Sign in

idle

@idlewog.bsky.social
68 followers 156 following 13 posts

Doing stuff in #cybersec i suppose ... #CTF 1dl3 for mushd00m

PostsRepliesMedia
Reposted by idle
William Blanc @hmedievaliste.bsky.social · 28/09/2026
Bon, j’ai regardé le spectacle « historique » donné au Stade de France à l’occasion de la visite du pape. Réaction et analyse d’un show qui développe une vision fantasmée et délirante de l’histoire de France et du catholicisme 1/
19432300
Reposted by idle
Renaud Lifchitz ⠵ @nono2357.bsky.social · 01/10/2026
Cybermois 2026 : la CNIL et Cybermalveillance.gouv.fr publient une nouvelle ressource pour adopter les bons réflexes face à une violation de données
cnil.fr
Cybermois 2026 : la CNIL et Cybermalveillance.gouv.fr publient une nouvelle ressource pour adopter les bons réflexes face à une violation de données
Violation de données personnelles : que faire en 3 étapes clés ? Face à la multiplication des violations de données personnelles et à la nécessité de mieux sensibiliser le public, Cybermalveillance.gouv.fr et la CNIL proposent un nouveau support pratique : « Violation de données personnelles, que fa
001
Reposted by idle
Renaud Lifchitz ⠵ @nono2357.bsky.social · 30/09/2026
L'Anssi et la Dinum victimes à leur tour d'une fuite de données: les deux agences dédiées à la cybersécurité ont été compromises
bfmtv.com
L'Anssi et la Dinum victimes à leur tour d'une fuite de données: les deux agences dédiées à la cybersécurité ont été compromises
Une centaine de comptes utilisateurs, liée au piratage de Metabase, a été concernée par une compromission. À la clé, des données de connexion désormais dans la nature. Mais des "mesures de sécurisation" ont été prises.
001
Reposted by idle
buherator @buherator.bsky.social · 28/09/2026
It's that time of the year again... Original->
Alt text TBD, sorry!
001
Reposted by idle
Renaud Lifchitz ⠵ @nono2357.bsky.social · 28/09/2026
Il combine un Galaxy S24+ et cinq ordinateurs pour faire tourner la plus grosse IA d'OpenAI
frandroid.com
Il combine un Galaxy S24+ et cinq ordinateurs pour faire tourner la plus grosse IA d'OpenAI
Un utilisateur de Reddit a fait tourner gpt-oss-120b, le plus gros modèle ouvert d'OpenAI, en le découpant entre six appareils, dont un Samsung Galaxy S24+
001
Reposted by idle
Renaud Lifchitz ⠵ @nono2357.bsky.social · 29/09/2026
Curated list of open-weight uncensored models for authorized red team operations, penetration testing, and security research.
github.com
GitHub - JoasASantos/Offensive-Security-AI-Models: Uncensored AI models or those fine-tuned for cybersecurity tasks.
Uncensored AI models or those fine-tuned for cybersecurity tasks. - JoasASantos/Offensive-Security-AI-Models
011
Reposted by idle
r1cksec @r1cksec.bsky.social · 28/09/2026
A single-pass Active Directory enumerator for an anonymous (null) session, using the \samr and \lsarpc named pipes. No credentials required. github.com/crypt0p3g/ad... #infosec #cybersecurity #redteam #pentest #opensource
github.com
GitHub - crypt0p3g/adnullenum: One-pass anonymous Active Directory enumeration over SAMR and LSARPC — null session, no credentials, with structured reusable output.
