Skip to content
Latest
Langflow RCE Shows Why AI Workflow Tools Need Cloud-Grade IsolationBINDCLOAK Shows Why C2 Detection Needs Message-Level VisibilityPasskey Attacks Show Why Passwordless Still Needs Endpoint DefenseDPRK npm Compromises Show Why Dependency Trust Is Now Identity RiskN-able N-central Exploitation Shows Why MSP Tools Are Control-Plane RiskHOLLOWGRAPH Shows Why Microsoft 365 Is Now Part of the C2 BattlefieldFuyao Android TV Botnet Shows Why Cheap Streaming Sticks Are Business Network RiskSonicWall SMA Exploit Chain Shows Why VPN Appliances Need Incident Response, Not Just PatchingAdform Script Compromise Shows Why Third-Party Tags Need Supply-Chain ControlsCaptiveCrunch Shows Why Travel Wi-Fi Is Now an Identity Attack SurfaceXCSSET v40 Shows Why Developer Macs Are Supply-Chain Infrastructure84 4G/5G Core Flaws Show Why Telecom Trust Zones Need Zero TrustAstaroth WhatsApp Web Spambot Shows Browser Sessions Are Distribution InfrastructureTA488 Turns Outlook Web Access Into a Stealthy Persistence Layer

Category Archive

Red Teaming

10 reports · All intelligence

Offensive operations and adversary simulation — tradecraft, tooling, and the techniques red teams use in the field.

Red Teaming
I Got In Without A Badge Easy!? Social Engineering Strategies.
Red Teaming·

I Got In Without A Badge Easy!? Social Engineering Strategies.

People assume social engineering is all charm and quick thinking. But real operators know the truth:Preparation is the payload.Execution is just the final click. This is how I walked into a secured corporate building twice without a badge, without clearance, and without triggerin

General CTI
THIS WEEK IN SECURITY: LOOP DOS, FLIPPER RESPONDS, AND MORE!
General CTI·

THIS WEEK IN SECURITY: LOOP DOS, FLIPPER RESPONDS, AND MORE!

by: Jonathan Bennett Here’s a fun thought experiment. UDP packets can be sent with an arbitrary source IP and port, so you can send a packet to one server, and could aim the response at another server. What happens if that response triggers another response? What if you could cra

Red Teaming
Bypassing EDRs With EDR-Preloading
Red Teaming·

Bypassing EDRs With EDR-Preloading

READ ARTICLE Marcus Hutchins Previously, I wrote an article detailing how system calls can be utilized to bypass user mode EDR hooks. Now, I want to introduce an alternative technique, “EDR-Preloading”, which involves running malicious code before the EDR’s DLL is loaded into the

Bug Bounty
Detecting API endpoints and source code with JS Miner
Bug Bounty·

Detecting API endpoints and source code with JS Miner

Read Article DANA EPP’S BLOG Security (de)engineering for fun and profit Let’s be honest. Most APIs are naked without some sort of web app frontend calling it. These days, those apps are usually written in some sort of framework based on Javascript. With a bit of work, we can do

Bug Bounty
Book.HackTricks
Bug Bounty·

Book.HackTricks

To the Book! Disclaimer This book, ‘HackTricks,’ is intended for educational and informational purposes only. The content within this book is provided on an ‘as is’ basis, and the authors and publishers make no representations or warranties of any kind, express or implied, about

Offensive Devices / Tactics
Active Directory Penetration Testing Orange Cyber-defense mind maps
Offensive Devices / Tactics·

Active Directory Penetration Testing Orange Cyber-defense mind maps

Get Mind Map!

Bug Bounty
SQLmap Cheat Sheet
Bug Bounty·

SQLmap Cheat Sheet

Link to Sheet

Bug Bounty
Announcing cvemap from ProjectDiscovery
Bug Bounty·

Announcing cvemap from ProjectDiscovery

Read Article Project Discovery Tool ManagerGitHub pdtm is a simple and easy-to-use golang based tool for managing open source projects from ProjectDiscovery. Security professionals are constantly on guard against cyber threats, especially given the rising number and sophisticatio

Offensive Devices / Tactics
How to protect Evilginx using Cloudflare and HTML Obfuscation
Offensive Devices / Tactics·

How to protect Evilginx using Cloudflare and HTML Obfuscation

Read Article Using a combination of Cloudflare and HTML Obfuscation, it is possible to protect your Evilginx server from being flagged as deceptive and so increase your chances of success on Red Team and Social Engineering engagements. Anyone who has tried to run a Social Enginee

Business
How to Leverage Internal Proxies for Lateral Movement, Firewall Evasion, and Trust Exploitation
Business·

How to Leverage Internal Proxies for Lateral Movement, Firewall Evasion, and Trust Exploitation

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.