Sign in

droner.bsky.social

@droner.bsky.social
136 followers 205 following 25 posts

researcher. exploit dev. pdx. hacking @ atredis dronesec.net

PostsRepliesMedia
Reposted by @droner.bsky.social
buherator @buherator.bsky.social · 21/09/2026
[RSS] Windows Exploitation Techniques: Dangling COM Object Registrations projectzero.google -> Original->
021
Reposted by @droner.bsky.social
Atredis Partners @atredispartners.bsky.social · 18/09/2026
Atredian Matt Burch (@emptynebuli.bsky.social) will be presenting his ATM supply chain research and demonstrating new exploitation tooling at #GrrCon! 📅 Friday, Sept 25 @ Noon 🔗 Abstract: buff.ly/GvZm49g
023
Reposted by @droner.bsky.social
BSidesPDX @bsidespdx.bsky.social · 16/09/2026
⏳ CFP DEADLINE: September 25th! Got a talk, breakdown, or project you want to share with the community? Don't wait until the final hour. First-time and experienced speakers are equally welcome. Submit your proposal here: cfp.bsidespdx.org/bsidespdx-2026 #InfoSec #CyberSecurity #CFP
032
Reposted by @droner.bsky.social
Stephen Fewer @stephenfewer.bsky.social · 10/09/2026
New (draft) @metasploit-r7.bsky.social exploit module in the queue for the latest N-able N-central unauth RCE, CVE-2026-86218. Already being exploit in-the-wild, was disclosed five day ago, added to KEV two days ago. github.com/rapid7/metas...
Metasploit exploit module for N-able N-central unauthenticated RCE (CVE-2026-86218)
021
Reposted by @droner.bsky.social
Stephen Fewer @stephenfewer.bsky.social · 08/09/2026
While researching last months N-able N-central exploit (CVE-2026-18577, on KEV), we found and reported a new authentication bypass chain (CVE-2026-86206 and CVE-2026-86207). Patched and disclosed by the vendor over the weekend, full details on the @rapid7.com blog: www.rapid7.com/blog/post/ve...
rapid7.com
Rapid7
While conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central....
011
Reposted by @droner.bsky.social
Natalie Silvanovich @natashenka.bsky.social · 08/09/2026
Today, Project Zero is releasing MAccConc, a tool by Jann Horn that enables deterministic testing of race conditions on Linux. It can be used for fuzzing, ad-hoc exploration, regression tests and more! projectzero.google/2026/09/macc...
projectzero.google
Testing race conditions with memory access tracing and stack-based delay injection
Many security bugs are race conditions, where multi-threaded execution has to occur with the righ...
1101
Reposted by @droner.bsky.social
Binary Ninja @binary.ninja · 08/09/2026
RE//verse 2027 tickets are LIVE! Trainings too! Round 1 is the cheapest pricing we’ll offer, so grab your ticket before they sell out. See you in Orlando: re-verse.io
re-verse.io
RE//verse - Reverse Engineering Conference
RE//verse is a premier reverse engineering, vulnerability research, and malware analysis conference. More info on the next event coming soon.
013
Reposted by @droner.bsky.social
BleepingComputer @bleepingcomputer.com · 08/09/2026
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.
bleepingcomputer.com
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.
275
Reposted by @droner.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 01/09/2026
After HardBrEacher, a zero-day in the Kaspersky EDR, Nightmare Eclipse has also published zero-days in Nvidia drivers (GreenSection) and the Avast antivirus (PrettyPrague) github.com/MSNightmare/... github.com/MSNightmare/... github.com/MSNightmare/...
github.com
GitHub - MSNightmare/HardBreacher: Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability
Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability - MSNightmare/HardBreacher
098
Reposted by @droner.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 03/09/2026
Another one... FalconFlank in CrowdStrike github.com/MSNightmare/...
0138
Reposted by @droner.bsky.social
Winnona @winnona.bsky.social · 30/08/2026
Mark your calendars!! @districtcon.bsky.social tickets sold out in 10 seconds last year…
011
Reposted by @droner.bsky.social
DistrictCon @districtcon.bsky.social · 21/08/2026
OUR CALL FOR PAPERS IS OFFICIALLY OPEN! We want to see all of your hacking magic, informing policy, or roundtable idea submissions. For more ideas, you can check out our page or submit directly! sessionize.com/districtcon www.districtcon.org/cfp
068
Reposted by @droner.bsky.social
MatrixMantis @matrixmantis.bsky.social · 12/08/2026
this.weekinsecurity.com/microsoft-wi... This is what you get when you're a bad citizen: 0-days
this.weekinsecurity.com
Microsoft wins 'lamest vendor' at Pwnie Awards 2026 for threatening security researchers with legal action
"This is a shame award. Don't forget to feel that shame."
