Honteux. L'objectif d'une redteam sera toujours de protèger pas juste de pwn...

Randori discovered and used a Palo Alto Networks GlobalProtect VPN zero-day (CVE-2021-3064) as part of its red team engagements for a year before disclosing the issue to the vendor


Check our new internship position! Let's hunt backdoors, tools or configurations that could maintain the (silent) presence of an attacker in a system. Good knowledge required in Windows and ready-to-learn in computer forensics.
🇫🇷 synacktiv.com/recherche-sur-le

Turns out CVE-2021-22205 has been actually a pre-auth RCE, unlike what original advisory stated. security.humanativaspa.it/gitl

🇫🇷 ANSSI does not recommend anymore to enforce password expiry, except for privileged accounts.
Of course renewal must be triggered if a leak is suspected.

Big change with the end of this old rule. France finally in line with other international recommendations. twitter.com/ANSSI_FR/status/14

Unauthenticated Remote Code Execution (RCE) vulnerability in Hikvision IP cameras/NVR firmware ,Patch now (*CVE-2021-36260) : watchfulip.github.io/2021/09/1 credits @Watchful_IP@twitter.com

[🛡️ ] Bienvenue à @ACEService2@twitter.com qui rejoint le .
ACE Service accompagne ses clients depuis plus de 10 ans sur leurs problématiques de cybersécurité en fournissant des services autour de : l'audit, l'intégration, la mise en œuvre et l'hébergement.

🔴 : l'AP-HP annonce avoir porté plainte auprès du Procureur de la République de Paris après avoir constaté le vol de fichiers contenant des données nominatives, à la suite d’une attaque informatique conduite au cours de l’été et confirmée le 12 septembre dernier.

Sigma rule to detect CVE-2021-40444 exploitation activity

- Office program with control.exe child seems to be stable enough (1 exception)
- also works for the RTF vector twitter.com/WLesicki/status/14
- control.exe + .cpl isn't good enough


Une vulnérabilité critique du composant MSHTML de Microsoft a été détectée et peut mener à une exécution de code. Pour le moment pas de patch officiel mais des contournements sont possibles notamment via la désactivation d'ActiveX.


Top 10 2021 DRAFT is out!!!
Now available for peer review, comment, translation, and suggestions for improvements:


Need local admin and have physical access?
- Plug a Razer mouse (or the dongle)
- Windows Update will download and execute RazerInstaller as SYSTEM
- Abuse elevated Explorer to open Powershell with Shift+Right click

Tried contacting @Razer@twitter.com, but no answers. So here's a freebie

Here's a quick cheatsheet on moving your cursor quickly in bash.

idk why I havent thought of this before, but its very easy to hide those "external sender" warnings that get appended to your emails during phishing campaigns 🤔. Email gateways/FW just add HTML at the start/end of emails, simply add CSS to hide it!

See images:

tmpmail : A temporary email right from your terminal written in POSIX sh : github.com/sdushantha/tmpmail credits @sidheart@twitter.com

Je ne pensais pas avoir besoin d'un MiSTer jusqu'à ce que je vois ces beautés 😍

🥁 We're thrilled to announce that we've raised €16M in our Series B funding! So today, we want to thank you, hunters, for making up our community. We wouldn’t be here without you!
Full announcement: bit.ly/3hVXBWp