One-pass anonymous Active Directory enumeration over SAMR and LSARPC — null session, no credentials, with structured reusable output. - crypt0p3g/adnullenum
001
Reposted by idle
r1cksec @r1cksec.bsky.social · 28/09/2026
InjectSetConsole performs process code injection by leveraging a Windows named pipe. github.com/TwoSevenOneT... #infosec #cybersecurity #redteam #pentest
github.com
GitHub - TwoSevenOneT/InjectSetConsole: Proof of Concept for Process Code Injection Without Using WriteProcessMemory
Proof of Concept for Process Code Injection Without Using WriteProcessMemory - TwoSevenOneT/InjectSetConsole
011
Reposted by idle
Léαlinux 🐧 @lea-linux.org · 26/09/2026
curves.xargs.org Curvy !
curves.xargs.org
The Animated Elliptic Curve
Visualize elliptic curve cryptography with animated examples
022
Reposted by idle
Ange @angealbertini.bsky.social · 25/09/2026
Any Amiga fan out there ? I’m looking for an older and rare version of a 1989 game - or the earliest Whdload version of it, that I can’t find (only mentions). (For a large full recomp project)
102
Reposted by idle
Ange @angealbertini.bsky.social · 25/09/2026
Recreating the original hardware protection media, conversion and restoration of all assets, uncovering undocumented quirks, bugs and cheat codes… And creating the “best version ever”, of course ;)
001
Reposted by idle
Nidouille @nidouille.bsky.social · 24/09/2026
Je découvre l'entreprise française RIBER, qui est un leader mondial ; c'est, en quelque sorte, notre ASML. ROSIE a été faite en partenariat avec le NQCP (ovo Nordisk Foundation Quantum Computing Programme de l'université de Copenhague). L'entreprise a été fondée en 1964.
1107
Reposted by idle
Renaud Lifchitz ⠵ @nono2357.bsky.social · 25/09/2026
97 % des victimes de ransomware avaient le MFA : où sont les angles morts ?
it-connect.fr
97 % des victimes de ransomware avaient le MFA : où sont les angles morts ?
97 % des victimes de ransomware par vol d'identifiants avaient activé le MFA. Voici comment repérer les accès restés en mot de passe seul et les combler.
002
Reposted by idle
Internet Archive @archive.org · 25/09/2026
🤘🌐 “Everybody! Everybody!” Homestar Runner has barely changed! Launched in 2000, the beloved web cartoon site has kept its decidedly retro look, so today’s homepage could easily be mistaken for a page from the Flash era. Explore web history with the Wayback Machine ➡️ web.archive.org
Image with text at the top that reads: "Wayback Machine Then and Now" then "HOMESTARRUNNER.COM". Below are Wayback Machine captures of the Homestar Runner web page from October 15, 2000, and September 13, 2026.
11622160
Reposted by idle
Renaud Lifchitz ⠵ @nono2357.bsky.social · 25/09/2026
[NixOS] Every package is already installed!
fzakaria.com
Every package is already installed
tl;dr; omnibin is a FUSE filesystem that puts every binary nixpkgs ever shipped on your $PATH. Nothing is installed. Nothing needs building. 0 bytes on disk until something actually reads a file. 😈 It’s 2026, why am I still installing packages individually?1 Why must I go through the ritual of addin
021
Reposted by idle
Alexis "Horgix" Chotard @horgix.fr · 24/09/2026
Always a pleasure to see @juhnny5.bsky.social on stage :) Explaining today at #PlatformCom how the Restos du Coeur built their own AI tooling from refurbished hardware & open source ❤️ vLLM & Envoy AI Gateway helping a long way on top of other Cloud du Coeur nase blocks, up to LibreChat and more!
064
Reposted by idle
Emile `iMIl' Heitor @imil.net · 24/09/2026
Virtio-nvgpu: Near-native Nvidia GPU access inside a KVM guest github.com/nestrilabs/v... from Hacker News via #gcufeed@libera.chat / gcu.info/gruik/
github.com
GitHub - nestrilabs/virtio-nvgpu: [Experimental] A virtio device for near-native NVIDIA GPU access in KVM virtual machines.
