💥 leonjza @leonjza.bsky.social · 06/08/2026Join us on Saturday at 1100 for some seriously fun card machine hacking by Reino from our Orange Cyberdefense’s @sensepost.com team at @defcon.bsky.social 34 this weekend! Every single dry run I have seen of this talk had me excited, giggling and blown away by his crafty hacks. 🙃 000
Reposted by 💥 leonjzashifttymike.bsky.social @shifttymike.bsky.social · 27/07/2026It’s the default tool for WiFi hacking but there were a few things that bugged me, so I made it better. Then I made it nicer. Here’s the link: github.com/shifttymike/... Static bins available in releases :)github.com 046
💥 leonjza @leonjza.bsky.social · 20/07/2026I used to like to see peoples browser tabs they have open to get a sense of what they are working on, but ChatGPT conversation titles are so much better at that. 000
Reposted by 💥 leonjzaDominic White @singe.bsky.social · 20/07/2026I put up a writeup of our @sensepost annual artwork up here sensepost.com/blog/2026/se... Free downloads if you like it.sensepost.com SensePost | SensePost’s 2026 Artwork 001
Reposted by 💥 leonjzaDominic White @singe.bsky.social · 13/06/2026Check whether a site supports post quantum crypto* quantumhello.xyz * Well hybrid PQ key exchange in the form of TLS 1.3 with X25519MLKEM768 104
Reposted by 💥 leonjzalynn @chordbug.bsky.social · 24/04/2026highly unfortunate max-width on this div 634741
💥 leonjza @leonjza.bsky.social · 21/04/2026Not bad! Single shotted this image with @OpenAI ChatGPT Images 2.0. 000
Reposted by 💥 leonjzaKatie Mack @astrokatie.com · 07/04/2026The #Artemis II astronauts said they needed more superlatives to describe their view of the eclipse, when the Sun was behind the Moon and its near surface was faintly illuminated by Earthshine 322854755
💥 leonjza @leonjza.bsky.social · 15/03/2026Just pushed some slides and labs polish for next weeks @1ns0mn1h4ck.bsky.social before my flight. The whole repo (which includes the training platform, labs, and slides) is quite... diverse :D 011
Reposted by 💥 leonjzaDavid Crawshaw @crawshaw.io · 11/03/2026macOS already ships age verification 7630104
💥 leonjza @leonjza.bsky.social · 13/02/2026Had a case this week of a fairly secure deployment of BeyondTrust, but vulnerable to CVE-2026-1731. With basically zero egress, I implemented a timing oracle POC instead. Takes about 20 minutes to get the ls command output in this demo, but hey, it works! :D 020
Reposted by 💥 leonjzaBad Sector Labs @badsectorlabs.com · 10/02/2026"Negative-day" discovery (@spaceraccoonsec), Exploit gen with LLMs (@seanhn), Harmony LPE (@johnnyspandex + @buffaloverflow), NetSupport Manager RCE (@0xor_solo), Azure blob C2 (@KingOfTheNOPs + @senderend) and more! blog.badsectorlabs.com/last-week-in...blog.badsectorlabs.comLast Week in Security (LWiS) - 2026-02-09 001
💥 leonjza @leonjza.bsky.social · 28/01/2026Noone asked for this, but I'm trying to get more comfortable with qemu as a whole which has resulted in this overly fancy Qemu Machine Protocol (QMP) socket client, complete with dynamic schema parsing, event subscriptions and tab completion, because why not :P 011
Reposted by 💥 leonjzaDavid Buchanan @retr0.id · 28/01/2026an easy way to remember the difference between ssh -L and ssh -R is to try both until it works 1217514
💥 leonjza @leonjza.bsky.social · 21/01/2026Quick lunch time side quest building a simple lab to play with the inetutils-telnetd authentication bypass as disclosed on oss-sec ₁. github.com/leonjza/inet... ₁ seclists.org/oss-sec/2026... 043
💥 leonjza @leonjza.bsky.social · 19/01/2026Really excited to present this Frida training @1ns0mn1h4ck.bsky.social with @ipmegladon.bsky.social and myself! If you've dabbled with Frida before, but want a practical learning opportunity to improve your usage and understanding, this one is for you! 033
Reposted by 💥 leonjzatmp0ut @tmpout.sh · 14/01/2026We are excited to announce the CFP for the next tmp.0ut Volume 5! tmpout.sh/blog/vol5-cf... 03218
💥 leonjza @leonjza.bsky.social · 07/12/2025Two blog posts just dropped - one with the details on the bloatware pwning shenanigans I was up to earlier in the year, and another on pipetap, a new Windows named pipe proxy/tool. sensepost.com/blog/2025/pw... sensepost.com/blog/2025/pi... 032
