Sign in

mig 🇺🇦

@miguelaya.bsky.social
106 followers 180 following 184 posts

infosec / fuck putin / fuck trump / fuck musk

PostsRepliesMedia
mig 🇺🇦 @miguelaya.bsky.social · 08/10/2026
www.p1sec.com/blog/present...
p1sec.com
DiagNG: capture 2G/3G/4G/5G air interface traces to PCAP
DiagNG, the open-source successor to QCSuper: a Linux GUI tool, now in beta, that produces 2G/3G/4G/5G PCAP captures from Qualcomm Snapdragon basebands.
011
mig 🇺🇦 @miguelaya.bsky.social · 25/09/2026
Not only an unauth RCE on tac_plus, but a way to try to crack the TACACS secret remotely www.elttam.com/blog/att-cki...
elttam.com
ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE - elttam
Details a pre-auth format string vulnerability in tac_plus, a popular daemon implementing TACACS+ for network device management, and the shared secret oracle that makes it a practical RCE chain.
010
mig 🇺🇦 @miguelaya.bsky.social · 06/09/2026
SIM relay salmg.net/2026/09/04/s...
salmg.net
SIMtrace2 T-1 Research Project
Card Relay Internals How a physical smart card connected to a desk-side reader can be made to communicate with a remote terminal as if the card were connected locally. The research focuses on ISO/I…
000
mig 🇺🇦 @miguelaya.bsky.social · 21/07/2026
Cool audio project odio.love
odio.love
odio: revive any Raspberry Pi as an open-source audio streamer
Revive any Raspberry Pi as a self-hosted audio streamer. AirPlay 2, Spotify, Snapcast multiroom, Home Assistant. One curl install. Free Volumio alternative.
010
mig 🇺🇦 @miguelaya.bsky.social · 10/07/2026
I've got 99 followers but your mom ain't one
110
mig 🇺🇦 @miguelaya.bsky.social · 08/06/2026
Pretty cool phased array antenna project moonrf.com
moonrf.com
ScaleRF | Taking phased arrays to the next level
000
mig 🇺🇦 @miguelaya.bsky.social · 27/05/2026
Details on the TETRA attack on Taiwan Shinkansen www.midnightblue.nl/blog/analyzi...
midnightblue.nl
Analyzing the Taiwan High-Speed Rail (THSR) TETRA cyber incident (part 1)
Deep dive analysis of the TETRA cyber incident which disrupted operations at Taiwan High Speed Rail (THSR) in April 2026.
000
Reposted by mig 🇺🇦
Catalin Cimpanu @campuscodi.risky.biz · 24/05/2026
Microsoft has banned Nightmare Eclipse from GitHub: github.com/Nightmare-Ec... This is the researcher who disclosed several zero-days after Microsoft also deleted his MSRC account They now moved on GitLab: deadeclipse666.blogspot.com
820559
mig 🇺🇦 @miguelaya.bsky.social · 24/05/2026
"Hold your camera still" BUT THE UNIVERSE IS MOVING
000
mig 🇺🇦 @miguelaya.bsky.social · 24/05/2026
Surveillance companies can't get my location, I'm always moving, the information is already old
000
mig 🇺🇦 @miguelaya.bsky.social · 20/05/2026
I tasted sweet dreams and they were not made of this
000
mig 🇺🇦 @miguelaya.bsky.social · 21/04/2026
community.penthertz.com/t/the-mifare...
community.penthertz.com
000
mig 🇺🇦 @miguelaya.bsky.social · 12/04/2026
infosecwriteups.com/ot-reconnais...
infosecwriteups.com
OT Reconnaissance with Wireshark and GrassMarlin
Read every packet. Spot every anomaly. Baseline your OT network before attackers do.
000
Reposted by mig 🇺🇦
cosmic angel @itcleb.bsky.social · 11/04/2026
i might become something later
071
Reposted by mig 🇺🇦
SwiftOnSecurity @swiftonsecurity.com · 10/04/2026
A guiding principle of my life is, "there is no perfection without iteration." You must fail. You must be humiliated in the results of your initiative. There is no other way.
