Sign in

ocdsec

@ocdsec.bsky.social
219 followers 492 following 11 posts

🏴‍☠️ 💚 🇺🇦 computer tester | 603,628 km²

PostsRepliesMedia
Reposted by ocdsec
ZAP by Checkmarx @zaproxy.org · 01/07/2026
ZAP Blog: June Updates www.zaproxy.org/blog/2026-07... More PTK integration, lots of Client Spider improvements, and much more.. #zaproxy #appsec
zaproxy.org
ZAP Updates - June 2026
In June the OWASP PTK add-on graduated to beta with its integration now properly matching ZAP’s architecture, a security advisory was issued and patched for the Viewstate add-on, and the Client Spider...
063
Reposted by ocdsec
RastaMouse @rastamouse.me · 22/01/2026
A nice workaround against my YARA rule. kuwaitist.github.io/posts/Patchi...
kuwaitist.github.io
Patching Crystal Palace: bypassing detection
Lately I’ve been studying CRTL which focuses on developing offensive tradecraft using Crystal palace framework. I never had the chance to use it before this, so am not an expert in any type of way.
092
Reposted by ocdsec
Catalin Cimpanu @campuscodi.risky.biz · 07/12/2025
A Chinese think tank has published a hit piece on seven cybersecurity and policy experts specializing in Chinese cyber operations www.guancha.cn/xinzhiguanch...
154
Reposted by ocdsec
InfoSec @infosec.skyfleet.blue · 02/12/2025
Ukraine Hackers Attacking Russian Aerospace Companies and Other Defence-Related Sectors
cybersecuritynews.com
Ukraine Hackers Attacking Russian Aerospace Companies and Other Defence-Related Sectors
041
Reposted by ocdsec
pard0p.bsky.social @pard0p.bsky.social · 02/11/2025
LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes. github.com/pard0p/LibIPC
github.com
GitHub - pard0p/LibIPC: LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes.
LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes. - pard0p/LibIPC
054
Reposted by ocdsec
Bryan Steele 🦋🍁 @brynet.ca · 29/09/2025
Slides from Alexander Bluhm (bluhm@)'s talk "Update on #OpenBSD Networking Performance Improvements" today at #EuroBSDcon 2025. www.openbsd.org/papers/eurob...
events.eurobsdcon.org
Update on OpenBSD Networking Performance Improvements EuroBSDCon 2025
Since my previous talk about this topic in 2022 major improvements in the OpenBSD network stack have been achieved. The socket API has been unlocked in the kernel. This means that multiple userland ...
012
Reposted by ocdsec
InfoSec @infosec.skyfleet.blue · 12/08/2025
Netscaler vulnerability was exploited as zero-day for nearly two months (CVE-2025-6543)
helpnetsecurity.com
Netscaler vulnerability was exploited as zero-day for nearly two months (CVE-2025-6543) - Help Net Security
The CVE‑2025‑6543 NetScaler ADC vulnerability - patched in late June 2025 - has been exploited as a zero-day vulnerability since May 2025.
011
Reposted by ocdsec
InfoSec @infosec.skyfleet.blue · 07/07/2025
New Batavia spyware targets Russian industrial enterprises
securityaffairs.com
New Batavia spyware targets Russian industrial enterprises
Since March 2025, fake contract emails have been spreading Batavia spyware in targeted attacks on Russian organizations.
022
Reposted by ocdsec
InfoSec @infosec.skyfleet.blue · 07/06/2025
Hundreds of GitHub Malware Repos Targeting Novice Cybercriminals Linked to Single User
cybersecuritynews.com
Hundreds of GitHub Malware Repos Targeting Novice Cybercriminals Linked to Single User
032
Reposted by ocdsec
Will Dormann @wdormann.infosec.exchange.ap.brid.gy · 25/02/2025
From over at the Bad Place: There's an interesting NTFS symlink attack outlined here: dfir.ru/2025/02/23/symlink-attacks-… Basically, if an NTFS filesystem is corrupted in a way to provide duplicate file names, Windows will […] [Original post on infosec.exchange]
Powershell: after 5 "type .\5\test.txt" calls, the test.txt file is a symlink to win.ini
CMD: A single "type .\6\test.txt" call results in every single file being printed, including the final win.ini symlink
11613
Reposted by ocdsec
Dustrial @dustrial.net · 27/03/2025
cybercrime but its bigger and on both sides.
