Patch your Linux boxes!
Copy.Fail is a trivially exploitable logic bug in Linux, reachable on all major distros released in the last 9 years. A small, portable python script gets root on all platforms.
Found by the teams at @theori_io and @xint_official
More details below
xint.io/blog/copy-fail…
So Microsoft Copilot has its own App-Bound Encryption now. The standalone Copilot app (mscopilot.exe) is a full Chromium browser based on Edge, ships with its own elevation_service.exe, a dedicated COM interface (IElevatorCopilot), and a separate ABE key scope.
Decrypting the ABE key gives us some cookies (copilot.microsoft.com auth, MUID, MSAL session, Cloudflare tokens) and the Microsoft Account token from the token_service database.
Local Storage also holds MSAL.js cached tokens. An ID token, two access tokens (chatai.readwrite for the Copilot API + user.read for Microsoft Graph), and account metadata for the signed-in MSA.
These use MSAL's own browser-bound CryptoKey encryption, not ABE.
Edge 147 also quietly hardened IElevator2 by switching from oleaut32 to a custom proxy/stub but simultaneously registered IElevatorCopilot with oleautomation. Closed one door, opened another.
Next up: decrypting the MSAL tokens? 🤔
A new evasion technique known as "EDR-Freeze" has emerged, changing the way attackers neutralize endpoint security. Unlike traditional methods that attempt to crash or terminate security software (which often triggers alerts), EDR-Freeze suspends the security process entirely, rendering it "comatose" but technically alive. This attack is particularly dangerous because it operates entirely in user mode, meaning it does not require the attacker to bring a vulnerable driver (BYOVD) or exploit kernel-level flaws. Instead, it abuses legitimate Windows error reporting tools to freeze Endpoint Detection and Response (EDR) agents, creating a blind spot where malicious activity can occur undetected.
picussecurity.com/resource/blog/…
Bypassing PPL in Userland
TLDR: bypass the latest mitigation implemented by Microsoft and develop a new Userland exploit for injecting arbitrary code in a PPL with the highest signer type.
itm4n.github.io/bypassing-ppl-…
🔥 ZoomEye Black Friday – LIFETIME Deals 🔥
⏰ Nov 27, 10:00 HKT – Limited Stock
💥 Lifetime Plans - One payment, access forever!
1. Membership — $149
Access to all standard features. Perfect for Pentesters & Researchers.
2. Membership Pro — $999
Includes everything in Membership, plus the vul.cve Filter & BugBounty Radar. Perfect for Senior Analysts & Intel Experts.
3. 2024 Membership upgrade to Pro → $666 only
🎉 Bonus ZoomEye-Points
1. Register before Nov 27, 00:00 HKT + buy any lifetime plan = Up to 3 million ZoomEye-Points
2. Use an invitation code → Both get 100k ZoomEye-Points
● Full details & rewards on the purchase page.
● All bonus ZoomEye-Points valid 1 year.
🎁 Giveaway — Winners announced on Dec 2 (HKT)
We're giving away 5× 1-month ZoomEye Professional memberships (worth $109 each)!
Just RT this post to enter.
Don't miss the biggest ZoomEye deal of the year!
👉 zoomeye.ai/pricing?utm_so…#BlackFridaySale#BlackFridayDeals#ZoomEye#cybersecurity#OSINT
Administrator Protection in Windows 25H2 Changes Everything
With update KB5067036, Windows quietly introduced Administrator Protection, and it changes how Windows handles admin rights.
Until now, being a local admin meant living like Clark Kent: doing normal tasks in plain clothes but turning into Superman the moment you hit “Run as administrator.” Same user, same identity, just with hidden powers always waiting to be (ab)used.
Administrator Protection breaks that link. When you elevate, Windows now creates a separate system account to handle the task, keeping Superman isolated and out of reach when you’re done.
Want to see how it really works under the hood? The new blog dives into it.
patchmypc.com/blog/administr…#Intune#MSIntune#Windows#Windows11 #Security
You got access to vsphere and want to compromise the Windows hosts running on that ESX? 💡
1) Create a clone into a new template of the target VM
2) Download the VMDK file of the template from the storage
3) Parse it with Volumiser, extract SAM/SYSTEM/SECURITY
(1/3)
Dumping LSASS is old school. If an admin is connected on a server you are local admin on, just create a scheduled task asking for a certificate on his behalf, get the cert, get its privs. All automatized in the schtask_as module for NetExec 🥳🥳🥳
7K Followers 3K FollowingEnfocados en elevar la #Seguridad de la Información y #Ciberseguridad en la escala nacional.
Focused on #InfoSec & #Cybersecurity at the national level.
0 Followers 163 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/PXYxuvrAR9
891 Followers 1K FollowingFounder @Hackmetrix & Security Researcher. Always watching, never seen. D̶o̶n̶’̶t̶ have the drive to become a big scary famous hacker.
25K Followers 27K FollowingA Hacker who is A Lover of People, and Life @RetroTwinz @Secbsd, @GrumpyHackers, @NovaHackers, @deadpixelsec @hacknotcrime Advocate @PositivelyBlue_ OSCP, OSWP
1K Followers 16 FollowingWhat if the world's best hackers rebuilt AppSec from the ground up with AI?
Meet Xint - autonomous, comprehensive, fast, and actionable.
5K Followers 9 Following@Openwall oss-security mailing list thread summaries, currently maintained by @solardiz. Originally setup and maintained as an automated feed by @eugeneteo.
16K Followers 1 FollowingAnnouncements, tips and support via DM of
KNOXSS - The most comprehensive XSS tool available
by @BRuteLogic https://t.co/Ar5icALkk6
8K Followers 2K FollowingFounder of @Sn1perSecurity. Creator of Sn1per and @SILENTCHAINAI. Top 20 worldwide on @bugcrowd in 2016. OSCE/OSCP - https://t.co/iqw8gBpkKb
2K Followers 1K FollowingSecurity Engineer
Blue team by ☀️ ,
Red team by 🌃
Full Freelancer pentest Web&mobile application
code review (Java,php,python) | OSCP|OSCE3|CRTL|CRTE
2K Followers 1 FollowingTrain on raw telemetry from actual breaches. Investigate malware and reconstruct the kill chain from process creation to exfiltration and beyond.
1K Followers 223 FollowingData breach revealed,
Malware lurks, silent, stealthy -
OSINT tracks the thread.
URLs I post may contain malware – be careful and check yourself before running
17K Followers 3K Following🛠️ Former Sysadmin, now Pentester | Microsoft MVP | Helping IT teams make their environment harder to attack | @SecurIT360 & @CyberThreatPOV