My top #GitHub list for cybersecurity projects is updated for this month. Explore top FOSS projects spanning both the defensive and offensive sides ππ
Find a high-res pdf book with all my #cybersecurity related infographics from study-notes.org
#infosec #pentesting #informationsecurity
27.01.2026 13:10
π 2
π 1
π¬ 0
π 0
Great read! Very interesting use of stenography to obfuscate payloads.
25.11.2025 13:49
π 1
π 0
π¬ 0
π 0
CISA, eyeing China, plans hiring spree to rebuild its depleted ranks
The agency will also change some of its workforce policies to avoid driving away talented staff.
Scoop: CISA plans to embark on a hiring spree and change some workforce policies in an effort to rebuild its depleted ranks ahead of a possible conflict with China, according to a memo from its acting director that I obtained.
www.cybersecuritydive.com/news/cisa-hi...
17.11.2025 21:30
π 44
π 35
π¬ 8
π 11
We identified a malvertising campaign targeting users searching for legitimate software, leading to the download of a trojanized WinSCP installer that deployed Broomstick/OysterLoader.
All files involved in the initial access phase were signed with valid certificates.
16.10.2025 13:29
π 2
π 1
π¬ 1
π 0
Super helpful thread - thanks for the intel
06.10.2025 16:52
π 0
π 0
π¬ 0
π 0
Kevin Beaumont (@GossiTheDog@cyberplace.social)
Attached: 1 image
LAPSUS$ have now listed the breach at Red Hat on their portal.
They have posted CER - Consulting Engagement Requests. Sensitive info, for AMEX, Atos, HSBC, Walmart, NHS Scotland am...
LAPSUS have the Red Hat gitlab breach up on their portal
Theyβve posted Consulting Engagement Requests for AIR, AMEX_GBT, Atos_Group (NHS Scotland), BOC, HSBC and Walmart. Also a file tree, 370,852 directories, 3,438,976 files.
cyberplace.social/@GossiTheDog...
05.10.2025 23:44
π 20
π 7
π¬ 2
π 0
Shutdown guts U.S. cybersecurity agency at perilous time
The lead U.S. agency for protecting the electric grid, water supply and other critical services from hacking has furloughed most of its staff.
The lead U.S. cyber defense agency has furloughed 65% of its staff. The 20-year-old law that encourages organizations to share information on attacks just expired. Happy Cybersecurity Awareness Month! wapo.st/46Nk53R
02.10.2025 14:51
π 175
π 88
π¬ 13
π 14
New: The Multi-State Information Sharing and Analysis Center lost its federal funding at midnight. Here's my story about what happened, why it matters, and how the group β a critical resource for state and local governments β is trying to move forward: www.cybersecuritydive.com/news/ms-isac...
01.10.2025 14:04
π 55
π 35
π¬ 2
π 6
When sharing articles or open-source intel, be sure to read and digest the entire article. Be an expert on the data or information you're communicating, or things may slip through the cracks.
Don't just be a reposter; communicate *how* or *why* the information being shared is important.
29.09.2025 13:39
π 1
π 0
π¬ 0
π 0
Interview with Cloud Architect in 2025
YouTube video by Kai Lentit
Public S3 Bucket is not a mistake, it's a 'Growth Hacking Funnel'
www.youtube.com/watch?v=xIk0...
25.09.2025 17:43
π 0
π 0
π¬ 0
π 0
Reading material:
www.nsa.gov/Press-Room/P...
27.08.2025 15:01
π 13
π 4
π¬ 1
π 0
FBI has issued an alert about Russian hackers exploiting a vulnerability in Cisco networking devices to target critical infrastructure orgs & do recon on industrial control systems: www.ic3.gov/PSA/2025/PSA...
Cisco also published research on the group: blog.talosintelligence.com/static-tundra/
20.08.2025 17:00
π 8
π 6
π¬ 0
π 0
GitHub - edoardottt/cariddi: Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more - edoardottt/cariddi
Cariddi is a CLI tool for IT pros, developers & infosec pros that scans websites to find hidden endpoints, exposed secrets like API keys and credentials, and sensitive files. It's an ideal tool for bug pentester, providing customizable scans with options for custom endpoint lists, regex patterns etc
19.08.2025 19:03
π 33
π 5
π¬ 0
π 0
Itβs wild that the same day the president did a weird roof dance for no apparent reason, the state dept implements huge visa fees and the head of the HHS cancels vaccine research. This is just one day! And not even all the terrible things that happened! I feel insane!
06.08.2025 03:02
π 56
π 7
π¬ 3
π 1
Scoop: CISA's contract with ICF has expired, reducing the JCDC's contractor workforce from 100+ to just 10. CISA can use emergency money & 2-week extensions to keep those 10 around, but only through Sept. Other contracts also caught up in huge backlog. www.cybersecuritydive.com/news/cisa-jo...
30.07.2025 14:53
π 19
π 13
π¬ 2
π 1
How to disable handsfree mode for bluetooth headphones on windows 11
Bose + Windows 11 + Updates rechecking 'handsfree telophony' has one of the deepest rabbit holes through the Windows 11 settings menu. If your audio sucks, check this out.
www.reddit.com/r/Windows11/...
25.07.2025 15:09
π 0
π 0
π¬ 0
π 0
YouTubeβs July 15th Update: Is Your AI Channel About to Get Demonetized?
For the past few weeks, thereβs been a lot of nervous chatter in the YouTube community, especially among creators who use Artificialβ¦
YouTube's changes for payout of AI generated content is promising. There's so much AI garage that pushes genuine and creative content down.
www.merca20.com/goodbye-yout...
09.07.2025 13:29
π 0
π 0
π¬ 0
π 0
20.06.2025 10:47
π 105
π 33
π¬ 3
π 2
This is a big deal. Predatory Sparrowβs past cyber attacks on Iranian steel plants and gas stations have demonstrated tangible effects in Iran. Disrupting the availability of this bankβs funds, or triggering a broader collapse of trust in Iranian banks, could have major impacts there.
17.06.2025 12:07
π 6
π 1
π¬ 0
π 0
CVE-2025-33053 is really interesting. Setting a working directory to a remote WebDAV location and it works. Even worse than hash coercion since you can run something.
12.06.2025 13:29
π 1
π 1
π¬ 0
π 0
Abuse will continue until we fix the legal system to the point they are afraid to do this on camera.
That's the bare minimum. They must be afraid to be recorded in their misdeeds. If we can't hit that VERY LOW bar, abuse will continue unchecked. That was so obviously assault.
10.06.2025 10:30
π 26
π 6
π¬ 2
π 0
ποΈ New Podcast Episode Dropping Soon!
We dive into our latest public report with Randy Pargman, Jake Ouellette, Kostas T., and Mangatas Tondang.
Stay tuned for deep insights, behind-the-scenes analysis, and expert commentary from the front lines of DFIR. π
10.06.2025 12:06
π 2
π 1
π¬ 1
π 0
Duping Cloud Functions: An emerging serverless attack vector
Cisco Talos built on Tenableβs discovery of a Google Cloud Platform vulnerability to uncover how attackers could exploit similar techniques across AWS and Azure.
Another prime example of 'it's in the cloud, its secure'. It's super important to understand attack vectors in the cloud. Serverless is extremely powerful and popular solution, but not immune to attack or misconfigurations.
blog.talosintelligence.com/duping-cloud...
20.05.2025 13:45
π 0
π 0
π¬ 0
π 0