot to tell copilot to make no mistakes
Microsoft has failed to properly patch RoguePlanet (CVE-2026-50656), ShieldBreak, a PoC that demonstrates a full bypass to the previous patch is now public. github.com/MSNightmare/Shiel… The PoC works with the latest August 2026 patch
1
16
1,766
General announcement for all researchers: Could you please hit pause a bit on the publishing? I spent the last weeks on traveling across the world (still stuck at CDG) and can't keep up with all these new hot stuff to implement and already getting anxiety on the upcoming work
12
922
My recent talk from @x33fcon is now available on YouTube ☝️
2
27
99
6,553