1321329
Reposted by mig 🇺🇦
Nick vs Networking @nickvsnetworking.bsky.social · 24/03/2026
I'm always having to look up or reference 3GPP specs and at a protocol level, what you can and can't do for Diameter/GTP-C/PFCP/MAP/SBI, so I made a Pokèdex for protocols: protocoldex.omnitou.ch
protocoldex.omnitou.ch
Omnitouch Protocoldex - Telecom Protocol Reference
Comprehensive telecom protocol reference for Diameter AVPs, GTPv2-C IEs, MAP operations, 5G SBI APIs, and PFCP. Search and explore protocol specifications instantly.
141
mig 🇺🇦 @miguelaya.bsky.social · 27/03/2026
redteam.vip/ram-rfid-att...
redteam.vip
RAM | RFID Attack Matrix
Interactive RFID Attack Matrix with discovery workflows, attack paths, and countermeasures.
000
Reposted by mig 🇺🇦
SpecterOps @specterops.io · 17/02/2026
Every Entra ID assessment ends here: “How do I get a token without triggering Conditional Access controls?” 🤔 Lee Robinson built CAPSlock, an offline ROADrecon-based Conditional Access engine that simulates sign-ins & flags gaps without touching the tenant. ghst.ly/4aHUGuD
ghst.ly
STOP THE CAP: Making Entra ID Conditional Access Make Sense Offline - SpecterOps
Analyze Entra ID Conditional Access policies offline. CAPSlock simulates sign-ins and exposes enforcement gaps without generating tenant activity.
062
mig 🇺🇦 @miguelaya.bsky.social · 19/12/2025
How to crash your phone: run the benchmark of webcrack.octopwn.com
webcrack.octopwn.com
WebCrack GPU
000
Reposted by mig 🇺🇦
SpecterOps @specterops.io · 12/12/2025
PingOneHound, created in partnership with @pingidentity.com, brought BloodHound visibility into PingOne this year, helping defenders discover and remediate identity attack paths. Check out @andyrobbins.bsky.social's post to learn more → ghst.ly/poh-eoybsky
021
Reposted by mig 🇺🇦
Andrew Morris @andrewmorr.is · 29/11/2025
Shamlessly reposting from elsewhere- you can easily communicate between Linux VMs and guests using VSOCK (man7.org/linux/man-pa...). Here's some silly examples of bidirectional chat btwn host & guest using Socat. Or connecting via SSH to my home router from the VM without TCP/IP. No code required.
2143
mig 🇺🇦 @miguelaya.bsky.social · 24/11/2025
1-click RCE on automotive industry konatabrk.github.io/perfektblue/
konatabrk.github.io
PerfektBlue
000
mig 🇺🇦 @miguelaya.bsky.social · 19/11/2025
sensepost.com/blog/2025/no...
sensepost.com
SensePost | Noooooooooo touch!
Leaders in Information Security
000
Reposted by mig 🇺🇦
Kate from Kharkiv @kateinkharkiv.bsky.social · 01/11/2025
When I was younger, I naively believed that if the genocides of the past had occurred in our age of developed social media, the world would have stopped them sooner. ​And then Ukraine was attacked in this very age of developed social media: an era where everyone has their own "version of truth";
1140570
Reposted by mig 🇺🇦
Nathan McNulty @nathanmcnulty.com · 10/10/2025
Intune now has dedicated security recommendations docs just like Entra 🔥 The Entra security docs are extremely popular, and I love seeing other teams publishing this kind of guidance Thanks to my collegaue (Josh Gatewood) for pointing this out! learn.microsoft.com/en-us/intune...
0279
mig 🇺🇦 @miguelaya.bsky.social · 02/10/2025
The drones in the nordics are a good example of hybrid warfare from russia. In a DDoS attack a force multiplier is used: send a little traffic somewhere, get it to respond manyfold. Drones are a cheap way to cause NATO countries to divest attention and resources from helping Ukraine.
