Advertisement · 728 × 90

Posts by Aloïs Thévenot

Preview
WireGuard VPN developer can't ship software updates after Microsoft locks account | TechCrunch The popular open source VPN maker is the second high-profile developer to say Microsoft locked his account without notifying him and are blocking their ability to send software updates to users.

New, by me at TechCrunch: The developer of the widely popular Wireguard VPN says he is also unable to ship software updates to Windows users after Microsoft locked his account, marking the second high-profile app developer (VeraCrypt) in the past few weeks to face this issue.

1 week ago 110 66 4 11
Preview
JamfHound v1.1 Update: SSO Attack Paths and Okta Additions - SpecterOps The latest release of the JamfHound OpenGraph collector has new SSO management and Okta hybrid edges integrating into BloodHound Enterprise this spring.

Lance Cain’s latest blog covers something we see a lot in real ops:

SSO → unexpected privilege escalation.

The new JamfHound update maps those paths in JAMF Pro & connects them to Okta. Now integrated with BloodHound Enterprise!

Check it out: https://ghst.ly/4t8EYQS

3 weeks ago 2 1 0 0
Post image

It appears that Microsoft removed the discovery of all domains in a tenant through ACS, a technique that I shared at my BH/DC talks last summer (though probably not many people spotted the reference). I found it out during a live demo of course 🙃

1 month ago 7 2 0 0

Chrome 137+ added a CNG wrinkle to App-Bound Encryption.

@harmj0y.bsky.social & @tifkin.bsky.social share how Nemesis 2.2 handles it, automating DPAPI decryption from SYSTEM & user masterkeys through Chromekey1 to cookie/login recovery, w/ retroactive artifact linking. https://ghst.ly/3OzfkFN

1 month ago 0 2 0 0
What’s Running on That Port? Introducing Nerva for Service Fingerprinting

What’s Running on That Port? Introducing Nerva for Service Fingerprinting

1 month ago 0 1 0 0
Preview
Havoc Professional Release The initial release of the long awaited Havoc Professional and the Kaine-kit is finally here and new team member.

Havoc Professional Finally Released! 🕸️🕷️

I'm excited to finally share the work my team and I have put in over the past year. This is just the beginning of what we have planned.

www.infinitycurve.org/blog/release

1 month ago 5 4 0 0
Preview
Don’t expose yourself in public — let AWS error messages do it for you AWS now reveals public permissions in error messages. Learn how a deny-all session policy exposes which actions would succeed safely.

Hey wake up! New offensive AWS meta just dropped! Thanks to Daniel Grzelak, we now have an effective oracle for determining if resources are publicly exposed without leaving logs. (As an offsec person) LFG!!!

www.plerion.com/blog/dont-ex...

2 months ago 2 2 0 0
Post image

On Apple M3, a Linux KDE plasma desktop under Fedora Asahi Remix is now WORKING! Super excited to share this update and happy to answer any questions! Co-credits to noopwafel and Shiz. :)

2 months ago 412 69 15 11
Advertisement
Preview
On the Coming Industrialisation of Exploit Generation with LLMs Recently I ran an experiment where I built agents on top of Opus 4.5 and GPT-5.2 and then challenged them to write exploits for a zeroday vulnerability in the QuickJS Javascript interpreter. I adde…

We are on the verge of the commoditization of exploitation. Every vuln will functionally have a public PoC available because attackers can generate them in minutes.

The advantage will increasingly belong to organizations that can detect, respond, and contain fast.

sean.heelan.io/2026/01/18/o...

3 months ago 6 2 0 0
Preview
Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8554 | Datadog Security Labs A look at how Kubernetes CVE-2020-8554 works

I've been meaning to write more about "the unpatchable 4", which are a set of Kubernetes CVEs for which there are no patches, you need to mitigate them with configuration or architecture choices.

First up is CVE-2020-8554.

securitylabs.datadoghq.com/articles/unp...

3 months ago 11 6 0 0
Preview
Last Week in Security (LWiS) - 2026-01-12 SmarterMail Pre-auth RCE (@chudyPB + @SinSinology), Claude Code code execution (@ryotkak), VSS create (@RicardoJoseRF ), EDRStartupHinder (@TwoSevenOneT), and more!

SmarterMail Pre-auth RCE (@chudyPB + @SinSinology), Claude Code code execution (@ryotkak), VSS create (@RicardoJoseRF ), EDRStartupHinder (@TwoSevenOneT), and more!

blog.badsectorlabs.com/last-week-in...

3 months ago 1 1 0 0
Preview
Fortinet warns of critical FortiCloud SSO login auth bypass flaws Fortinet has released security updates to address two critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could allow attackers to bypass FortiCloud SSO…

Fortinet warns of critical FortiCloud SSO login auth bypass flaws www.bleepingcomputer.com/news/securit...

4 months ago 0 1 0 0
LOC record - Wikipedia

TIL: On peut mettre des coordonnées GPS dans un record DNS !
en.wikipedia.org/wiki/LOC_rec...

Pour tester ça : on se retrouve à l'adresse une-tasse-de.cafe le 12 & 13 février 😇

4 months ago 8 2 0 1
Preview
Red Team Ops II Gain the knowledge and skills necessary to operate against advanced defences.

The new version of RTO II is finally available to purchase.
www.zeropointsecurity.co.uk/course/red-t...

