𝙍𝙤𝙤𝙩𝙎𝙚𝙘
Open in Telegram
Free content of OFF-SEC, SANS, ec-council, INE, eLearnSecurity, udemy coupons and many more #Malware_analysis #RootSec
Show more1 774
Subscribers
+224 hours
+127 days
+2830 days
Posts Archive
1 774
Repost from 🇮🇳WIZARDSEC🦅
+8
In action of ongoing cyberattacks or trolls by some kanglu hookers with their 3rd class so called hooking (2sec ddos and 3rd grade web hacking )
We Decided To Step In And We Did It
Bangladesh Navy Submarine Branch Has Been Compromised And Wiped Out
We Got Acces To Their Internal Server
Private Databases And Every Single Task Given To Them , 10 Years Database Of Their Work
Who Am I ?
That's None Of Your Work
Jaii Hind Jaii Bharat 🇮🇳
1 774
#tools
#Fuzzing
"Hunting CUDA Bugs at Scale with cuFuzz", Mar. 2026.
]-> https://github.com/NVlabs/cuFuzz
// A GPU-oriented coverage-guided fuzzer for userland CUDA applications
1 774
#AIOps
#MLSecOps
#Infosec_Standards
NIST AI 800-4:
"Challenges to the Monitoring of Deployed AI Systems", March 2026.
1 774
#exploit
#reversing
1⃣ Getting a Shell on the Tapo C260 Camera (CVE-2026-0651, CVE-2026-0652, CVE-2026-0653)
https://spaceraccoon.dev/getting-shell-tapo-c260-webcam
// Reverse-engineered Tapo C260 firmware reveals vulnerabilities enabling local file disclosure and full RCE through path traversal and configuration manipulation
2⃣ nginx UI Vulnerability
https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762
// CVE-2026-27944 (9.8/10)
3⃣ Patch diff to SYSTEM
https://www.elastic.co/security-labs/patch-diff-to-system
// Researchers utilized LLMs and patch diffing to develop a reliable privilege escalation exploit for Windows DWM via a UAF, demonstrating AI's growing role in vulnerability discovery and exploitation
4⃣ Reverse engineering Claude's CVE-2026-2796 exploit
https://red.anthropic.com/2026/exploit
]-> Claude Code skill to support Android app's reverse engineering
// Disclaimer
1 774
#Whitepaper
#Threat_Research
"Autonomous Threat Emulation and Detection Using Agentic AI", Jan. 2026.
// Traditional threat emulation frameworks struggle to capture the dynamic and adaptive behaviours of modern APTs, leaving defenders reliant on static tests that quickly become obsolete. Existing open-source BAS frameworks, such as MITRE Caldera and Atomic Red Team, provide structured, repeatable adversary simulations; however, their behaviour remains largely prescripted and dependent on continuous human tuning. This paper presents an agentic AI-driven threat emulation and detection framework that adapts attack tactics in response to defensive telemetry
1 774
#Mobile_Security
#5G_Network_Security
"Ghost SIM Attack:
How to take advantage of weak authentication policies in 2G, 3G, 4G and 5G mobile networks", 2026.
// Presents a comprehensive overview of the experimental setup and methodology utilized to execute the Ghost SIM Attack, along with an in-depth analysis of the authentication policies implemented by various operators and technologies across multiple countries around the world. The results reveal that the Ghost SIM Attack is successful across all the selected technologies and operators highlighting the weak authentication policies configured
1 774
#CogSec
#Analytics
"How Effective Are Publicly Accessible Deepfake Detection Tools? A Comparative Evaluation of Open-Source and Free-to-Use Platforms", Mar. 2026.
// This paper presents the first cross-paradigm evaluation of six tools, spanning two complementary detection approaches: forensic analysis tools (InVID \& WeVerify, FotoForensics, Forensically) and AI-based classifiers (DecopyAI, FaceOnLive, Bitmind)
1 774
Repost from Rootsec
📌13 ai tools to finish months of work in minutes!
1. Image Generator ⇢ leonardo.ai
2. Writing & Automation ⇢ blaze.today
3. Meeting Assistant ⇢ tactiq.io
4. Productivity/Note-taking ⇢ anytype.io
5. Chat Assistant ⇢ claude.ai
6. Video Generation ⇢ app.pixverse
7. Search Engine ⇢ phind.com
8. Avatar Video Creation ⇢ heygen.com
9. Chatbot service ⇢ manychat.com
10. Audio/Video Editing ⇢ descript.com
11. Coding Assist ⇢ codeium.com
12. Video Edit ⇢ runwayml.com
13. Voice Generation ⇢ elevenlabs.io
1 774
#Offensive_security
A Deep Dive into the GetProcessHandleFromHwnd API
https://projectzero.google/2026/02/gphfh-deep-dive.html
// From Windows XP to Windows 11 24H2
See also:
]-> PPLwindow PPL Bypass via GetProcessHandleFromHwnd
1 774
#DevOps
"Authoritative Guide to AI/ML-BOM:
Drive Transparency, Compliance, and Security Across the AI Supply Chain", First Edition, Mar. 2026.
// An ML-BOM (Machine Learning Bill of Materials) is a document to address the unique complexities and risks of AI/ML systems. It provides a detailed inventory of all components, configurations, and processes involved in the development, training, deployment, and hosting (i.e., via hardware/software stacks and frameworks) of a ML model
1 774
#AIOps
#MLSecOps
#Infographics
MITRE ATT&CK ATLAS v.5.4.0 (Feb 2026):
1 matrix, 16 tactics, 97 techniques, 58 sub-techniques, 35 mitigations, and 52 case studies
https://atlas.mitre.org/resources/updates/2026-02
]-> ATLAS Data v.5.4.0
// Added new techniques, Updated existing techniques, Added new case studies, Fixed typos
1 774
#Research
#MLSecOps
"Real Money, Fake Models: Deceptive Model Claims in Shadow APIs", Mar. 2026.
// Through multidimensional auditing of three representative shadow APIs across utility, safety, and model verification, we uncover both indirect and direct evidence of deception practices in shadow APIs
1 774
#AIOps
#Research
"CIBER: A Comprehensive Benchmark for Security Evaluation of Code Interpreter Agents", Feb. 2026.
// CIBER - automated benchmark that combines dynamic attack generation, isolated secure sandboxing, and state-aware evaluation to systematically assess the vulnerability of code interpreter agents against four major types of adversarial attacks: Direct/Indirect Prompt Injection, Memory Poisoning, and Prompt-based Backdoor