💥 leonjza @leonjza.bsky.social · 06/12/2025It’s almost time for my @BSidesCapeTown talk, and I’ve just open sourced pipetap. My Windows named pipe proxy & multi-tool. Excited to see what you do with it! github.com/sensepost/pi...github.comGitHub - sensepost/pipetap: A Windows Named Pipe Multi-tool / ProxyA Windows Named Pipe Multi-tool / Proxy. Contribute to sensepost/pipetap development by creating an account on GitHub. 0124
💥 leonjza @leonjza.bsky.social · 05/12/2025Honestly excited for this years BSides Cape Town with fellow hackers and the @sensepost.com crew! See you soon Cape Town! 010
Reposted by 💥 leonjzaRastaMouse @rastamouse.me · 01/12/2025[BLOG] This update solved a big issue I had with merging raw assembly into PIC. I cover the new linkfunc command and the updated addhook command. rastamouse.me/pic-symphony/rastamouse.mePIC SymphonyRaffi just released another update to Crystal Palace, which serves to improve the way specification files are handled by making them more modular. Tradecraft Orchestration in the GardenWhat’s more re... 032
Reposted by 💥 leonjzapard0p.bsky.social @pard0p.bsky.social · 01/12/2025LibPicoManager is a unified PICO management framework that provides centralized control over PICOs in memory, enabling dynamic code loading, runtime PICO substitution, and advanced evasion techniques like sleep masking through a single RWX code block. github.com/pard0p/LibPi...github.comGitHub - pard0p/LibPicoManager: LibPicoManager is a unified PICO management framework that provides centralized control over Position Independent Code Objects in shared memory, enabling dynamic code l...LibPicoManager is a unified PICO management framework that provides centralized control over Position Independent Code Objects in shared memory, enabling dynamic code loading, runtime PICO substitu... 043
Reposted by 💥 leonjzaInsomni'hack @1ns0mn1h4ck.bsky.social · 01/12/2025🎟️ Early Bird tickets for Insomni'hack 2026 are live! Join us in Switzerland for talks, CTF and networking with industry leaders. Don’t miss out! Secure your spot now: ow.ly/iKes50XzTj3 #INSO26 #Cybersecurity #EthicalHacking #Event 032
Reposted by 💥 leonjzaRastaMouse @rastamouse.me · 28/11/2025The new version of RTO II is finally available to purchase. www.zeropointsecurity.co.uk/course/red-t...zeropointsecurity.co.ukRed Team Ops IIGain the knowledge and skills necessary to operate against advanced defences. 1107
Reposted by 💥 leonjzaCarlos Holguera @grepharder.bsky.social · 21/11/2025We've been waiting 5 years for this: objection has been updated to 1.12.x with Frida17+ support. Thank you so much @leonjza.bsky.social and everyone who contributed! github.com/sensepost/ob... Thanks to @ipmegladon.bsky.social for updating the MASTG accordingly (OWASP/mastg/pull/3378)github.comRelease 1.12.0 · sensepost/objectionThe, wow, finally, a release release! 😂 Honestly, there has been so much that has changed, and it's hard to thank and attribute to everyone that has contributed. To that end, thank you for your con... 043
💥 leonjza @leonjza.bsky.social · 21/11/2025It's... been a while since the last objection release got tagged. We finally landed a 1.12 release today which also means pypi is up to date again, and for the foreseeable future! Work never really stopped, and plenty of bug fixes are included. More in 🧵 github.com/sensepost/ob... 133
Reposted by 💥 leonjzaDominic White @singe.bsky.social · 20/11/2025Made this last night, it’s useful for finding a large number of domains hosting phishing kits or malware based on a consistent pattern github.com/singe/domain-p… Might be useful for some of you.github.comGitHub - singe/domain-probe: A utility to find identically configured domains and web-servers based on a pattern. Used to find phishing kits.A utility to find identically configured domains and web-servers based on a pattern. Used to find phishing kits. - singe/domain-probe 064
Reposted by 💥 leonjzaSensePost @sensepost.com · 19/11/2025Need to open doors from the outside without touching anything? Turns out thats possible with no touch sensors as @shifttymike.bsky.social details in his latest blog post. sensepost.com/blog/2025/no... 042
