Command Injection61 Telegram Desktop: one-click account takeover via IPC injection
BeakSec's CVE-2026-107181: Telegram Desktop through 7.2.8 handed clicked links to the running instance over a local socket and never escaped the semicolon…
Command Injection61 BeakSec's CVE-2026-107181: Telegram Desktop through 7.2.8 handed clicked links to the running instance over a local socket and never escaped the semicolon…
AI Agents449 Eddie Zhang / Project Black: Claude refuses an LSASS dumper; DeepSeek builds one EDR still catches; uncensored Qwen 3.8 27B on two…
AI Agents404 Adam Chester’s SpecterOps research on disposable Mythic agents: from a vibe-coded abomination to a two-hour Oracle harness that one-shots stage-0 implants in…
Active Directory366 Hope Walker's SpecterOps sequel to manual LDAP querying: OR parentheses that lie, nested Domain Admins, Kerberoastable SPNs, userAccountControl sticker-math, passwords in schema…
Active Directory301 When BloodHound and PowerView will not load, Active Directory is still a phone book. Hope Walker's SpecterOps lab shows how to query…
Red Team Operations594 BOFScale combines a modified Tailscale daemon, client, and port forwarder running as Beacon Object Files to enable in-memory C2 networking infrastructure through…
Credential Attacks527 From a compromised session, a TPM-backed Windows Hello for Business key can be driven to sign arbitrary data with no PIN or…
Exploit Development495 COFF mixing combines capability code with benign functions and links them as PE-ready COFF objects, eliminating memory-injection IOCs while preserving agent capabilities…
Exploit Development480 R.B.C (g3tsyst3m) builds crudeRAT: a minimal Python C2 implant using QUIC (RFC 9000) as its transport. Starting from an unprivileged shell, the…
EDR Evasion483 klezVirus introduces frame swapping — a technique that hides Windows callback frames from EDR call-stack inspectors while preserving return value recovery. Building…
A walkthrough of how an LLM, wrapped in a tiered build-and-test harness, can take a Mythic C2 agent from a one-paragraph spec…
Credential Attacks364 Windows Sandbox is supposed to be the safe place to open untrusted files — but the .wsb configuration file is parsed by…