Sign in

Bad Sector Labs

@badsectorlabs.com
514 followers 53 following 83 posts

Cybersecurity news, techniques, exploits, and tools every week at blog.badsectorlabs.com 🐘@badsectorlabs@infosec.exchange

PostsRepliesMedia
Bad Sector Labs @badsectorlabs.com · 13/08/2026
The Sunday morning DEF CON hangover is real and the data proves it! We had over 1,000 people sit down at our laptops last weekend, and trained over 2,500 tactics. But traffic was lowest Sunday morning 😅. Thanks to the Red Team Village for having us! (1/2)
111
Bad Sector Labs @badsectorlabs.com · 07/08/2026
At DEF CON and want to customize your badge? Use our web based image transfer (Chrome/Edge only for web serial support) and rock the 🏟️ Ludus logo or upload your own! badge.ludus.cloud We're in the Red Team Village if you want to say hi!
000
Bad Sector Labs @badsectorlabs.com · 07/08/2026
Come learn new "tactics" at the Red Team Village! These are hosted on an offline 🏟️Ludus cluster (3x MS-A2) but if the table is full you can access a cloud hosted version as well (from the conference only for now). Look for the guys w/ village badges to chat Ludus. See you there!
000
Bad Sector Labs @badsectorlabs.com · 19/06/2026
Ludus Feature Friday! The new 2.2.0 release brings "sources" which allow you to easily add blueprints, templates, and roles to your Ludus host. We even converted GOAD to a fully Ludus-native blueprint! Check out the full change log and video here: ludus.cloud/changelog/2....
ludus.cloud
Ludus 2.2.0: Sources — Ludus
Add blueprints, templates, and roles/collections from trusted sources to your Ludus host — shipping with native GOAD, a no-Defender Windows 11 template, and every Bad Sector Labs template and role pre...
010
Reposted by Bad Sector Labs
Raphael Mudge @raphaelmudge.bsky.social · 01/06/2026
Relax and unwind in the Tradecraft Garden aff-wg.org/2026/06/01/r... Celebrating one year of Tradecraft Garden. 40 blog posts. ~30 POCs/projects. A lot of thank you's inside. The release itself: stack unwinding data generation, reference relaxation in the linker, and COFF mixing (+disco baby!)
aff-wg.org
Relax and unwind in the Tradecraft Garden
We’re at the 12th release of Crystal Palace and marking one year in the Tradecraft Garden. This release adds reference relaxation to make global references PIC-friendly. I’ve also added stack unwin…
2148
Bad Sector Labs @badsectorlabs.com · 30/04/2026
CopyFail (CVE-2026-31431) in Go. In case you want to get root from a static binary without Python as a dependency. github.com/badsectorlab...
020
Bad Sector Labs @badsectorlabs.com · 30/03/2026
🏟️❤️🤖 Ludus MCP/Skills (@badsectorlabs), Grapefruit 📱 security suite (@CodeColorist), 2 Citrix NetScaler posts (@AlizTheHax0r + @_mccaulay), 🔒 BIOS bypass (@craigsblackie), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2026-03-30
🏟️❤️🤖 Ludus MCP/Skills (@badsectorlabs), Grapefruit 📱 security suite (@CodeColorist), 2 Citrix NetScaler posts (@AlizTheHax0r + @_mccaulay), 🔒 BIOS bypass (@craigsblackie), and more!
000
Bad Sector Labs @badsectorlabs.com · 25/03/2026
The FCC bans all new foreign routers, Delve was a compliance as a service scam, ForceHound, VMKatz, and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2026-03-24
The FCC bans all new foreign routers, Delve was a compliance as a service scam, ForceHound, VMKatz, and more!
000
Bad Sector Labs @badsectorlabs.com · 16/03/2026
🏟️ Ludus launched 2 years ago and the community embraced and extended it with write-ups, roles, configs, and environments. We're excited to see what you build with Ludus 2! (1/4)
110
Bad Sector Labs @badsectorlabs.com · 10/03/2026
Ludus 2 (@badsectorlabs), new GOAD lab (@M4yFly), 🍪 hack (@XeEaton), DPAPI + Nemesis (@harmj0y + @tifkin_), iOS exploit kit found (@Mandiant), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2026-03-09
Ludus 2 (@badsectorlabs), new GOAD lab (@M4yFly), 🍪 hack (@XeEaton), DPAPI + Nemesis (@harmj0y + @tifkin_), iOS exploit kit found (@Mandiant), and more!
