πππ
πππ
It's here.
The latest iteration of our Top 10 includes the most important developments in initial access tradecraft; from macOS targeting of ClickFix, to Zip Smuggling, to QRLJacking.
Blog:
With a process that began two and a half years ago, I'm very excited to announce that I've written a book with @nostarchpress.bsky.social! π
"Practical Purple Teaming" tells you all you need to know to get started with collaborative offensive testing.
nostarch.com/purple-teaming
β οΈ CVE-2025-21298 - A vuln in Windows could enable remote code execution via a crafted RTF file, just by the user previewing the file in Outlook
π‘οΈ We've added a POC to delivr.to to test deliverability: delivr.to/?id=d22c9632...
π Detect RTFs with our Sublime rule: sublime.security/feeds/delivr...
Twice a year we take a deep dive into the latest, notable tradecraft that has caught our attention in the world of phishing and initial access over the past six months. From Pastejacking, to image-less QR codes, to zip concatenation.
π Read our new Top 10: blog.delivr.to/delivr-tos-t...
Blue Team Con 2025. Training + Conference. September 4-7. Fairmont Chicago. www.blueteamcon.com
@volexity.comβs latest blog post describes in detail how a Russian APT used a new attack technique, the βNearest Neighbor Attackβ, to leverage Wi-Fi networks in close proximity to the intended target while the attacker was halfway around the world.Β
Β
Read more here: www.volexity.com/blog/2024/11...
I made a Detection Engineering starter pack, will be adding more as more folks jump over to bluesky! go.bsky.app/HenXJUR
New place, same content from delivr.to π¦π
This is a really simple, but effective, initial access technique for evading mail filtering and delivering blocked file types (the original sample straight-up delivers an EXE π). Great research from Perception Point!
hey hey! π