12510
Reposted by @droner.bsky.social
TrendAI Zero Day Initiative @thezdi.bsky.social · 11/08/2026
Happy Patch Tuesday! It's a smaller release for #Adobe, but another huge one from #Microsoft in what may be the new normal. @dustinchilds.bsky.social breaks it all down for you at www.zerodayinitiative.com/blog/2026/8/...
zerodayinitiative.com
Zero Day Initiative — The August 2026 Security Update Review
I’ve successfully survived Hacker Summer Camp, and I have returned with a new outlook on patch density. When even Linus Torvalds says that huge updates are the “ new normal ”, it’s time to readjust wh...
141
Reposted by @droner.bsky.social
Barry Dorrans @blowdart.me · 11/08/2026
It's Patch Tuesday, and you know what that means ... FREE SOFTWARE FROM Microsoft. .NET this month has 10 CVEs this month. So, let's break them down in no particular order... (because I usually miss one and add it out of order) #dotnet #patchTuesday
11810
Reposted by @droner.bsky.social
buherator @buherator.bsky.social · 08/08/2026
It's time to time-travel debug a fuzzer! How's your Saturday going? Original->
021
Reposted by @droner.bsky.social
Stephen Fewer @stephenfewer.bsky.social · 28/07/2026
We have published our @rapid7.com analysis of CVE-2026-16232, the auth bypass in Check Point Security Management Server that was disclosed last week as a zero-day exploited in-the-wild. Full details and PoC: www.rapid7.com/blog/post/ra...
112
Reposted by @droner.bsky.social
Atredis Partners @atredispartners.bsky.social · 28/07/2026
Next week at @blackhatofficial.bsky.social, join Matt Burch (@emptynebuli.bsky.social) as he dives into the ATM supply chain. If you are attending Black Hat, add this to your schedule! 📅 AUG 5 at 2:35 PM 📍 South Seas C&D, Level 3 #BHUSA2026 #Cybersecurity #InfoSec #BlackHat
blackhat.com
Black Hat USA 2026
Black Hat USA 2026
012
Reposted by @droner.bsky.social
buherator @buherator.bsky.social · 28/07/2026
Apple MIE exploitation challenge blog.calif.io -> "In this blog, we'll share the details of the two vulnerabilities behind our [MIE bypassing] exploit" Original->
012
Reposted by @droner.bsky.social
TrendAI Zero Day Initiative @thezdi.bsky.social · 21/07/2026
#Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at www.zerodayinitiative.com/blog/2026/7/... #P2OIreland
zerodayinitiative.com
Zero Day Initiative — Pwn2Own Ireland 2026 – New Targets and Categories
If you just want to read the rules, you can find them here .   Pwn2Own Ireland returns for 2026, and it’s the third year for this event in the Emerald Isle. Despite the dreary Irish skie...
003
Reposted by @droner.bsky.social
Atredis Partners @atredispartners.bsky.social · 21/07/2026
If you are heading to @defcon.bsky.social this summer, don't miss Atredian Matt Burch (@emptynebuli.bsky.social) and his continued CryptoPro research in Compounding Interest: Exploiting the ATM Supply Chain. See you at Track 4, Saturday Aug 8 at 12:30. defcon.org/html/defcon-...
defcon.org
DEF CON® 34 Hacking Conference - Main Stage Talks
1.1 Million Cameras, One Wildcard: Architectural Surveillance in an IoT Cloud Sammy Azdoufal
003
Reposted by @droner.bsky.social
buherator @buherator.bsky.social · 21/07/2026
Qualys Security Advisory - Local Privilege Escalation in set-capabilities versions of snap-confine (CVE-2026-8933) www.openwall.com -> Original->
001
Reposted by @droner.bsky.social
Tim Blazytko @mrphrazer.bsky.social · 19/06/2026
The slides from our @reconmtl.bsky.social talk with @nicolo.dev on agentic deobfuscation are now online. Topics: commercial VMs, anti-cheat, DRM systems, malware, and anti-agentic obfuscation. Slides: synthesis.to/presentation...
