optionalctf's profile picture. The proud owner of two brain cells. HTB with @barctf | OSCP, CRT, CRTL

optional

@optionalctf

The proud owner of two brain cells. HTB with @barctf | OSCP, CRT, CRTL

مثبتة

Introducing C2structor, a deployment tool to automate red team infrastructure within AWS. Utilising Terraform and Ansible to allow for seamless customisation to each individual's use-case. Currently supports C2 deployment, redirectors and phishing inf. github.com/optionalCTF/C2…


Labour's 1984 shit show is already showing cracks and backfiring. Can't wait to see the shit show Digital ID gets compromised because they rushed to implement something no one wants...

Discord has begun sending e-mails notifications about a cybersecurity incident which occurred September 20th, 2025. It appears people who submitted support tickets are the ones primarily impacted. Literally peoples entire identity stolen from this shit

vxunderground's tweet image. Discord has begun sending e-mails notifications about a cybersecurity incident which occurred September 20th, 2025.

It appears people who submitted support tickets are the ones primarily impacted.

Literally peoples entire identity stolen from this shit


optional أعاد

It gets better ;) I totally forgot about this little persistence method, lol

NathanMcNulty's tweet image. It gets better ;)

I totally forgot about this little persistence method, lol

Hahaha, wow... 😮 If you leave App passwords enabled and enforce MFA through per-user MFA, the MFA enrollment wizard actually makes the user to create an app password 🤯

NathanMcNulty's tweet image. Hahaha, wow... 😮

If you leave App passwords enabled and enforce MFA through per-user MFA, the MFA enrollment wizard actually makes the user to create an app password 🤯


optional أعاد

AWS quietly updated T&Cs to ban “Fireprox”style use of API Gateway closing a handy pentest trick. @ZephrFish and @turvsec already rolled alternatives such as Omniprox and Flareprox. Banning tools only hampers legit testers, attackers will proxy anyway.


optional أعاد

This release is probably going to be one of our biggest and most impactful! Kudos to the team @peterwintrsmith @modexpblog @s4ntiago_p @GigelV41464 @saab_sec 🙌

We're really bringing the 🔥 with our next Nighthawk release - Janus - nighthawkc2.io/janus/

MDSecLabs's tweet image. We're really bringing the 🔥 with our next Nighthawk release - Janus - nighthawkc2.io/janus/


optional أعاد

i never saw this coming

ThePrimeagen's tweet image. i never saw this coming

optional أعاد

PDQ SmartDeploy versions prior to 3.0.2046 used static, hardcoded encryption keys for cred storage. Low-privileged users could potentially access admin creds from registry or deployment files. @unsigned_sh0rt unpacks his testing in his latest blog post. ghst.ly/4mjyuvw


optional أعاد

Developing a scriptable (pwndbg-like) debugger for windows. Few more things we need to iron out but will be releasing soon 🐸

0xLegacyy's tweet image. Developing a scriptable (pwndbg-like) debugger for windows. Few more things we need to iron out but will be releasing soon 🐸

optional أعاد

Here’s my slides from today’s “Regex For Hackers” talk at DEFCON with @NahamSec, bookmark this for some exciting news in the near future docs.google.com/presentation/d…


optional أعاد

Had an awesome time at #DefCon 33. Lots of new discoveries, first time speaking at the #redteamvillage along with @zer0phat and met lots of cool people. Looking forward to the next one!

kreepsec's tweet image. Had an awesome time at #DefCon 33. Lots of new discoveries, first time speaking at the #redteamvillage along with @zer0phat and met lots of cool people. Looking forward to the next one!
kreepsec's tweet image. Had an awesome time at #DefCon 33. Lots of new discoveries, first time speaking at the #redteamvillage along with @zer0phat and met lots of cool people. Looking forward to the next one!

optional أعاد

💻 ModuleOverride – Changing a Tyre Whilst Driving – @zer0phat & @kreepsec teach process injection using existing memory sections to run malicious shellcode. Hands-on demos and detection strategy discussions at @redteamvillage_ during @defcon 33! ⚡

RedTeamVillage_'s tweet image. 💻 ModuleOverride – Changing a Tyre Whilst Driving – @zer0phat & @kreepsec teach process injection using existing memory sections to run malicious shellcode. Hands-on demos and detection strategy discussions at @redteamvillage_ during @defcon 33! ⚡

optional أعاد

#x33fcon 2025 talks: @domchell - Hiding in Plain Sight > youtu.be/GyoxCTYPAus

x33fcon's tweet image. #x33fcon 2025 talks: @domchell - Hiding in Plain Sight > youtu.be/GyoxCTYPAus

optional أعاد
vxunderground's tweet image.

optional أعاد

Happy Friday! We're ending the week by publishing our analysis of Fortinet's FortiWeb CVE-2025-25257.... labs.watchtowr.com/pre-auth-sql-i…


optional أعاد

PSA to anyone struggling, don't be told that "you're just worried", "you're just feeling sad", "you're overthinking things"... depression, anxiety, OCD, ADHD, Autism are killers. Talk, and advocate for yourself!

Finally landed on an OCD diagnosis yesterday, the fucking relief is unreal. Not like it's a shock, but it's been a loooooong time to get to this point. Look after your mental health h4xx0rz! youtube.com/watch?v=NDBRjB…

_xpn_'s tweet card. Sick In The Head

youtube.com

YouTube

Sick In The Head



Nothing like scratching the bug bounty itch with several crits to end the night. Now to rest ready for Steelcon


optional أعاد

Today MSRC fixed two vulnerabilities I reported a couple months ago. EoP in Windows Update service (affects only windows 11/10 with at least 2 drives) msrc.microsoft.com/update-guide/v… EoP in Microsoft PC Manager msrc.microsoft.com/update-guide/v… PoC for CVE-2025-48799: github.com/Wh04m1001/CVE-…


optional أعاد

I'm teaching an intro to cloud security workshop on July 11th. This is a pay what you can course so you can take it for free. I'll also be teaching the full version of my Breaching the Cloud course at @WWHackinFest in October. Registration links below: Workshop:…


optional أعاد

if you're looking for a @Pocket replacement, I built Obsidian Web Clipper — it's open source and works with any app that supports Markdown (not just Obsidian)

Obsidian Bases + Obsidian Web Clipper is the web archival tool I always wanted replaces my read-it-later app and saves everything to local markdown files



optional أعاد

ZPS has a new site with some pretty cool changes to pricing, labs, and exams. Read more here: zeropointsecurity.co.uk/blog/new-site-…


optional أعاد

HELLO NAHAMCON 2025 CTF IS MAY 23 TO MAY 25 BEN ASKED ME TO HELP PROMOTE AND I FORRGOOTTT PLEASE REGISTER AND PLAY OUR GAME jh.live/nahamcon-ctf I WILL CONTINUE TO SPAM UNTIL SHOWTIME AND DURING EVENT SORRY BUT IT WILL BE FUN I PINKY PROMISE

_JohnHammond's tweet image. HELLO
NAHAMCON 2025 CTF IS MAY 23 TO MAY 25
BEN ASKED ME TO HELP PROMOTE AND I FORRGOOTTT
PLEASE REGISTER AND PLAY OUR GAME
jh.live/nahamcon-ctf
I WILL CONTINUE TO SPAM UNTIL SHOWTIME AND DURING EVENT SORRY BUT IT WILL BE FUN I PINKY PROMISE

Loading...

Something went wrong.


Something went wrong.