💥 leonjza @leonjza.bsky.social · 17/11/2025Landed a new gowitness release, this time focussing on performance! 🎉 v3.1.0 github.com/sensepost/go...github.comRelease 3.1.0 · sensepost/gowitnessA new release, this time focussing on performance and various bug fixes! Thanks to all of the contributors! Enjoy! 🎉 New Refactor the chromedp driver, focussing on performance. The new implementat... 022
Reposted by 💥 leonjzaRastaMouse @rastamouse.me · 29/10/2025I've also updated Crystal Loaders to benefit from some of the new CP features github.com/rasta-mouse/...github.comGitHub - rasta-mouse/Crystal-Loaders: A small collection of Crystal Palace PIC loaders designed for use with Cobalt StrikeA small collection of Crystal Palace PIC loaders designed for use with Cobalt Strike - rasta-mouse/Crystal-Loaders 012
Reposted by 💥 leonjzaMITRE ATT&CK @attack.mitre.org · 28/10/2025ATT&CK v18 is now out! Today marks the release of Detection Strategies, where we've moved from single-sentence notes to structured, behavior-focused strategies across the board. A new blog post describes the changes medium.com/mitre-attack... with details at attack.mitre.org/resources/up....medium.comATT&CK v18: Detection Strategies, More Adversary Insights,ATT&CK v18 is released with new Detection Strategies, Analytics, and revamped Data Components! 095
Reposted by 💥 leonjzaDominic White @singe.bsky.social · 28/10/2025Just added SOCKS support to this reverse tunnelling tool github.com/singe/contun... 021
Reposted by 💥 leonjzaDominic White @singe.bsky.social · 27/10/2025github.com/singe/contun.p… this was a fun nerd snipe - how do you build a listed:listen connect:connect reverse tunnel that can handle concurrent connections when you only have Perl.github.comGitHub - singe/contun.pl: A concurrent listen:listen connect:connect tunnelling solution written in PerlA concurrent listen:listen connect:connect tunnelling solution written in Perl - singe/contun.pl 021
Reposted by 💥 leonjzaInsomni'hack @1ns0mn1h4ck.bsky.social · 23/10/2025🚀 Insomni’hack 2026 is coming! 🗓️ March 16-20 @ SwissTech, Lausanne Mon-Wed: Workshops | Thu-Fri: Talks | Fri-Sat: CTF 👉 More details soon: ow.ly/S3uv50XgSuS 🔔 Save the dates & stay tuned! #INSO26 #cybersecurity #CTF #event #Lausanne 031
Reposted by 💥 leonjzaCalzone @calz0n3.bsky.social · 16/10/2025Working on a new PICO! This one is an in-memory CLR hoster that uses the same technique as execute-assembly/donut to invoke a .NET assembly without touching the disk. 251
Reposted by 💥 leonjzaInsomni'hack @1ns0mn1h4ck.bsky.social · 15/10/2025📢Insomni'hack Call for Paper is now open! The CFP 2026 is now accepting submissions. Want to speak, lead a workshop, or present a case study? We want to hear from you! 🔗 Submit: ow.ly/nNov50Xbylu #InsomniHack #CFP #Cybersecurity #Infosec #TechTalks 054
Reposted by 💥 leonjzaPaged Out! @pagedout.bsky.social · 04/10/2025pagedout.institute ← we've just released Paged Out! zine Issue #7 pagedout.institute/download/Pag... ← direct link lulu.com/search?page=... ← prints for zine collectors pagedout.institute/download/Pag... ← issue wallpaper Enjoy! Please please please share to spread the news - thank you! 12017
💥 leonjza @leonjza.bsky.social · 28/09/2025Romhack was absolute 🔥! The conference, the community, the vibe - all of it was just something else. Special mention to merlos1977@x and the CybersaiyanIT@x team for making the speaking experience excellent too. 🙃 071
💥 leonjza @leonjza.bsky.social · 18/09/2025Soon™ Private invites at Romhack next week, public release a while later. 040
Reposted by 💥 leonjzaJulia Evans @b0rk.jvns.ca · 16/09/2025added a cheat sheet to the official Git website (with a lot of help from other folks who work on the website) git-scm.com/cheat-sheetgit-scm.comGit Cheat Sheet 1029557
💥 leonjza @leonjza.bsky.social · 10/09/2025I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :) 297
Reposted by 💥 leonjzasam henri gold @samhenri.gold · 06/09/2025Did you know your MacBook has a sensor that knows the exact angle of the screen hinge? It’s not exposed as a public API, but I figured out a way to read it and make it sound like an old wooden door. 11675691936
💥 leonjza @leonjza.bsky.social · 27/08/2025Using @radareorg.bsky.social to dynamically get the virtual address of a @golang.org embed.FS structure to extract some sus embed's with go-embed-extractor¹ in this "dodgy-go-bin" 🔥 ¹ github.com/BreakOnCrash... 012