Meet Octoagent, Octopwn's on-prem, model agnostic internal network pentesting agent, boosted by local or cloud LLMs.
Fully onprem, controlled, customizable, transparent and logged.
youtu.be/f_HqEnIe1zM
SkelSec retweeted
New gowitness, 3.20! github.com/sensepost/gowitne…
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/askWAM
SkelSec retweeted
Повну емуляцію апаратної платформи Nokia 6600 (NHL-10) у QEMU завершено. GSM-зв’язок працює end-to-end:
Відправка та прийом СМС
ARM → DSP → IQ → Osmocom → IQ → DSP → ARM
SkelSec retweeted
FalconFlank : Crowdstrike Falcon 0day LPE is now public
github.com/MSNightmare/Falco…
SkelSec retweeted
I've published UniBLEed, a fully wormable proximity Bluetooth RCE affecting Unitree's G1 humanoids. Blog spans cloud, mobile, firmware, Bluetooth & hardware. Two multi-bug RCE chains. 3 months into ~80 minutes, $6,700 in bounties. Go jailbreak your G1s!!
boschko.ca/g1-ble-rce/
SkelSec retweeted
My @x33fcon talk about Credential Relay Phishing is finally out!
Watch me struggle through the live Google phishing demo, a day after the pirate ship party, which deprived me of my last few brain cells. 😜
Wrath of demo gods and AI lulz included. 🥳
youtu.be/dNtqZJmtIpw
📢 The next edition of my offensive Entra ID security class just opened up for registration! November 16-19 in The Hague, Netherlands. In this 4 day class we deep dive into Entra ID security, tokens, oauth2 and Conditional Access. More info and reg: events.outsidersecurity.nl/e…
THIS HAS HAPPENED TO ME AS WELL!
Even worse some notifications popped up randomly then when I check there are no new messages then weeks later it shows up????
hey peeps who are using my aiosmb module. I've been thinking on adding compression support to the library but to do it properly the algo would be implemented in rust. so the options are:
30%mandatory rust
30%make it separate package
0%no compression at all
40%yolo it in C
10 votes • Final results SkelSec retweeted
I have finally started working on the official Evilginx cookie manager extension for Chrome. 🍪
Over the years, I recommended either EditThisCookie, CookieEditor or StorageAce for importing your captured session cookies.
It always felt wrong to endorse a third-party extension I am not affiliated with, especially since extensions can eventually be sold to shady companies by their authors.
Soon, you will be able to enjoy an official, completely free Evilginx extension for cookie management, fully compatible with both Evilginx 3.0 and Evilginx Pro.
Considering that now I can make the cookie manager extension as I want it, it will be packed with extra features to help with phishlets development.
Here is the list of ideas I have, which may change during development:
▫️ Real-time cookie monitoring to pinpoint exactly which cookies may hold session tokens.
▫️ Automated detection of relevant cookie combinations to find the ones holding the session tokens.
▫️ Export identified session cookies to both Phishlets V1 and V2 formats.
▫️ Integration with Evilginx Pro client's REST API to view captured session tokens and import them in one click.
▫️ Proxying traffic through the local Evilginx Pro client SOCKS5 proxy to aid with additional HTTP packet interception, which cannot be done with Manifest V3 extensions. This may be used as a companion for phishlet development.
As for the GenAI slop concerns:
AI was used for bootstrapping the project. I am fairly capable in Vue.js, so I handle that part by hand to ensure the user experience is exactly what I would expect from the product I can vouch for personally. Quality and usability are still my highest priority. You can expect no slop. 💩🚫
I may release the extension soon as a simple cookie manager and add the new features later in iterative updates.
Stay tuned for more news! 🔥
Letters of Marque 2.0
Who doesn't want to add a whole new level of fun when traveling abroad?
nitter.cf/WeldPond/status/208771…
We're back from Hacker Summer Camp (Black Hat and DEFCON) from Las Vegas. Thank you for all the great meetings, fun discussions and great memories!
If you're thinking about booking a demo to get set up w/ Octopwn, you can do it at demo dot octopwn dot com
See you soon!
They forgot to tell copilot to make no mistakes
Microsoft has failed to properly patch RoguePlanet (CVE-2026-50656), ShieldBreak, a PoC that demonstrates a full bypass to the previous patch is now public.
github.com/MSNightmare/Shiel…
The PoC works with the latest August 2026 patch
General announcement for all researchers:
Could you please hit pause a bit on the publishing?
I spent the last weeks on traveling across the world (still stuck at CDG) and can't keep up with all these new hot stuff to implement and already getting anxiety on the upcoming work