000
Bad Sector Labs @badsectorlabs.com · 05/03/2026
We try hard to do this with Ludus. We've gotten huge value from the Ludus Discord and watching what people struggle with or have to fight to get to work and that makes us try to solve that issue in Ludus itself. It's a balance of not adding every little feature though, so there is art to it.
120
Reposted by Bad Sector Labs
Raphael Mudge @raphaelmudge.bsky.social · 04/03/2026
A Scalpel, A Hammer, and a Foot Gun aff-wg.org/2026/03/03/a...
aff-wg.org
A scalpel, a hammer, and a foot gun
Last month, I released a Yara signature generator for Crystal Palace. AKA, an invariant content observation tool. I then used the feature to document the physics of various content-signature parame…
053
Bad Sector Labs @badsectorlabs.com · 03/03/2026
SolarWinds RCE (@chudyPB), Windows 11 Recall-based LPE (@filip_dragovic), Robot RCEs (@olivier_boschko + @ruikai), EDR as a RAT (@p0w1_), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2026-03-02
SolarWinds RCE (@chudyPB), Windows 11 Recall-based LPE (@filip_dragovic), Robot RCEs (@olivier_boschko + @ruikai), EDR as a RAT (@p0w1_), and more!
000
Bad Sector Labs @badsectorlabs.com · 24/02/2026
Firefox RCE (@kqx_io), Havoc Professional (@C5pider + @0xC4RN4GE + @avx128), afd.sys UAF (@Dark_Puzzle + @Bad_Jubies), macOS JIT abuse (@kyleavery), AEMonitor (@__pberba__), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2026-02-23
Firefox RCE (@kqx_io), Havoc Professional (@C5pider + @0xC4RN4GE + @avx128), afd.sys UAF (@Dark_Puzzle + @Bad_Jubies), macOS JIT abuse (@kyleavery), AEMonitor (@__pberba__), and more!
000
Bad Sector Labs @badsectorlabs.com · 17/02/2026
SharePoint enumeration (@matthiasdeeg), LNK "0days" (@Wietze), AMD driver LPE (@Bad_Jubies), POSTing to superadmin (@XeEaton), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2026-02-16
SharePoint enumeration (@matthiasdeeg), LNK
021
Bad Sector Labs @badsectorlabs.com · 10/02/2026
"Negative-day" discovery (@spaceraccoonsec), Exploit gen with LLMs (@seanhn), Harmony LPE (@johnnyspandex + @buffaloverflow), NetSupport Manager RCE (@0xor_solo), Azure blob C2 (@KingOfTheNOPs + @senderend) and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2026-02-09
001
Bad Sector Labs @badsectorlabs.com · 13/01/2026
SmarterMail Pre-auth RCE (@chudyPB + @SinSinology), Claude Code code execution (@ryotkak), VSS create (@RicardoJoseRF ), EDRStartupHinder (@TwoSevenOneT), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2026-01-12
SmarterMail Pre-auth RCE (@chudyPB + @SinSinology), Claude Code code execution (@ryotkak), VSS create (@RicardoJoseRF ), EDRStartupHinder (@TwoSevenOneT), and more!
011
Bad Sector Labs @badsectorlabs.com · 06/01/2026
Start your 2026 off with 3 weeks of news, techniques, write-ups, and exploits! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2026-01-05
Windows ARM64 internals (@33y0re), VEH^2 PoC (@0xfluxsec), macOS 26 TCC bypass (@patch1t), BOFs with Crystal Palace (@_RastaMouse), Flare-On 2025 write-ups (@washi_dev), and more!
020
Bad Sector Labs @badsectorlabs.com · 16/12/2025
We published 44 editions of Last Week in Security in 2025, the best free technical cybersecurity newsletter. We sifted through the noise (without AI!) to deliver: 📰 179 News Stories 🧠 407 Techniques & Write-ups 🛠️ 438 Tools & Exploits 👀 51 New X Accounts & 37 New Blogs followed
130
Bad Sector Labs @badsectorlabs.com · 09/12/2025
SCOM lab (@synzack21), WatchGuard RCE (@_mccaulay), Clickjacking with SVGs (@rebane2001), macOS LPE (@theevilbit), a new private phone company (@nickcalyx + @phreeli), Proxmox tradecraft (@ZephrFish) and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-12-08
SCOM lab (@synzack21), WatchGuard RCE (@_mccaulay), Clickjacking with SVGs (@rebane2001), macOS LPE (@theevilbit), a new private phone company (@nickcalyx + @phreeli), Proxmox tradecraft (@ZephrFish) ...