4 months ago 11 8 1 1
Preview
'Unauthorized' Edit to Ukraine's Frontline Maps Point to Polymarket's War Betting It looks like someone invented a fake Russia advance in Ukraine to manipulate online gambling markets.

So it sure looks like someone invented a fake Russian advance in Ukraine to manipulate the online gambling market Polymarket. Gamblers are making money by betting on the outcomes of battles big and small in the war. Edited map is run by DC-based think tank

www.404media.co/unauthorized...

4 months ago 251 111 12 36
Preview
Pesticides : quand les équipements censés protéger exposent davantage Peu adaptées aux conditions de travail réelles des agriculteurs, les équipements censées les protéger des expositions aux pesticides se révèlent bien souvent inefficaces voire même néfastes.

Un rappel sur la fiction du contrôle des risques que constituent ces équipements pour les agris.

theconversation.com/pesticides-q...

5 months ago 14 6 1 1
Preview
Release 3.1.0 · sensepost/gowitness A new release, this time focussing on performance and various bug fixes! Thanks to all of the contributors! Enjoy! 🎉 New Refactor the chromedp driver, focussing on performance. The new implementat...

Landed a new gowitness release, this time focussing on performance! 🎉 v3.1.0

github.com/sensepost/go...

5 months ago 2 2 0 0
Advertisement
Preview
TOAD Attacks via Entra Guest Invites A new reverse phishing campaign uses Microsoft Entra Guest invites to bypass email filters.

Actual threat intelligence! A few friends and I identified a new reverse phishing campaign leveraging Entra Guest User invitations.

This campaign was newly discovered and corroborated. I recommend reviewing organization email for these invitations.

taggart-tech.com/ent...

5 months ago 5 4 0 1
Preview
Insiders – Now free for everyone - Material for MkDocs We just released 9.7.0 – the final version of Material for MkDocs, which includes all features that were previously exclusive to sponsors

📣 Material for MkDocs Insiders now free for everyone!

With 9.7.0, we release all Insiders features previously exclusive to sponsors! This marks the last version of Material that includes new features, as we now enter maintenance mode.

A thread ⬇ 1/4

squidfunk.github.io/mkdocs-mater...

5 months ago 8 4 2 0

Same, I followed their webinar and now I'm less worried about getting replaced by AI :)

5 months ago 0 0 0 0
Preview
Nano Banana can be prompt engineered for extremely nuanced AI image generation Nano Banana allows 32,768 input tokens and I’m going to try to use them all dammit.

New blog post up: I spent a lot of time researching Nano Banana, Google's new generative AI model, and not only is it substantially better than ChatGPT, it is capable of taking extremely nuanced prompts even thousands of tokens long to generate exactly what you want. minimaxir.com/2025/11/nano...

5 months ago 26 3 0 0

"I did give a heads up to Elastic before publishing this post. They have taken this technique into account and are working on updates to the detection rules to catch this."

"Provided as a Crystal Palace shared library. Format inspired by @rastamouse.me 's LibTP. "

Ground truth security research.

5 months ago 5 2 0 0
Introduction - OWASP Top 10:2025 RC1 OWASP Top 10:2025 RC1

Here we go, new OWASP Web Top 10:

5 months ago 1 2 0 0
Preview
FBI Tries to Unmask Owner of Infamous Archive.is Site The FBI has subpoenaed the domain registrar of archive.today, demanding information about the owner.

The FBI is trying to unmask the owner of infamous archiving site Archive.is, according to a subpoena the site posted. No other information given, the site quietly posted the document a few days ago. FBI telling domain registrar to hand over all sorts of ID'ing info
www.404media.co/fbi-tries-to...

5 months ago 549 278 22 29
Video

Found an XSS but got blocked by the CSP?

https://cspbypass.com has a compiled list of ways to bypass the Content-Security Policy. Check out the video below 👇

6 months ago 8 6 2 0
Advertisement
Parts 136 and 137 of the UK ICO report detail the Costs of Implementation of Active Directory tiering at Capita. Specifically, acknowledging that this Standard of Care requires a complex, potentially costly, and resource-intensive task to meet.

Parts 136 and 137 of the UK ICO report detail the Costs of Implementation of Active Directory tiering at Capita. Specifically, acknowledging that this Standard of Care requires a complex, potentially costly, and resource-intensive task to meet.

Penalty Notice Capita Plc by UK ICO

Detailed breach analysis after 2023 ransomware attack. £14M fine. Which standards of care weren't met?

* Understaffed SOC (1 analyst/shift)
* 58hr SOC response vs. 4.5hr AD takeover
* Failure to implement Active Directory tiering.

ico.org.uk/media2/pv5nh...

6 months ago 3 2 0 1

pagedout.institute ← we've just released Paged Out! zine Issue #7
pagedout.institute/download/Pag... ← direct link
lulu.com/search?page=... ← prints for zine collectors
pagedout.institute/download/Pag... ← issue wallpaper
Enjoy!

Please please please share to spread the news - thank you!

6 months ago 20 17 1 3

I'll unpack a few thoughts on this...

6 months ago 4 1 1 0
Preview
‘I Was a Weird Kid’: Jailhouse Confessions of a Teen Hacker Noah Urban’s role in the notorious Scattered Spider gang was talking people into unwittingly giving criminals access to sensitive computer systems.

A lire, le long récit saisissant de la dérive criminelle de Noah Urban par Bloomberg www.bloomberg.com/news/feature...

6 months ago 1 1 0 0