Every tool call needs your explicit approval.
Also shipped: AI-enhanced auth in the Website Scanner, tests grouped by port in results, 5 new Sniper exploits, two new API endpoints for scan tests, and refreshed docs.
Full breakdown: pentest-tools.com/change-log
#offensivesecurity #infosec
Online vulnerability scanners - Pentest-Tools.com
Tool sprawl in vulnerability assessment isn't a tool problem. It's a handoff problem.
Web scan. Network scan. API scan. Three exports. Manual cross-referencing. Report assembly that has nothing to do with actual security work.
#offensivesecurity #infosec
3 of 7 steps detected. 4 missed.
Guard walks the kill chain in your environment, then measures what your defenses actually saw. The gap analysis isn't theoretical.
#cybersecurity #offensivesecurity #CISO #MITRE #redteam
Another talk for BSides Luxembourg!
๐ฅ๐ฅ ๐ง๐๐ ๐ช๐๐๐ฆ๐ง๐๐๐ฆ ๐๐ข ๐ช๐ข๐ข ๐ช๐ข๐ข: ๐ฆ๐๐๐ ๐๐๐๐ฅ๐ง๐ฆ, ๐ง๐๐ฅ๐๐๐ง ๐๐๐ง๐๐๐ง๐๐ข๐ก ๐๐ก๐ ๐ง๐จ๐ก๐๐ก๐ ๐จ๐ก๐ก๐๐๐๐ฆ๐ฆ๐๐ฅ๐ฌ ๐ก๐ข๐๐ฆ๐ - ๐ ๐๐๐๐ก๐ ๐ฃ๐๐๐๐๐๐ฃ๐ฆ ( @tx_princess ) ๐ต๏ธโโ๏ธโ๏ธ
Security teams donโt miss alerts because theyโre careless, they miss them because their [โฆ]
[Original post on infosec.exchange]
Default credentials still cause more breaches than zero-days. Most teams don't test for them at scale.
Brutus does. 22 protocols. One binary. Open source.
github.com/praetorian-i...
#TheGuardPlatform #Praetorian #OffensiveSecurity
Matei "Mal" Bฤdฤnoiu and Raul Bledea found the gap. Full PoC can be found in our Offensive Security Research Hub: pentest-tools.com/research
#offensivesecurity #vulnerabilityresearch #infosec #RCE
The cybersecurity certification landscape
negativepid.blog/the...
#defensiveSecurity #threatHunting #forensics #offensiveSecurity #ethicalHacking #cybersecurityCareers #cybersecurityCerts #certifications #Cybersecurity #ITcareers #onlineSecurity #negativepid
How we use AI in Pentest-Tools.com
Skeptical of AI in #offensivesecurity tools? Good. You should be.
The last thing you need is for AI to:
โ Generate synthetic or "hallucinated" vulnerabilities
โ Bypass authorization boundaries, or
โ Autonomously control scanning engines
Breaking into offensive security
negativepid.blog/bre...
#OffSec #offensiveSecurity #ethicalHacking #redTeam #Cybersecurity #cyberattacks #cyberThreats #onlineSecurity #negativepid
The venue was a nice touch too - the Computer History Museum in Ljubljana. Very hackerish energy for a security talk.
Curious how Razvan works in practice? Watch him run a full pentest workflow here: pentest-tools.com/webinars/how...
#offensivesecurity #infosec #cybersecurity #BSides
Razvan Ionescu, our Head of #OffensiveSecurity Services recently gave a heartfelt talk at #BSidesLjubljana. ๐ธ๐ฎ
He shared the steps, mindset, and what actually worked for him in becoming the penetration tester he is today.
๐ CVE-2025-33073 revives NTLM reflection attacks. Any domain user can hit SYSTEM on unpatched hosts without SMB signing.
Chain with unconstrained delegation โ full domain compromise.
www.praetorian.com/blog/cve-202...
#offensivesecurity #activedirectory #theguardplatform #praetorian
Breaking into offensive security
negativepid.blog/bre...
#OffSec #offensiveSecurity #ethicalHacking #redTeam #Cybersecurity #cyberattacks #cyberThreats #onlineSecurity #negativepid
Thatโs how strong security communities grow: through practice, support, and a room for new people to welcome and nurture them.
Good luck to all finalists and bootcamp participants! Make the best of it! ๐
Learn more about UNbreakable Romรขnia: unbreakable.ro
#offensivesecurity #infosec
Just Announced for BSides Luxembourg 2026!