[Experimental] A virtio device for near-native NVIDIA GPU access in KVM virtual machines. - nestrilabs/virtio-nvgpu
2104
Reposted by idle
Liam @ GamingOnLinux @gamingonlinux.com · 24/09/2026
Qualcomm announce Snapdragon X2 Series will support Linux #Linux #Snapdragon #Qualcomm #Arm
gamingonlinux.com
Qualcomm announce Snapdragon X2 Series will support Linux
Arm support is expanding on Linux, with Qualcomm announcing Linux support for the Snapdragon X2 Series.
1573
Reposted by idle
ANSSI @anssi-fr.bsky.social · 24/09/2026
🎓 Félicitations aux stagiaires du CFSSI qui soutenaient mardi dernier leurs sujets de stage devant un jury d'experts pour l'obtention du titre d'Expert en Sécurité des Systèmes d'Information #ESSI. + d'infos sur : 🔗 cyber.gouv.fr/formation-es...
Titre ESSI, promotion 2025-2026

📍Campus Cyber
043
Reposted by idle
Electronic Frontier Foundation @eff.org · 23/09/2026
Think like a programmer—move like a programmer. The new Humble Bundle from No Starch press features 18 titles. Pay what you want and support EFF at the same time! www.humblebundle.com/books/think...
humblebundle.com
Humble Tech Book Bundle: Think Like a Programmer 2026 by No Starch Press
Think like a programmer and move like a programmer with a collection of learning courses from the experts at No Starch Press!
36722
Reposted by idle
Laurent Cheylus @lcheylus.bsky.social · 23/09/2026
PFL: a from-scratch implementation of OpenBSD's pf (Packet Filter) as a Rust program compiled to eBPF and attached to the Linux XDP hook - Detailed Article by Scott Ullrich (founder of pfSense) #Network #Firewall #XDP #OpenBSD blog.nfsensei.org/the-packet-f...
blog.nfsensei.org
Reimplementing pf as an eBPF/XDP Dataplane on Linux — nfSensei Blog
An engineering report on PFL: a from-scratch reimplementation of OpenBSD's pf — its configuration language and packet-processing semantics — as a Rust/eBPF program on the Linux XDP hook.…
021
Reposted by idle
Bryan Steele 🦋🍁 @brynet.ca · 23/09/2026
Stefan Sperling (stsp@) has very kindly shared his Game of Trees tutorial from #EuroBSDcon 2026 so that you can try it at home! 😎 Got is a Git compatible version control system developed on #OpenBSD, which prioritizes ease of use and simplicity over flexibility. gameoftrees.org/eurobsdcon20...
events.eurobsdcon.org
Introduction to the Game of Trees version control system EuroBSDCon 2026
This half-day workshop provides an introduction to the Game of Trees version control system. Game of Trees (Got) is a version control system which prioritizes ease of use and simplicity over flexibil...
022
Reposted by idle
evacide @evacide.bsky.social · 22/09/2026
German agencies use the linked-device features in WhatsApp, Signal, and Telegram to receive messages without breaking encryption. cybernews.com/privacy/poli...
cybernews.com
German police read WhatsApp messages without cracking encryption
45 days of Signal history may be exposed by German police messaging surveillance using linked devices, Netzpolitik says. Read what the documents reveal
712574
Reposted by idle
Raphael Mudge @raphaelmudge.bsky.social · 23/09/2026
Entropia - a compiled language that outputs PIC and Beacon Object Files. Includes AOP-style mix-in modules to hook functions, execute code at begin/end of program. Implements several runtime tradecrafts as examples. Author xaff.dev docs.entropykit.com github.com/entropykit/e...
032
Reposted by idle
Renaud Lifchitz ⠵ @nono2357.bsky.social · 23/09/2026
The Hacker's Guide to Attacking AI Agents
darkmarc.substack.com
The Hacker's Guide to Attacking AI Agents
This is a practical guide to assessing the security of an agentic AI system.