020
mig 🇺🇦 @miguelaya.bsky.social · 30/09/2025
hey @bsky.app can you fix the app so you can select text
000
mig 🇺🇦 @miguelaya.bsky.social · 26/09/2025
RPC interfaces blog.jcspencer.net/rpc-interfaces/
blog.jcspencer.net
Windows RPC Interface Database - @jcspencer
A simple database of Windows RPC interfaces (DCE/RPC & Named Pipes)
000
mig 🇺🇦 @miguelaya.bsky.social · 26/08/2025
Good post on using your context with SOCKS on other machines specterops.io/blog/2025/08...
specterops.io
Operating Outside the Box: NTLM Relaying Low-Privilege HTTP Auth to LDAP - SpecterOps
TL;DR When operating out of a ceded access or phishing payload with no credential material, you can use low-privilege HTTP authentication from the current user context to perform a proxied relay to LD...
120
mig 🇺🇦 @miguelaya.bsky.social · 22/08/2025
Good resource on Android apps interacting with SIM stackoverflow.com/questions/30...
stackoverflow.com
Send APDU commands to USIM/SIM card in android
I was already worked with smart cards and I am familiar with APDU commands (that are defined in ISO/IEC 7816 and Global Platform specifications). Now I want to know if there is any way to send an...
010
mig 🇺🇦 @miguelaya.bsky.social · 22/08/2025
github.com/mnemonic-no/...
github.com
GitHub - mnemonic-no/ScapySMS: Complete SMS packet manipulation
Complete SMS packet manipulation. Contribute to mnemonic-no/ScapySMS development by creating an account on GitHub.
010
mig 🇺🇦 @miguelaya.bsky.social · 22/08/2025
RPC tutorial clearbluejar.github.io/posts/from-n...
clearbluejar.github.io
From NtObjectManager to PetitPotam
Windows RPC enumeration, discovery, and auditing via NtObjectManager. We will audit the vulnerable RPC interfaces that lead to PetitPotam, discover how they have changed over the past year, and overco...
000
mig 🇺🇦 @miguelaya.bsky.social · 19/08/2025
github.com/Sleepw4lker/...
github.com
GitHub - Sleepw4lker/TameMyCerts: Policy Module for Microsoft Active Directory Certificate Services
Policy Module for Microsoft Active Directory Certificate Services - Sleepw4lker/TameMyCerts
000
mig 🇺🇦 @miguelaya.bsky.social · 19/08/2025
cicada-8.medium.com/impacket-dev...
cicada-8.medium.com
Impacket Developer Guide. Part 1. RPC
Learn the basics of RPC, develop a client and server using C++
000
mig 🇺🇦 @miguelaya.bsky.social · 18/08/2025
Good stuff!
000
mig 🇺🇦 @miguelaya.bsky.social · 12/08/2025
So cool www.midnightblue.nl/research/2te...
midnightblue.nl
2 TETRA 2 BURST
Three device vulnerabilities in Gen 3 Sepura devices (such as the SC20 series) ranging from code execution to key exfil, requiring only brief physical access.
000
mig 🇺🇦 @miguelaya.bsky.social · 31/07/2025
New baseband vulns www.linkedin.com/posts/yongda...
linkedin.com
* USING LLFUZZ TO EXPOSE CRITICAL VULNERABILITIES IN BASEBAND LOWER LAYERS * | Yongdae Kim
* USING LLFUZZ TO EXPOSE CRITICAL VULNERABILITIES IN BASEBAND LOWER LAYERS * - One malformed packet is enough to crash a smartphone -- To be presented at USENIX Security 2025 Baseband modems handle a...
000
mig 🇺🇦 @miguelaya.bsky.social · 29/07/2025
Rehost your firmware github.com/rehosting/pe...
github.com
GitHub - rehosting/penguin: PENGUIN (Personalized EmulatioN Generated Using Instrumented Analysis) takes a target centric approach to rehosting using a precise and tailored specification of the rehost...
PENGUIN (Personalized EmulatioN Generated Using Instrumented Analysis) takes a target centric approach to rehosting using a precise and tailored specification of the rehosting process - rehosting/p...
000
mig 🇺🇦 @miguelaya.bsky.social · 29/07/2025
This NTLM relay article node has edges to plenty of great article nodes specterops.io/blog/2025/07...
specterops.io
Escaping the Confines of Port 445 - SpecterOps
NTLM relay attacks targeting SMB restrict lateral movement options to those that solely require port 445/TCP. Learn at least one method of overcoming this restriction to enable additional lateral move...