cybercrime zeroday faded tee
6499
Reposted by ocdsec
netbiosX @netbiosx.bsky.social · 09/03/2025
github.com
GitHub - DarkSpaceSecurity/RunAs-Stealer: RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging
RunAs Utility Credential Stealer implementing 3 techniques : Hooking CreateProcessWithLogonW, Smart Keylogging, Remote Debugging - DarkSpaceSecurity/RunAs-Stealer
031
Reposted by ocdsec
Catalin Cimpanu @campuscodi.risky.biz · 24/02/2025
VulnCheck has extracted and made a list of all the CVEs mentioned in a recent leak from the internal Matrix chat server of the BlackBasta ransomware group. The list includes 62 vulnerabilities. VulnCheck says the group focuses on CVEs with already public exploits vulncheck.com/blog/black-b...
1247
Reposted by ocdsec
evacide @evacide.bsky.social · 24/02/2025
I cannot overstate the value of being in community with other activists right now. It is what gives me the strength to get up in the morning and fight fascism.
611817200
Reposted by ocdsec
Catalin Cimpanu @campuscodi.risky.biz · 25/02/2025
"Over the course of the GitVenom campaign, the threat actors behind it have created hundreds of repositories on GitHub that contain fake projects with malicious code" Campaign delivers an infostealer, obviously. The threat-du-jour these days securelist.com/gitvenom-cam...
securelist.com
Fake GitHub projects distribute stealers in GitVenom campaign
Kaspersky researchers discovered GitVenom campaign distributing stealers and open-source backdoors via fake GitHub projects.
093
Reposted by ocdsec
netbiosX @netbiosx.bsky.social · 18/01/2025
elastic.co
Detonating Beacons to Illuminate Detection Gaps — Elastic Security Labs
Learn how Elastic Security leveraged open-source BOFs to achieve detection engineering goals during our most recent ON week.
031
Reposted by ocdsec
Mark Manning @antitree.com · 11/01/2025
I just finished our #shmoocon talk on container security. Here's my seccomp bpf disassembler and diffing tool. github.com/antitree/sec...
github.com
GitHub - antitree/seccomp-diff
Contribute to antitree/seccomp-diff development by creating an account on GitHub.
03711
Reposted by ocdsec
Alexandre Borges @alexandreborges.bsky.social · 02/01/2025
Diving into ADB protocol internals: part 01: www.synacktiv.com/publications... part 02: www.synacktiv.com/en/publicati... #adb #mobile #protocol #informationsecurity #cybersecurity #reverseengineering
031
Reposted by ocdsec
ϻг_ϻε @steven.srcincite.io · 22/12/2024
These are some really nice blog posts regarding algo confusion bugs in JWT by @pentesterlab.com pentesterlab.com/blog/jwt-alg... & pentesterlab.com/blog/another... nice one @snyff.pentesterlab.com!
pentesterlab.com
PentesterLab Blog: Another JWT Algorithm Confusion Vulnerability: CVE-2024-54150
Discover how a code review uncovered a JWT algorithm confusion vulnerability (CVE-2024-54150). Learn key insights to enhance your security skills and spot vulnerabilities effectively.
1205
Reposted by ocdsec
UK 🇬🇧 🤝 🇺🇦 □ @ukbastard.bsky.social · 19/12/2024
Ruble to fall to 200 per dollar: Russian economist warns of approaching catastrophe – media читайте подробнее на сайте "Диалог.UA": www.dialog.ua/business/306...
dialog.ua
Курс рубля рухнет до 200 за доллар: экономист в РФ предупредил о приближении катастрофы – СМИ
В России скопилась огромная рублёвая масса, которая уже вскоре хлынет на рынок и вызовет массовый спрос на валюту, это обвалит курс рубля как минимум до 200 за доллар.