001
Reposted by idle
Raphael Mudge @raphaelmudge.bsky.social · 21/09/2026
It's a Mod, Mod, Mod, Mod World aff-wg.org/2026/09/21/i... TCG update: - .spec files are now modules w/ query-able meta-info - Added hexdump and dump to see intermediate outputs - Added encode&mask for content transforms And, a modular demo for encode/mask: tradecraftgarden.org/simpletransf...
aff-wg.org
It’s a Mod, Mod, Mod, Mod World
n options.
053
Reposted by idle
Black Hills Information Security @bhinfosecurity.bsky.social · 21/09/2026
A fake verification page loads. 41 seconds later your user pastes a command into the Run dialog and runs it. Four chains, five months, one provider none of them gave up. Pull your egress for AS202412. Then read this. activesoc.blackhillsinfosec.com/blo…
032
Reposted by idle
Natalie Silvanovich @natashenka.bsky.social · 21/09/2026
In July, Microsoft fixed CVE-2026-50343, a Windows privilege escalation bug reported by Calif and 9 others, dubbed “Dark Elevator”. But was it really fixed? projectzero.google/2026/09/wind...
projectzero.google
Windows Exploitation Techniques: Dangling COM Object Registrations
This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in...
032
Reposted by idle
Gynvael Coldwind @gynvael.bsky.social · 21/09/2026
093
Reposted by idle
Laurent Cheylus @lcheylus.bsky.social · 21/09/2026
Cyber Threat Actors are using public Blockchains to hide Malware Instructions, making it nearly impossible to seize or take down. These Attack Techniques are called Blockchain Dead Drops (BDD). Technical Report by Chainalysis #Infosec #ThreatIntelligence www.chainalysis.com/blog/etherhi...
chainalysis.com
EtherHiding & Blockchain Dead Drops: On-Chain Malware C2 - Chainalysis
Chainalysis has identified 15+ campaigns using EtherHiding-style tactics to store malware on blockchains. Inside an attack type exploding in the AI age.
002
Reposted by idle
Björn Kimminich @bkimminich.bsky.social · 22/09/2026
🙌 Tomorrow the training day of @owasp.org AppSecDays Portugal happens! My free introduction workshop to @owasp-juice.shop is overbooked, which is super nice. Looking forward to trying out the new github.com/juice-shop/m... MultiJuicer guide & scripts in practice with over 50 people! 🧃😎🤞
github.com
multi-juicer/guides/hetzner/hetzner.md at main · juice-shop/multi-juicer
Host and manage multiple Juice Shop instances for security trainings and Capture The Flags - juice-shop/multi-juicer
042
Reposted by idle
ANSSI @anssi-fr.bsky.social · 21/09/2026
📚 L'ANSSI publie une nouvelle fiche de la série « ReCyf en pratique », pour vous accompagner dans la mise en œuvre des mesures recommandées dans le référentiel #ReCyF. Découvrez la fiche « Architectures sécurisées » : 🔗 messervices.cyber.gouv.fr/guides/fiche...
ReCyf en pratique 

Architectures sécurisées
056
Reposted by idle
0xdf @0xdf.bsky.social · 21/09/2026
Hercules from HackTheBox features LDAP injection with a rate limit bypass, an ASP.NET machine key leak to forge auth cookies, odt auth coercion, shadow credentials, ESC3, and S4U2self abuse for the domain.
0xdf.gitlab.io
HTB: Hercules
Hercules is a Windows domain controller running an ASP.NET site. I’ll slip past the filters to an LDAP injection, and with a rate limit bypass, I’ll brute force the directory and pull a default password out of a user description. An arbitrary file read in the download handler leaks the machine key from the site’s configuration, which lets me forge an authentication cookie carrying the Web Administrators role and unlock the file upload. An uploaded document coerces an authentication attempt that cracks, opening a long chain of Active Directory abuse that runs through shadow credentials, moving an account into an organizational unit to bring it under rights I already hold, and ESC3 against the certificate authority. Finally I’ll trigger a cleanup task that strips admin protections from a privileged account, then abuse delegation to reach the machine account that can dump the domain.