000
Reposted by Bad Sector Labs
SpecterOps @specterops.io · 09/12/2025
SCOM is one of the most deployed, but least researched, System Center products. Zach Stein breaks down how it works + how to build a lab to test new tradecraft. ghst.ly/3Ymzfcw
ghst.ly
Git SCOMmit - Putting the Ops in OpsMgr - SpecterOps
Yet another System Center Ludus configuration for your collection. https://github.com/Synzack/ludus_scom
151
Bad Sector Labs @badsectorlabs.com · 11/11/2025
Apple's sourcemaps takedown (@moeruri), Call stack sig bypass (@saerxcit), AD Site pwnage (@croco_byte), sneaky remap (@MagisterQuis), Deceptiq launch (@deceptiq_), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-11-10
Apple's sourcemaps takedown (@moeruri), Call stack sig bypass (@saerxcit), AD Site pwnage (@croco_byte), sneaky remap (@MagisterQuis), Deceptiq launch (@deceptiq_), and more!
010
Bad Sector Labs @badsectorlabs.com · 07/10/2025
WriteAccountRestrictions fun (@unsigned_sh0rt), RCE in Dell UnityVSA (@SinSinology), Unity Runtime exploit (@ryotkak), Lenovo DCC LPE (@0x4d5aC), remote control over generators (@XeEaton), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-10-06
WriteAccountRestrictions fun (@unsigned_sh0rt), RCE in Dell UnityVSA (@SinSinology), Unity Runtime exploit (@ryotkak), Lenovo DCC LPE (@0x4d5aC), remote control over generators (@XeEaton), and more!
020
Bad Sector Labs @badsectorlabs.com · 16/09/2025
FreeBPX RCE (@chudyPB), badpie (@dtmsecurity), macOS auditd malloc woes (@jfmeee), Spotlight TCC leak (@patrickwardle), WSUS relaying (@Coontzy1), pyLDAPGui (@ZephrFish), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-09-15
FreeBPX RCE (@chudyPB), badpie (@dtmsecurity), macOS auditd malloc woes (@jfmeee), Spotlight TCC leak (@patrickwardle), WSUS relaying (@Coontzy1), pyLDAPGui (@ZephrFish), and more!
020
Bad Sector Labs @badsectorlabs.com · 09/09/2025
Sure, a bunch of NPM packages got backdoor'd (again), but don't miss the great research and tools released last week! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-09-08
Metamorphic compilation (@tijme), Windows Secure Calls (@33y0re), macOS race condition exploit (@patch1t), NTLM relaying (@elad_shamir), iOS zero-click RE (@quarkslab), and more!
000
Bad Sector Labs @badsectorlabs.com · 26/08/2025
Lots of tooling around the new Bloodhound "OpenGraph" standard this week including vCenterHound from @m0rd4vid and the bhopengraph library from @podalirius_. blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-08-25
WebClient deep dive (@0xthirteen), 2x RCE chains in Commvault (@chudyPB), how to rob a hotel (@dmcxblue), MSI patch/protocol handler RCE (@johnnyspandex), self-relaying (@_logangoins), and more!
020
Bad Sector Labs @badsectorlabs.com · 19/08/2025
DEF CON releases, PDQ SmartDeploy creds (@unsigned_sh0rt), FortiSIEM root command injection (@SinSinology), a cat themed loader (@vxunderground), fine-tune LLMs for offsec (@kyleavery_), juicing NTDS.DIT (@MGrafnetter), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-08-18
DEF CON releases, PDQ SmartDeploy creds (@unsigned_sh0rt), FortiSIEM root command injection (@SinSinology), a cat themed loader (@vxunderground), fine-tune LLMs for offsec (@kyleavery_), juicing NTDS....
131
Bad Sector Labs @badsectorlabs.com · 08/08/2025
Come see a preview of the new Web UI for 🏟️Ludus at the Embedded Systems Village. Our mini-workshop walks you through deploying a range and then hacking an emulated IP camera.
010
Bad Sector Labs @badsectorlabs.com · 07/08/2025
In Vegas for hacker summer camp and trying to get food without breaking the bank? I vibed a simple map site: defconfood.badsectorlabs.com Come see Ludus at the embedded Systems Village - hack an IP camera, see the new UI, and get a sticker!
defconfood.badsectorlabs.com
DEF CON Las Vegas Food Map
031
Bad Sector Labs @badsectorlabs.com · 05/08/2025
Last LWIS before DEF CON. Come see us in the Embedded Systems Village where we have a mini-workshop hosting an emulated camera on Ludus for you to hack! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-08-04
AEM RCE (@infosec_au), Intune cert abuse (@_dirkjan), Entra tradecraft (@hotnops), LLMs for R&D (@kyleavery_), File System API research (@Print3M_), and more!