4158
Reposted by ocdsec
netbiosX @netbiosx.bsky.social · 21/12/2024
beierle.win
Weaponizing WDAC: Killing the Dreams of EDR
051
Reposted by ocdsec
Taggart @taggart-tech.com · 20/12/2024
Wow, a fairly serious auth bypass in Next.js, a super popular frontend framework: "If a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed." securityonline.info/...
securityonline.info
CVE-2024-51479: Next.js Authorization Bypass Vulnerability Affects Millions of Developers
Find out about the Next.js vulnerability CVE-2024-51479 that could have exposed sensitive data. Take necessary measures to secure your Next.js application.
0114
Reposted by ocdsec
Bryan Steele 🦋🍁 @brynet.ca · 18/12/2024
The #OpenBSD Foundation is currently at ~$230,280 (65%) raised of the $350,000 goal for their 2024 Fundraising Campaign, and it's nearly the end of December. 🐡 www.openbsdfoundation.org/campaign2024... www.openbsdfoundation.org/donations.html Donations fund events for developers, infra. costs.
011
Reposted by ocdsec
Amethyst Basilisk @amethyst.systems · 07/12/2024
I did a blog instead of working on my projects again. This time a maldev blog talkin' about PE runtime decryption and other ways to be an asshole to the analyst. amethyst.systems/blog/posts/v... #infosec #malware
amethyst.systems
Various Ways to Be an Asshole with Runtime PE Decryption
I am currently procrastinating undoing the mess I made with CMake files for a bigger project I’m working on. It’s not hard– it’s just annoying, and I have no one to blame but myself. I did this intent...
02610
Reposted by ocdsec
Raphaela Mettig @rmettig.com · 06/12/2024
The #OBTS day 2 livestream is on! www.youtube.com/watch?v=Nm0z...
youtube.com
Objective by the Sea v7.0 - Day 2
YouTube video by Objective-See Foundation
022
Reposted by ocdsec
Alexandre Borges @alexandreborges.bsky.social · 05/12/2024
Decrypting CryptProtectMemory without code injection: blog.slowerzs.net/posts/cryptd... #crypto #decryption #cybersecurity #informationsecurity #rdp #windows #programming
blog.slowerzs.net
Decrypting CryptProtectMemory without code injection
082
Reposted by ocdsec
Catalin Cimpanu @campuscodi.risky.biz · 04/12/2024
"We can now share that our latest investigation also found links between some of Doppelganger’s activities and individuals associated with MGIMO (Moscow State Institute of International Relations)." via Meta/PDF: scontent.fotp7-2.fna.fbcdn.net/v/t39.8562-6...
0115
Reposted by ocdsec
Swissky @swissky.bsky.social · 29/11/2024
NTLM Relaying – Making the Old New Again labs.jumpsec.com/ntlm-relayin...
labs.jumpsec.com
NTLM Relaying - Making the Old New Again | JUMPSEC LABS
I am old enough to remember that it was not always possible to get domain admin within the first hour of a test via Active Directory Certificate Services (ADCS) misconfigurations or over permissioned ...
081
Reposted by ocdsec
David Kennedy @cyb3rc3lt.bsky.social · 15/11/2024
Great article on ESC15 especially after you realise PKInit won't work to auth but there is a workaround supplied too. medium.com/@offsecdeer/...
medium.com
ADCS Exploitation Series — Part 2: Certificate Mapping + ESC15
Certificate mapping is the process at the heart of multiple ADCS vulnerabilities, so I thought it would be appropriate to dedicate it its…
162
Reposted by ocdsec
Ninja Owl @ninjaowl.ai · 28/11/2024
XMLRPC npm Library Turns Malicious, Steals Data, Deploys Crypto Miner #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
122
Reposted by ocdsec
onion person @junlper.beer · 21/11/2024
despite the world becoming scary i still have a perhaps niave but unwaivering belief that a better world is possible
788327945367
Reposted by ocdsec
Lukasz Olejnik @lukaszolejnik.bsky.social · 22/11/2024
Cyberattackers may have compromised lots of organizations by exploiting two zero-day vulnerabilities found in widely used Palo Alto Networks systems. unit42.paloaltonetworks.com/cve-2024-001...
0179
Reposted by ocdsec
netbiosX @netbiosx.bsky.social · 22/11/2024
fluxsec.red
EDR Evasion: ETW Patching in Rust
Learn how to patch ETW using Rust for evading EDR detection. This detailed guide includes explanations, code snippets, and testing procedures to enhance stealth in offensive security operations.