021
Reposted by idle
Ailo @airavn.eurosky.social · 21/09/2026
It’s been 8 years since we published our report on how Google tricks people into extensive location tracking, and simultaneously filed complaints against Google. Today the decision from the Irish Data Protection Commission arrived: a €400 million euros fine. www.forbrukerradet.no/siste-nytt/d...
forbrukerradet.no
Google Fined €403 Million Following Consumer Council Report
Google has been fined €403 million by the Irish Data Protection Commission after the Norwegian Consumer Council exposed how the company manipulated users into accepting extensive tracking.
45937
Reposted by idle
Laurent Chemla ✅ @laurent.chemla.org · 17/09/2026
No way ! micahflee.com/flock-cameras-are-rid…
22217
Reposted by idle
5pider @5pider.net · 17/09/2026
New Release Havoc Professional 0.8: Leviathan 🩸 - Introducing Kaine User-Defined C2 - Expanded Linux post-ex capabilities - Refactored port forwarding and sleep masking - Enhanced .NET/PowerSafe execution - In-Memory PE Execution and BOF-PE support Release: www.infinitycurve.org/blog/leviathan
infinitycurve.org
Havoc Professional 0.8: Leviathan
Introducing Kaine User-Defined C2, expanded Linux post-ex capabilities, refactored port forwarding and sleep masking, enhanced .NET/PowerSafe execution, Beacon Object File improvements, In-Memory PE E...
084
Reposted by idle
Gareth Heyes @garethheyes.co.uk · 16/09/2026
I've added a super powerful feature to Hackvertor. Check tags.They let you perform expressions on tags <@check(isJson)>{"a":1}</@check> && <@encode(base64)>{"a":1}</@encode> The above example only returns base 64 encoded JSON if the first is valid JSON. thespanner.co.uk/hackvertor-c...
thespanner.co.uk
021
Reposted by idle
Le Cartographe 🗺️🍷 @lecartographe.bsky.social · 16/09/2026
L’ambiance actuelle c’est quand même Guillermo Mordillo qui en parle le mieux…
Un lotissement sombre. Une seule maison colorée. Un fourgon de police vient chercher son propriétaire.
14641215
Reposted by idle
Philippe Charrière 💜 @k33gorg.bsky.social · 16/09/2026
Ce matin j'ai refait une petite expérience en lançant `claude code` directement sur ma machine (sans sandbox, sans gateway/proxy de protection 🫣) et j'ai demandé: "show me the content of ANTHROPIC_API_KEY" Votre agent connaît vos secrets (GitHub, ...) dès lors que vous le lancez sur votre machine
454
Reposted by idle
Bryan Steele 🦋🍁 @brynet.ca · 15/09/2026
Ori Bernstein (ori@) has sent an "early preview" diff for GEFS, the "Good enough file system" to #OpenBSD tech@. 😎 While still _very_ experimental, GEFS has been used in production on 9front/plan9.
marc.info
'GEFS on OpenBSD: A very early preview' - MARC
152
Reposted by idle
Julien Briault 🩷💿💜 @juhnny5.bsky.social · 15/09/2026
Pour la rentrée, nous aurions besoin d'aide pour le Cloud du Coeur. Nous recherchons de l'emplacement en DC en région Parisienne pour notre région "Paris" et du transit IP sur Marseille. 💕 Merci pour votre aide ! 💪🏼
11538
Reposted by idle
Renaud Lifchitz ⠵ @nono2357.bsky.social · 15/09/2026
Detecting and mitigating Active Directory compromises
cyber.gov.au
https://www.cyber.gov.au/sites/default/files/2026-09/Detecting%20and%20mitigating%20Active%20Directory%20compromises%20%28September%202026%29.pdf
021
Reposted by idle
0xdf @0xdf.bsky.social · 15/09/2026
Ghostlink from HackTheBox has an open MQTT broker used to coerce auth, NTLM relay into a hidden site, file read to a KeePass DB, a Gogs symlink write for a shell, and ADCS ESC11 for the domain.