0107
Reposted by @droner.bsky.social
SpecterOps @specterops.io · 15/07/2026
Need to do an NTLM relay over C2 but local priv-esc isn't possible? @logangoins.bsky.social new post walks through relaying NTLM auth out of a network and back in through red team infra to bypass traditional relay controls, plus how defenders actually stop it. Check it out: ghst.ly/4wA3fkg
ghst.ly
There and Back Again: An Operators Guide on NTLM Relaying Egress
012
Reposted by @droner.bsky.social
Microsoft Threat Intelligence @threatintel.microsoft.com · 14/07/2026
The July 2026 security updates are available:
022
Reposted by @droner.bsky.social
Atredis Partners @atredispartners.bsky.social · 13/07/2026
@defcon.bsky.social 32 Matt (@emptynebuli.bsky.social) released 6 CE bugs affecting Diebold Nixdorf.. and now he is back with 9 more via the CryptoPro supply chain! 👀 Come join his #BHUSA briefing on Wednesday August 5th - you won't want to miss it! 🏧 🏦 @blackhatofficial.bsky.social
blackhat.com
Black Hat USA 2026
Black Hat USA 2026
013
Reposted by @droner.bsky.social
Atredis Partners @atredispartners.bsky.social · 10/07/2026
Atredian Matt (@emptynebuli.bsky.social) spoke with @DarkReading.bsky.social about his upcoming @BlackHatofficial.bsky.social talk "The Cost of Obscurity: Exploiting the ATM Supply Chain" 🔒️ 💵 Bottom line: Disk encryption doesn't help if the keys are stored right next to the lock.
darkreading.com
Fresh ATM Crypto Software Bugs: Jackpot or Bust?
Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper.
012
Reposted by @droner.bsky.social
emptynebuli.bsky.social @emptynebuli.bsky.social · 10/07/2026
I recently sat down with @darkreading.bsky.social to discuss my new research into CryptoPro and my @blackhatevents.bsky.social and @defcon.bsky.social talk Exploiting the ATM Supply Chain.. I look forward to catching you this summer 🏧💰
012
droner.bsky.social @droner.bsky.social · 08/07/2026
Am I crazy, is it common for dry runs to be the same week a CFP closes?
000
Reposted by @droner.bsky.social
OffensiveCon @offensivecon.bsky.social · 07/07/2026
CFP for #OffensiveCon26 Tokyo edition is STILL open. We're looking for real, original work: cutting-edge security research, novel exploit techniques and deep technical investigations that actually move the field forward. And yes, AI it's also in the game.
001
Reposted by @droner.bsky.social
buherator @buherator.bsky.social · 03/07/2026
[RSS] Exploring cross-domain & cross-forest RBCD: part 2 www.synacktiv.com -> Original->
001
Reposted by @droner.bsky.social
jstnkndy @jstnkndy.bsky.social · 03/07/2026
Thankfully the program actually knows how to triage bugs (the reopened it and triaged it themselves as a critical and paid it out) and clearly cares about the issues (they've already been fixed). This isn't the first time H1 messed up triage for bugs against this program. Makes you wonder.
021
Reposted by @droner.bsky.social
buherator @buherator.bsky.social · 01/07/2026
[RSS] Charting your way in: Helm template injection www.synacktiv.com -> Original->
001
Reposted by @droner.bsky.social
buherator @buherator.bsky.social · 01/07/2026
[RSS] Reverse-engineering VMware's encrypted + compressed VM memory checkpoint format (vTPM "partial" encryption) github.com -> Original->
012
Reposted by @droner.bsky.social
Hypervisible @hypervisible.blacksky.app · 01/07/2026
“A vulnerability in Apple’s ‘Hide My Email’ tool lets almost anyone discover a person’s real email address that is supposed to be hidden by the feature, and Apple has failed to fix it for more than a year…”
404media.co
Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses
”Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses,” the person who reported the issue said.
617363
Reposted by @droner.bsky.social
Allan “Ransomware Sommelier” Liska @ransomwaresommelier.com · 28/06/2026
There are many incredible journalists in the cybersecurity field and I am very lucky to have worked with a lot of them over the last 10-15 years. I share that to say @zackwhittaker.com is definitely one of my favorites and his reflections on 8 years of writing a newsletter is a must read.
this.weekinsecurity.com
Reflections on eight years of writing ~this week in security~
Your favorite weekly cybersecurity newsletter marks eight years on the web.