๐ง๐๐ ๐ฆ๐ฃ๐ฌ ๐ช๐๐ข ๐๐ข๐๐๐๐ ๐ ๐ - ๐ช๐๐๐ก ๐ฌ๐ข๐จ๐ฅ ๐ซ๐๐ฅ ๐๐ข๐๐ก๐ฆ ๐ง๐๐ ๐๐ง๐ง๐๐๐๐๐ฅ๐ฆ - Melina Phillips(@tx_princess )
Melina Phillips https://www.linkedin.com/in/melinaphillips-cissp/ is an Offensive Security Engineer with over 10 years of [โฆ]
[Original post on infosec.exchange]
This isnโt theory. This is real phishing ops. ๐ป Learn how real att&ckers craft campaigns, bypass filters, and expl0it human behavior.
๐จ Limited time offer: $49 only: cyberwarfare.live/product/offe...
#Phishing #COPO #OffensiveSecurity #CyberWarFareLabs
Chain it with PTT-2025-026 and you're looking at a 9.8 Critical unauthenticated RCE. One array to rule them all! ๐
Full PoC here: pentest-tools.com/research
#offensivesecurity #vulnerabilityresearch #infosec #accounttakeover
The demo makes one thing very clear: AI can speed up offensive security work, but it can also speed up bad decisions if you skip guardrails.
Need more reasons to keep the human in the loop?
Watch the full talk here: www.youtube.com/watch?v=x3z8...
#offensivesecurity #pentesting #llm #defcamp
Carter Ross from our team walks through what we've actually built, what we've learned, and why most detection stacks weren't designed for this reality.
It's worth the read! โก๏ธ buff.ly/Q6zYuSQ
#Praetorian #OffensiveSecurity #TheGuardPlatform
Open security and OffSec projects
negativepid.blog/ope...
#OpenSource #OffSec #OffensiveSecurity #Cybersecurity #onlineSecurity #Internet #tech #IT #science #STEM #computing #AI #innovation #negativepid
Our colleagues Matei "Mal" Bฤdฤnoiu and Raul Bledea did the digging. Full PoC and exploit is added here: pentest-tools.com/research
#offensivesecurity #vulnerabilityresearch #infosec
HttpOnly blocks document.cookie โ but endpoints reflecting cookies in the response body bypass it entirely. ๐
Our team chained XSS + GhostScript injection for full RCE. No zero-days.
๐ www.praetorian.com/blog/httponl...
#OffensiveSecurity #AppSec #TheGuardPlatform #Praetorian
XBOW secures $120M in Series C at a $1B+ valuation to boost its AI-driven platform that autonomously identifies and validates software vulnerabilities. Funding led by DFJ Growth and Northzone. #OffensiveSecurity #AIPlatform #USA
This Startupโs AI Beat 99% Of Humans In Six Elite Hacking Competitions www.forbes.com/sites... #cybersecurity #AI #AIHacking #OffensiveSecurity #AIAgent #AgenticAI #Tenzai #CTF
Open security and OffSec projects
negativepid.blog/ope...
#OpenSource #OffSec #OffensiveSecurity #Cybersecurity #onlineSecurity #Internet #tech #IT #science #STEM #computing #AI #innovation #negativepid
Unless you have been in a sandbox this week or not been paying attention the team behind Kali Linux dropped version 2025.4 with Ollama Llama 3 and Openwebui support, quick build guide with tests and cool results here! #BrainBytes #OffensiveSecurity #ProjectV
www.brainbytes.info/post/project...
Interested in the dark witchcraft of Windows Kernel Exploitation? Check out our training courses:
www.exploitpack.com/collections/...
#cybersecurity #exploitdevelopment #vulnerabilityresearch #windowskernel #exploitdev #reverseengineering #offensivesecurity #infosec #cyberattack #training
Exciting job opportunity! Replit is hiring an Offensive Security Engineer. This full-time, hybrid role is based in Foster City, CA with a salary range of $188,000 to $313,000 per year. #OffensiveSecurity #JobOffer
It also explains how Pentest-Tools.com validates findings across web, network, API, and cloud so teams spend less time re-checking and more time fixing.
Because more is NOT better. Get more arguments for internal debates from here: pentest-tools.com/usage/accuracy
#infosec #offensivesecurity
Many thanks to Matei Badanoiu, Raul Bledea and Eusebiu Boghici for their contributions.
#offensivesecurity #vulnerabilityresearch #pentesting #infosec
Out of curiosity: how often do you still run into 10+ year-old libraries during engagements?