@domchelli
iAccount based inUnited Kingdom
About this account
- Account based in
- United Kingdom
- Connected via
- United Kingdom App Store
Account-level information from X, not a live location or the device used for a specific post.
Just your friendly neighbourhood red teamer @MDSecLabs @nighthawk_c2 | Creator of /r/redteamsec | https://nitter.cf/t.co/3k3EBAZqGd | https://nitter.cf/t.co/KwO2OwDOkl
Manchester, England
Joined February 2009
- Tweets16.5K
- Following558
- Followers18.1K
- Likes17.3K
Pinned Tweet
Replying to @MDSecLabs
@MDSecLabs will be running our Red Team Capability Training out in #BlackHatUSA26 again this year. This year the course features a big refresh, with a bunch of new additions on the latest evolving techniques!
Early bird discounts end this month! @BlackHatEvents
blackhat.com/us-26/training/…
Another banger by Google
cloud.google.com/blog/topics…
Dominic Chell 👻 retweeted
‼️ BREAKING: Citrix confirms two NetScaler flaws have been exploited and has released fixes.
CVE-2026-88771 and CVE-2026-88772 were observed exploited on unmitigated deployments.
The new advisory covers eight CVEs affecting NetScaler ADC and Gateway.
New Details → thehackernews.com/2026/09/wa…
Dominic Chell 👻 retweeted
🚨 NEW: Research has found one in five working-age adults are now on Universal Credit
This includes 1.3 million people in their 20s, 2 million in their 30s and 1.9 million in their 40s according to the TaxPayers’ Alliance
Thank you @_RastaMouse
Dominic Chell 👻 retweeted
Kaspersky reports on NightEagle's attacks on firms in Russia, an expansion of geography
This actor was first exposed in July 2025 by QiAnXin (as APT-Q-95) & Qihoo 360 (as APT-C-78) for attacking China
Both CN vendors labeled it a North American APT
securelist.com/tr/nighteagle…
Individuals at risk are encouraged to follow our advice to detect spear-phishing attempts and defend against malicious activity that collects data from targets. For more information ⬇️2/2
ncsc.gov.uk/news/iranian-cyb…
Dominic Chell 👻 retweeted
‼️ Four espionage clusters used the same Chrome exploit kit within a week.
BlueMoon chained two V8 zero-days with a Windows privilege escalation flaw to deploy payloads including GemStone and ShadowPad.
Inside the exploit chain: thehackernews.com/2026/09/fo…
Don't forget to think about your well-being from time-to-time and go do other things that make you happy or provide fulfillment:
- Disconnect from social media
- Get off the screen and go touch grass and enjoy nature
- Embrace hobbies outside of tech/cyber/etc.
- Workout or go for a walk/run
- Wake up early to catch a sunrise with a coffee
Dominic Chell 👻 retweeted
Microsoft has failed to properly patch ShieldBreak CVE-2026-69414 - msrc.microsoft.com/update-gu…
ShieldCrash demonstrates a full bypass of the patch - github.com/MSNightmare/Shiel…
Works with latest September 2026 patch
Microsoft has failed to properly patch RoguePlanet (CVE-2026-50656), ShieldBreak, a PoC that demonstrates a full bypass to the previous patch is now public.
github.com/MSNightmare/Shiel…
The PoC works with the latest August 2026 patch
Dominic Chell 👻 retweeted
NetNTLMv1 is dead. Long live NetNTLMv1. 🌈
Today we're releasing NTLMRain: recovering NT hashes from NetNTLMv1 responses.
🌐 Browser-based cracking
⌨️ Cross-platform CLI with GPU/CPU support
💾 Searchable tables that fit on a 4 TB disk
Read the blog: outflank.nl/blog/2026/09/08/…
RedTreat #5 is a wrap, possibly the best one yet! Awesome talks, attendees and location ❤️ safe travels to all attendees from me, @MarcOverIP and @StanHacked
Dominic Chell 👻 retweeted
I really recommending reading this.
In summary, a company which does ID verification for in-person interactions (hotels, car rentals, ID verification for alcohol or marijuana, etc) has some how exposed over 153,000,000 drivers licenses for people in the United States and Canada.
It is a catastrophic data breach, probably one of the worse I've ever seen. If you're in the United States and have traveled, gotten a hotel, purchased marijuana or alcohol, there is a high probability you're in this.
Unlike other breaches, this includes a photo of the person (from the license), making verification you've identified the person significantly easier.
This poses a significant threat to celebrities (musicians, YouTubers, streamers, adult entertainers, actors, etc), politicians, lawyers, wealthy people (CEOs, investors, people of public interest), Law Enforcement Officers, etc
Krebs himself, and several other security researchers, have already confirmed they're in the data leak.
tl;dr gah damn dawg this company is going to be sued into oblivion
krebsonsecurity.com/2026/09/…
Dominic Chell 👻 retweeted
For more than 2 years now the Red Team at MDSec have been running riot in environments by abusing ServiceNow. Today we are releasing more of our research in this space:
mdsec.co.uk/2026/08/when-it-…
The TLDR - popping ServiceNow is one of the most impactful things you can do.
This post has been sat in drafts for 6+ months but with increased focus on snow, now felt like a good time to drop. Awesome stuff from @__invictus_ 🔥
When it Snows it Pours – Anatomy of a ServiceNow Red Team - new post by @__invictus_ mdsec.co.uk/2026/08/when-it-…
Dominic Chell 👻 retweeted
When it Snows it Pours – Anatomy of a ServiceNow Red Team - new post by @__invictus_ mdsec.co.uk/2026/08/when-it-…
Dominic Chell 👻 retweeted
🔴 CVE-2026-62911 için Microsoft Exchange Server'a yönelik bir PoC yayınlandı. Bu açık, kimlik doğrulama atlatma yoluyla yetki yükseltmeye ve saldırı zincirinin devamında uzaktan kod çalıştırmaya kadar gidebiliyor.
github.com/hypnguyen1209/cve…
Dominic Chell 👻 retweeted
Stop paying for Codex/Claude or Cursor .
Try using McDonalds ai with Unlimited credits 😭
Readers added context they thought people might want to know
McDonald's has no AI customer support chatbot that writes code. The screenshot and claims are from a viral hoax with fabricated images.
fastcompany.com/91532091/mcdon…
completeaitraining.com/news/viral-cla…