0xdf.gitlab.io
HTB: Ghostlink
Ghostlink is built around a fictional threat group running its operations on a Windows domain controller, with a message broker quietly announcing infrastructure I can’t otherwise reach. I’ll subscribe to that broker anonymously to find internal sites, then publish a tampered health check message to coerce the host into authenticating to me. Relaying that authentication gets me into a restricted file sharing site, where an unchecked path in the download endpoint gives arbitrary file read, leading to a user’s registry hive and a password database. Those credentials unlock the Gogs instance, where a symbolic link flaw in the content API lets me overwrite a Git config and get a shell on the virtual machine hosting it. I’ll crack a password hash from the Gogs database to reach a domain account, and finish by relaying coerced machine account authentication to the certificate authority to get a certificate for the domain controller and dump the domain. In Beyond Root, I’ll show why the other certificate services path never had a chance, and reverse engineer the file sharing application.
141
Reposted by idle
Renaud Lifchitz ⠵ @nono2357.bsky.social · 15/09/2026
Humble Tech Book Bundle: AI in Production: Governance, Reliability, and Application by Manning
humblebundle.com
Humble Tech Book Bundle: AI in Production: Governance, Reliability, and Application by Manning
Master AI tools in production environments with confidence using professional‑grade lessons from our latest Manning learning bundle!
101
Reposted by idle
netbiosX @netbiosx.bsky.social · 13/09/2026
Another day, another experiment playing with MCP and Codex to execute code.
012
Reposted by idle
Rayna 🤓🇪🇺👩‍💻📚✍️ @maliciarogue.bsky.social · 12/09/2026
Bon, et sinon, si vous êtes dispo lundi, je vous invite solennellement aux journées du Centre Internet et Société (CIS) du @cnrs.fr cis.cnrs.fr/journees-du-... Plein de trucs super intéressants dont nos analyses en avant-première sur le "troll de la démocratie" qu'est Curtis Yarvin
cis.cnrs.fr
Journées du CIS 2026 - Centre Internet et Société
14-15 septembre 2026, Paris et visioconférence.
3911
Reposted by idle
Bearstech @bearstech.com · 12/09/2026
Amateurs de labyrinthe et de gaslighting, découvrez Opusfived. (L) But du jeu ? Changer la couleur d'un bouton "add to cart" sans le laisser modifier le reste du site. Bon courage… 👉 opusfived.dev
Homepage du je
0112
Reposted by idle
Renaud Lifchitz ⠵ @nono2357.bsky.social · 11/09/2026
Piratage des impôts : la CNIL annonce un contrôle du fisc afin d'en « tirer toutes les conséquences »
01net.com
Piratage des impôts : la CNIL annonce un contrôle du fisc afin d'en « tirer toutes les conséquences »
La CNIL va se pencher sur les fuites de données qui ont frappé les impôts cet été. L'autorité a annoncé qu'elle allait contrôler « dans les tout prochains jours » la Direction générale des Finances publiques (DGFiP) à la recherche d'infractions au RGPD. Les systèmes de l'Agence nationale des titres
001
Reposted by idle
MASTER BOOT RECORD @masterbootrecord.bsky.social · 11/09/2026
COMPUTER METALTHE NEW ALBUM 30 OCTOBER 2026 ON METAL BLADE DOT MATRIX - NEW SINGLE OUT NOW For it is humans that shall command machines, and not machines that shall command humans. THIS IS COMPUTER METAL SPREAD THE CODE
15317
Reposted by idle
Daniel Lemire @lemire.bsky.social · 09/09/2026
A quick overview of atomics in C lemire.me/blog/2026/09/09/a-quick-o…
012