012
Bad Sector Labs @badsectorlabs.com · 29/07/2025
VMware Tools LPE (@justbronzebee), Adaptix C2 0.7 (@hacker_ralf), Ludus MCP (@__Mastadon), SOAP(y) (@_logangoins), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-07-28
VMware Tools LPE (@justbronzebee), Adaptix C2 0.7 (@hacker_ralf), Ludus MCP (@__Mastadon), SOAP(y) (@_logangoins), and more!
022
Bad Sector Labs @badsectorlabs.com · 22/07/2025
PIC agents (@_RastaMouse), ToolShell, Async BOFs (@Cneelis), SCCM MP relays (@unsigned_sh0rt), RAITrigger (@ShitSecure), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-07-21
PIC agents (@_RastaMouse), ToolShell, Async BOFs (@Cneelis), SCCM MP relays (@unsigned_sh0rt), RAITrigger (@ShitSecure), and more!
021
Bad Sector Labs @badsectorlabs.com · 15/07/2025
LudusHound (@bagelByt3s), SpeechRuntimeMove (@ShitSecure), Havoc Pro (@C5pider), FortiWeb RCE (@SinSinology), SailPoint IQService RCE (@NetSPI), Altiris RCE (@lefterispan), WAF bypass (@nyxgeek), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-07-14
LudusHound (@bagelByt3s), SpeechRuntimeMove (@ShitSecure), Havoc Pro (@C5pider), FortiWeb RCE (@SinSinology), SailPoint IQService RCE (@NetSPI), Altiris RCE (@lefterispan), WAF bypass (@nyxgeek ), and...
030
Bad Sector Labs @badsectorlabs.com · 14/07/2025
Ludushound shows the power of community driven innovation in cybersecurity. @bagelByt3s created an awesome tool to convert bloodhound data into a working lab in 🏟️ Ludus. Replicate complex live environments with automation - and get back to the fun stuff! specterops.io/blog/2025/07...
specterops.io
LudusHound: Raising BloodHound Attack Paths to Life - SpecterOps
LudusHound is a tool for red and blue teams that transforms BloodHound data into a fully functional, Active Directory replica environment via the Ludus framework for controlled testing.
031
Bad Sector Labs @badsectorlabs.com · 08/07/2025
Lots of good write ups (like Citrix Bleed 2) but my favorite was seeing how 🏟️ Ludus.cloud helped Cameron Stish of Guidepoint Security find "LoopyTicket" (CVE-2025-33073). blog.badsectorlabs.com/last-week-in...
ludus.cloud
Ludus
The easiest way to deploy testing infrastructure
030
Bad Sector Labs @badsectorlabs.com · 01/07/2025
Tons of great content released over the past few weeks. Get caught up with Last Week in Security! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-06-30
Linux sleep obfs (@k0zmer), sudo vuln (@0xm1rch), self-xss trick (@slonser_), primitive injection (@trickster012), Sitecore RCE (@chudyPB ), and more!
020
Bad Sector Labs @badsectorlabs.com · 10/06/2025
This week's edition is packed full of great techniques and tools! One of the longest posts we've done; there's so much cool stuff being released. blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-06-09
Windows self-delete on 24H2 (@TKYNSEC), DNS rebinding (@yarlob), VSCode backdoor (@d1rkmtr), leak Google users' 📞# (@brutecat), Entra sync dumping (@hotnops), Delegations (@podalirius_), Chrome abuse ...
021
Bad Sector Labs @badsectorlabs.com · 09/06/2025
@raphaelmudge.bsky.social summed up why we built and released Ludus open source: "Develop technologies that give individual operators and researchers LEVERAGE acting on hypothesis and make it fast to try things, adapt, and modify." When spinning up ADCS or SCCM is 3 commands, it gives you leverage.
010
Bad Sector Labs @badsectorlabs.com · 06/06/2025
Want to learn pivoting this weekend? The 🏟️Ludus community created a Pivot Lab with 11 different pivoting tools! Check it out: docs.ludus.cloud/docs/environ...
042
Bad Sector Labs @badsectorlabs.com · 02/06/2025
Stealth syscalls (@darkrelaylabs), VM introspection (@memn0ps), Marebackup LPE (@itm4n.bsky.social), Azure Arc C2 (@zephrfish.yxz.red), Obfusk8 (@x86byte), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-06-02
Stealth syscalls (@darkrelaylabs), VM introspection (@memn0ps), Marebackup LPE (@itm4n), Azure Arc C2 (@ZephrFish), Obfusk8 (@x86byte), and more!