000
mig 🇺🇦 @miguelaya.bsky.social · 21/07/2025
New LPE github.com/rtecCyberSec...
github.com
GitHub - rtecCyberSec/RAITrigger: Local SYSTEM auth trigger for relaying
Local SYSTEM auth trigger for relaying. Contribute to rtecCyberSec/RAITrigger development by creating an account on GitHub.
010
mig 🇺🇦 @miguelaya.bsky.social · 19/07/2025
specterops.io/blog/2025/07...
specterops.io
I’d Like to Speak to Your Manager: Stealing Secrets with Management Point Relays - SpecterOps
Network Access Account, Task Sequence, and Collection Settings policies can be recovered from SCCM by relaying a remote management point site system to the site database server.
010
mig 🇺🇦 @miguelaya.bsky.social · 15/07/2025
This is such a great upgrade, thx @specterops.io specterops.io/blog/2025/07...
specterops.io
LudusHound: Raising BloodHound Attack Paths to Life - SpecterOps
LudusHound is a tool for red and blue teams that transforms BloodHound data into a fully functional, Active Directory replica environment via the Ludus framework for controlled testing.
020
mig 🇺🇦 @miguelaya.bsky.social · 14/07/2025
Agree laforge.gnumonks.org/blog/2025070...
laforge.gnumonks.org
Security Issues regarding GSMA eSIMs / eUICCs + Javacard
The independent security researcher Adam Gowdiak has published an extensive report on flaws he found in some eUICCs (the chips used to store eSIM profiles within the GSMA eSIM architecture). While th
000
mig 🇺🇦 @miguelaya.bsky.social · 14/07/2025
Opsec for accessing Shadow Volumes www.linkedin.com/posts/stepha...
linkedin.com
During a recent incident response case, my colleague Yann M. | Stephan Berger
During a recent incident response case, my colleague Yann M. observed the following file access: \\localhost\C$\@ GMT-2025.06.21-10.53.43\Windows\NTDS\ntds.dit This is a...
000
mig 🇺🇦 @miguelaya.bsky.social · 27/06/2025
via @orangecyberdefense.bsky.social Turn-based pseudointeractive shell sensepost.com/blog/2025/no...
sensepost.com
SensePost | No egress, no shell, no problem
Leaders in Information Security
000
Reposted by mig 🇺🇦
SpecterOps @specterops.io · 26/06/2025
How attackers move between AD domains via trusts depends on trust type & config. We're replacing TrustedBy edge in BloodHound with new trust edges for better attack path mapping. Check out @jonas-bk.bsky.social's blog post to learn more. ghst.ly/4lj9C5T
ghst.ly
Good Fences Make Good Neighbors: New AD Trusts Attack Paths in BloodHound - SpecterOps
The ability of an attacker controlling one domain to compromise another through an Active Directory (AD) trust depends on the trust type and configuration. To better map these relationships and make i...
084
mig 🇺🇦 @miguelaya.bsky.social · 26/06/2025
New AD attack path specterops.io/blog/2025/06...
specterops.io
Untrustworthy Trust Builders: Account Operators Replicating Trust Attack (AORTA) - SpecterOps
Account Operators can compromise an Active Directory domain by using Incoming Forest Trust Builders and DnsAdmins to create a trust with TGT delegation enabled.
000
mig 🇺🇦 @miguelaya.bsky.social · 18/06/2025
www.p1sec.com/white-paper/... via @p1security.bsky.social
p1sec.com
Attacking GRX: Uncovering Security Risks in GPRS Roaming eXchange Networks
Explore the vulnerabilities of the GPRS Roaming eXchange (GRX) network, its exposure to cyber threats, and the critical security measures needed to protect mobile operators and nation-state infrastruc...
011
mig 🇺🇦 @miguelaya.bsky.social · 17/06/2025
g3tsyst3m.github.io/binary%20exp...
g3tsyst3m.github.io
Buffer Overflows in the Modern Era - Part 1
Last year I challenged myself to successfully revisit buffer overflows on a fully patched and updated version of Windows 11. Specifically, Windows 11 24H2. The last time I had messed with buffer ove...
100