Skip to content
Latest
Passkey Phishing Shows Why Microsoft 365 Needs Enrollment GuardrailsCyclops Blink on Cisco FMC Shows Why Edge Appliances Need Compromise ReviewRevolut Breach Shows Why Data Requests Need Verification ControlsCheck Point VPN Flaws Show Why Remote Access Needs Emergency Patch DisciplineMirth Connect Flaws Show Why Healthcare Middleware Needs Compromise ReviewAI Invoice Fraud Shows Why Finance Needs Verification ControlsAngular SSR Flaws Show Why Hydration and Edge Caches Need Security ReviewSloppyRAT Shows Why Ransomware Defense Has to Watch the Whole Infection FunneltestCloud Web Apps Need Attack-Path Defense, Not Just App ScansTHost9 Shows Why Exposed Android Debug Interfaces Need Compromise ReviewOfferLoader Shows Why Commodity Malware Needs Funnel-Aware DefenseApache Impala Flaws Show Why Data Platforms Need Zero-Trust ControlsChatGPT Sandbox Leak Shows Why AI Agents Need Tenant Isolation

Category Archive

Projects

6 reports·All intelligence

Bulwark Black cyber threat intelligence filed under Projects.

Projects
Velvet Tempest Ransomware Group Deploys CastleRAT via ClickFix Attacks Linked to Termite Operations
Projects·

Velvet Tempest Ransomware Group Deploys CastleRAT via ClickFix Attacks Linked to Termite Operations

Five-Year Ransomware Affiliate Uses Malvertising and Legitimate Windows Tools in Sophisticated Intrusion Security researchers at MalBeacon have exposed a 12-day intrusion campaign by Velvet Tempest (also tracked as DEV-0504), a prolific ransomware affiliate group now deploying th

Becoming Self Sufficient
Complete Guide: Setting Up FreePBX with VPS, Docker, and VPN (CGNAT Bypass Solution)
Becoming Self Sufficient·

Complete Guide: Setting Up FreePBX with VPS, Docker, and VPN (CGNAT Bypass Solution)

Complete FreePBX Setup Guide – Docker, VPN, and Twilio Integration Requirements / Setup Digital Ocean or whatever cloud provider you choose Docker (FreePBX) Nginx Setup OVPN Configuration IP Tables Setup YeaLink Phone configuration, the (YeaLinkT45w) was used in this tutorial Twi

Bug Bounty
Book.HackTricks
Bug Bounty·

Book.HackTricks

To the Book! Disclaimer This book, ‘HackTricks,’ is intended for educational and informational purposes only. The content within this book is provided on an ‘as is’ basis, and the authors and publishers make no representations or warranties of any kind, express or implied, about

Offensive Devices / Tactics
How to protect Evilginx using Cloudflare and HTML Obfuscation
Offensive Devices / Tactics·

How to protect Evilginx using Cloudflare and HTML Obfuscation

Read Article Using a combination of Cloudflare and HTML Obfuscation, it is possible to protect your Evilginx server from being flagged as deceptive and so increase your chances of success on Red Team and Social Engineering engagements. Anyone who has tried to run a Social Enginee

Offensive Devices / Tactics
PWNAGOTCHI: DEEP REINFORCEMENT LEARNING FOR WIFI PWNING!
Offensive Devices / Tactics·

PWNAGOTCHI: DEEP REINFORCEMENT LEARNING FOR WIFI PWNING!

Project Site Pwnagotchi is an A2C-based “AI” powered by bettercap and running on a Raspberry Pi Zero W that learns from its surrounding WiFi environment in order to maximize the crackable WPA key material it captures (either through passive sniffing or by performing deauthenticat

Business
Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike
Business·

Automating C2 Infrastructure with Terraform, Nebula, Caddy and Cobalt Strike

Read Article The ability to quickly build out a C2 infrastructure within a few minutes, including all the set up and tear down logic included would be a great asset for any offensive security group or operator. In this post, I will show exactly how to build a fully automated func

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.