120
Bad Sector Labs @badsectorlabs.com · 28/05/2025
BadSuccessor (@YuG0rd), o3 finds SMB 0day (@seanhn), crashing defender (@InfoGuard_Labs), MDT looting (@Oddvarmoe), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-05-27
BadSuccessor (@YuG0rd), o3 finds SMB 0day (@seanhn), crashing defender (@InfoGuard_Labs), MDT looting (@Oddvarmoe), and more!
020
Bad Sector Labs @badsectorlabs.com · 21/05/2025
MATCH (c1:Computer)-[:MemberOf*1..]->(g:Group) WHERE g.objectsid ENDS WITH '-516' WITH COLLECT(c1[.]name) AS dcs MATCH (c2:Computer) WHERE c2.enabled = true AND (c2.operatingsystem contains '2025') AND (c2[.]name IN dcs) RETURN c2[.]name If this query hits, you're DA: www.akamai.com/blog/securit...
akamai.com
042
Bad Sector Labs @badsectorlabs.com · 19/05/2025
Certipy 5 (@ly4k_), MobileIron pwnage (@chudyPB), new CRTO pricing (@_ZeroPointSec), Volatility 3 parity (@volatility), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-05-19
Certipy 5 (@ly4k_), MobileIron pwnage (@chudyPB), new CRTO pricing (@_ZeroPointSec), Volatility 3 parity (@volatility), and more!
050
Bad Sector Labs @badsectorlabs.com · 15/05/2025
Cobalt Strike for free!? Adaptix C2 (@hacker_ralf) is the best open source C2 I've used since Havoc (@C5pider). Adaptix has SOCKS5, remote and local port forwards, and BOF support! Now it's easy to install the server and client, especially on 🏟️Ludus with our new role: github.com/badsectorlab...
161
Bad Sector Labs @badsectorlabs.com · 13/05/2025
SysAid RCE (@SinSinology + @watchtowrcyber), defendnot (@es3n1n), iOS widget hacks (@brycebostwick.bsky.social), Sword of Secrets (@GiliYankovitch), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-05-12
SysAid RCE (@SinSinology + @watchtowrcyber), defendnot (@es3n1n), iOS widget hacks (@brycebostwick1), Sword of Secrets (@GiliYankovitch), and more!
020
Bad Sector Labs @badsectorlabs.com · 08/05/2025
The Ludus range config can get complex - lots of features == lots of options, but VSCode (and Cursor/Windsurf) can help if you add: # yaml-language-server: $schema=https://docs.ludus.cloud/schemas/range-config.json to the top of a yaml, the editor will highlight and explain errors! 🤯
000
Bad Sector Labs @badsectorlabs.com · 06/05/2025
ProxyBlobing (@_atsika), SonicWall n-days (@SinSinology), Drag and Pwnd (@d4d89704243), Loki C2 2.0 (@0xBoku), GraphSpy 1.5.0 (@RedByte1337), and more! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-05-05
ProxyBlobing (@_atsika), SonicWall n-days (@SinSinology), Drag and Pwnd (@d4d89704243), Loki C2 2.0 (@0xBoku), GraphSpy 1.5.0 (@RedByte1337), and more!
020
Bad Sector Labs @badsectorlabs.com · 02/05/2025
Got my hands on an unreleased Google DeepMind AI workstation! 🧠💻 jk, but the new 🏟️Ludus 🚫🏖️Anti-Sandbox update allows for full customization of machine values. Make your machines look like whatever you (or your APTs) expect. docs.ludus.cloud/docs/enterpr...
000
Bad Sector Labs @badsectorlabs.com · 29/04/2025
Survive the RSA noise by focusing on the technical, with Last Week in Security! blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-04-28
TTTracer unmasks sleep obfs (@felixm_pw), GitHub spoofing (@pfiatde), Synology RCE (@ret2systems), netify scraper (@Jhaddix), and more!
020
Bad Sector Labs @badsectorlabs.com · 22/04/2025
Go beyond the CVE drama; lots of good technical content from last week: blog.badsectorlabs.com/last-week-in...
blog.badsectorlabs.com
Last Week in Security (LWiS) - 2025-04-21
CVE drama (@MITREcorp), Control Flow Hijacking w/Data Pointers (@0xLegacyy), Copilot in notepad (@zux0x3a), .NET AOT in Ghidra (@washi_dev), CSWSH in 2025 (@IncludeSecurity), 300ms to Admin (@compasss...
031