073
Reposted by ocdsec
SpecterOps @specterops.io · 20/11/2024
Learn how BARK's latest functions enhance adversarial tradecraft research relevant to Azure Key Vault. In his blog post, @andyrobbins.bsky.social shares an example of how a #redteam operator may use these commands over the course of an assessment. Read more 👉 ghst.ly/3CEtXSo
042
Reposted by ocdsec
dmnk @dmnk.bsky.social · 21/11/2024
Rust pseudo code 👀 🦀🦀🦀
0101
Reposted by ocdsec
TomNomNom @tomnomnom.com · 20/11/2024
miss these guys
A group of 9 hackers stood in a colourful alleyway in VancouverA group of 9 women from a K-Pop band in the same colourful alleyway in Vancouver.
3233
Reposted by ocdsec
its-a-feature.bsky.social @its-a-feature.bsky.social · 18/11/2024
I'm going to be working on the DNS C2 Profile for Mythic this week (designing it), so if anybody has specific requests, comments, ideas, suggestions, etc, let me know! Also going to track a discussion here: github.com/its-a-featur...
github.com
DNS C2 Spec · its-a-feature Mythic · Discussion #418
On the roadmap for Mythic is to create a DNS C2 profile, so I'd like to start a discussion as to the features, requirements, and specifications people would like to see in it before we start the de...
3111
Reposted by ocdsec
Phil Stokes ⫍🐠⫎ @philofishal.bsky.social · 18/11/2024
Oh, that’s another handy #r2 #malware triage trick: print out the xrefs to all flagged strings: > axt @@ str* 👌
Output of the axt command in radare2 showing the strings and criss references found.
1133
Reposted by ocdsec
netbiosX @netbiosx.bsky.social · 17/11/2024
systemweakness.com
BYOVD A Kernel Attack: Stealthy Threat to Endpoint Security
Introduction:
031
Reposted by ocdsec
netbiosX @netbiosx.bsky.social · 17/11/2024
C++ code designed to easily perform stack spoofing with a fake stack frame after the gadget. This project is based on LoudSunRun, but instead of using the jmp RBX gadget, it utilizes jmp RDI
github.com
GitHub - NtDallas/Fenrir: stack spoofing
stack spoofing. Contribute to NtDallas/Fenrir development by creating an account on GitHub.
082
Reposted by ocdsec
James Kettle @jameskettle.com · 17/11/2024
We’re finally live! You can now watch “Listen to the whispers: web timing attacks that actually work” on YouTube: youtube.com/watch?v=zOPj...
youtube.com
YouTube
Share your videos with friends, family, and the world
0359
Reposted by ocdsec
Jeff Geerling @jeffgeerling.com · 15/11/2024
AMD 7000-series graphics cards now work on Raspberry Pi. 4K Doom Eternal. 4K Crysis. OBS hardware video transcoding. It all works!!! It's not perfect, but what graphics card driver is? Here's the video: www.youtube.com/watch?v=7Qx_... (more details on my blog).
youtube.com
My Raspberry Pi has a better GPU than Apple's M4 Pro
YouTube video by Jeff Geerling
1220317
Reposted by ocdsec
Raye @sweetbabyraye.bsky.social · 16/11/2024
All that’s gonna be left on X is bots talking to each other 😂🤣
48810306765
Reposted by ocdsec
Phillip Wylie @phillipwylie.bsky.social · 16/11/2024
youtu.be/tn9arlUXe6U?...
youtu.be
Mishaal Khan: The Evolution of OSINT in Cybersecurity
YouTube video by Phillip Wylie
0176
Reposted by ocdsec
0xdf @0xdf.bsky.social · 16/11/2024
To solve Axlle from HackTheBox, I'll create and phish with a malicous XLL file, edit a .url file, do some Bloodhound pivots, and abuse StandaloneRunner.exe.
0xdf.gitlab.io
HTB: Axlle
Axlle is a Windows host with some niche Windows exploitation paths. I’ll start by phishing a user using a Excel Add-On file, XLL. These are since mostly blocked, but were previously quite big in the phishing scene. Then I’ll modify a URL file to run my reverse shell. I’ll find come creds for the next user, and change the password on the next. For administrator, I’ll abuse the StandaloneRunner.exe LOLBIN.
061