1186
Reposted by @droner.bsky.social
buherator @buherator.bsky.social · 08/06/2026
[RSS] Off By !: Exploiting a Use-after-Free in the Linux Kernel blog.exodusintel.com -> Original->
011
Reposted by @droner.bsky.social
Kevin Beaumont @doublepulsar.com · 01/06/2026
Microsoft have walked this back, good: x.com/msftsecrespo...
x.com
0172
Reposted by @droner.bsky.social
OffensiveCon @offensivecon.bsky.social · 01/06/2026
Interested in becoming a speaker at Offensivecon Tokyo? You have three months to submit your talk on an innovative offensive security topic. More information here 👉️ cfp.offensivecon.jp/offensivecon...
001
Reposted by @droner.bsky.social
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 29/05/2026
NEW: Microsoft is so mad that a researcher published a handful of zero-days, and code to exploit them, that it is threatening legal action and even calling the cops on them. Yes, it's 2026, and one of the richest companies in the world is beefing about the ethics of disclosing bugs.
techcrunch.com
Microsoft under fire for threatening security researcher with criminal investigation | TechCrunch
A public spat between Microsoft and an independent security researcher reopens a long-running debate over who is responsible for securing software.
25732
Reposted by @droner.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 28/05/2026
Talks from the OffensiveCon 2026 security conference, which took place earlier this month, are now available on YouTube www.youtube.com/playlist?lis...
youtube.com
OffensiveCon26 - YouTube
OffensiveCon 2026 Talks
084
Reposted by @droner.bsky.social
Richard Johnson @richinseattle.bsky.social · 28/05/2026
Please tell your friends, four weeks before @phrack.org submission deadline! We also are seeking both interior and cover art. We are working with our friends at @pagedout.bsky.social again to create a fancy interior design for our main annual release!! Be a part of hacker history!
065
Reposted by @droner.bsky.social
Kevin Beaumont @doublepulsar.com · 28/05/2026
I've written something about Microsoft's apparent stance that not following made up responsible disclosure frameworks is criminal activity. doublepulsar.com/microsofts-s...
doublepulsar.com
Microsoft’s stance on zero day exploits is a dumpster fire of their own making
Nightmare Eclipse vs Microsoft risks turning into a wildfire of corporate protect over cyber defence.
58627
Reposted by @droner.bsky.social
DistrictCon @districtcon.bsky.social · 28/05/2026
It's basically summer which means you should be thinking about what video games you should be playing. We submit into record Command & Conquer Generals
162
Reposted by @droner.bsky.social
Phrack Zine @phrack.org · 27/05/2026
We're looking for a cover for the next issue of Phrack! Retro sci-fi, terminals, dystopian systems, chrome futures, hacker manuals from an alternate timeline. Make something timeless and strange. Send your work or idea to arts@phrack.org Deadline June 30th
13723
droner.bsky.social @droner.bsky.social · 27/05/2026
This is pretty concerning.
010
Reposted by @droner.bsky.social
Kevin Beaumont @doublepulsar.com · 27/05/2026
Gitlab have also kicked NightmareEclipse off their service. gitlab.com/nightmare-ec... cc @campuscodi.risky.biz
1176
Reposted by @droner.bsky.social
Catalin Cimpanu @campuscodi.risky.biz · 24/05/2026
Microsoft has banned Nightmare Eclipse from GitHub: github.com/Nightmare-Ec... This is the researcher who disclosed several zero-days after Microsoft also deleted his MSRC account They now moved on GitLab: deadeclipse666.blogspot.com
820559
Reposted by @droner.bsky.social
Atredis Partners @atredispartners.bsky.social · 16/05/2026
"Bad News for the Average Pentester" ... But who wants to be average? Here's some thoughts from Shawn on why Human-Powered Pentesting is here to stay. www.atredis.com/blog/2026/5/...
atredis.com
Bad News for the Average Pentester — Atredis Partners
With the changes to the market of late, Atredis has actually been exceedingly busy. We've been working with AI and related tech since we started the company over a dozen years ago, but in the last…
035
Reposted by @droner.bsky.social
buherator @buherator.bsky.social · 15/05/2026
ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass github.com -> Original->
011