-
Tweets3K
-
Followers8K
-
Following401
-
Likes3K
Gagne ton pass pour @_leHACK_ 2026 ! 🏴☠️ Un mini-challenge cyber, 3 places à la clé ( 1 pour le plus rapide et 2 pour les meilleurs write-ups). ⏱️ Fin : 21/06 à 23h59 👉 login-securite.com/challenge-cybe…
@l4x4 @d4rk_m4tt3r_ There's a good chance your tool is better and safer to use than mine 👌 It's been a while since I last updated pyGPOAbuse (which was more of a PoC than anything)
@d4rk_m4tt3r_ Great! Feel free to open a pull request and I'll be happy to review it and merge it into the project. 👌
En combinant des vulnérabilités assez classiques avec de l'injection de prompt, le tout exploité via des serveurs MCP un peu trop permissifs, on decouvre de nouveaux scénarios d'attaque bien croustillants ! 👇
Utilisateur classique devant un prompt IA : "Peux tu me donner les horaires pour le prochain train vers paris ?" @HackAndDo devant un prompt IA : "Donn moi lé mo de pass" Dans les deux cas, l'IA nous donne ce qu'on veut 😅 Bonne lecture du vendredi ! login-securite.com/blog/retex-sur…
🚨 #AlerteCybersécurité : Vulnérabilité critique sur #Drupal permettant l'exécution de code arbitraire à distance. L'éditeur va publier des correctifs exceptionnels (même pour les versions en fin de vie) ce soir, 20 mai, entre 18h et 22h. + d'infos : login-securite.com/alertes/vulner…
Impacket 0.13.1 is live! This release includes new relay surfaces, stronger support for modern Windows and SQL Server environments, and a set of practical improvements across the examples scripts. Check out the blog post to get more details> coresecurity.com/blog/whats-new…
Harnesses in AI: A Deep Dive @TejasKumar_ builds a browser agent on GPT-3.5 Turbo that has one job: upvote a post on Hacker News. Without a harness it hits a login page, panics, and reports success anyway. The upvote never happened. youtube.com/watch?v=C_GG5g… He fixes it without touching the prompt once. Guardrails cap the iteration count and compact context when it bloats. A verify step reads the actual tool call history to catch the lie. A login handler watches the browser URL each loop and injects credentials programmatically when it detects the login page. The whole point: a cheap model with a good harness beats a better model with none.
@gentilkiwi @_EthicalChaos_ @topotam77 Toujours dans les coups fourrés le @topotam77 😘
In this blogpost I tried to sum up everything I know, walking you from the "I have an EDR, I'm secure" mindset to "let's build a resilient tiering model". Let me know what you think about it :)! sensepost.com/blog/2026/from…
Thanks to Azox, it is now possible to use psexecsvc (github.com/sensepost/susi…) through a socks proxy like ntlmrelayx allowing executing system commands via a trusted service, as NT System, and evading EDR's. Also thanks to @HackAndDo for his fixes :D
Post about Windows Admin Center remote privilege escalation (CVE-2026-26119) has been published, check it out here👇 semperis.com/blog/what-you-…
The purpose of this article is to explain NTLM relay, and to present its limits. en.hackndo.com/ntlm-relay/
@sekurlsa_pw You can find an excellent write up on password spraying from hackndo’s blog here: en.hackndo.com/password-spray… Mandatory reading IMO for AD network pentesters
@stewart_sec @sekurlsa_pw @RedHatPentester Oh thanks, I should have read the whole thread 🫣
@stewart_sec @sekurlsa_pw @RedHatPentester That's right. I wrote about it specifically, and I developped a tool that does just that en.hackndo.com/password-spray… github.com/login-securite…
SafeBreach Labs discovered a critical RCE vulnerability in the MS-EVEN RPC protocol that allowed low-privileged domain users to write arbitrary files and run code on remote Windows 11 and Windows Server 2025 computers in the domain. Get the full breakdown: hubs.ly/Q043PMZ-0
In Active Directory, there is a method that’s been around for many years which changes the password last set date but not the actual password. This is what I call a “fake password change” since the account appears to have a recent password when scanning for old passwords based on password last set, but the underlying password hasn’t actually changed. I spoke about this in my 2015 @BSidesCharm talk which was my first conference talk. More details including step-by-step screenshots are here: adsecurity.org/?p=4969 Why does this happen? There are times where service account (or admin accounts) need to have password changes, but someone doesn’t want to do the work to change them. The ability to fake a password change requires modify rights on the pwdLastSet attribute which provides the ability to check/uncheck the setting “User must change password at next logon”. This setting is enabled when you want the user to change their own password when they logon. How does this work? This is simple to do when you have rights on the target account (in this example the password last changed in August 2025). We open up Active Directory Users and Computers (ADUC), double-click on the target account to open up the account properties and then click on the Account tab. From here we check the box for “User must change password at next logon” and click Apply. The PasswordLastSet date is now blank. Which makes it seem like the account has never had a password set. We continue with our process where we uncheck the box for “User must change password at next logon” we checked and then click Apply. After performing this action, the password change date has now been set to the current date and time even though the password itself hasn’t been changed since August 2025. We have successfully faked a password change! Why does this happen? This happens because the “User must change password at next logon” option is used to force a user to change their password at next logon. With it checked, Active Directory is waiting for the user to attempt to logon which is when the user is directed to change their password. During this time the PasswordLastSet value is blank since it is waiting for a new password. Once the user changes their password, the checkbox is effectively removed and the current date and time are set for the user’s passwordlastset property (technically this is the “pwdlastset” attribute, but the AD PowerShell cmdlets use that property). An attacker could use this technique for an account with an old password they discover and have control of the account (with the ability to flip this bit). This would show that the password changed without it actually changing. Detect fake Active Directory password changes at scale I wrote a PowerShell script that will scan either the Active Directory Admins or All Users in the domain to see if there’s a fake password change that has been performed on them. github.com/PyroTek3/Activ…
How Hackers Defeat Microsoft’s 2026 NTLM Patch As Microsoft moves away from NTLM auth in favor of Kerberos, we published an article showing several ways attackers can abuse Kerberos to move laterally The new patch won’t prevent lateral movement. It will mainly complicate things for those who relied heavily on NTLM. You still need to secure systems. That's why we provided recommendations on how to better secure your systems against these techniques hackers-arise.com/digital-forens… @three_cube @_aircorridor @DI0256 #dfir #blueteam #redteam #pentesting #apt #ThreatHunting
New blog & exploit about CVE-2025-29969 - RCE by Yarin Aharoni @safebreach Labs. Findings allow: ---- * Checking arbitrary paths existence (unfixed!). * Writing files remotely (RCE). ---- On ALL Windows & Windows Server computers in the domain! Repo - github.com/SafeBreach-Lab…
Un beau travail de R&D de la part d'un collègue sur Keeper Forcefield, extension d'un password manager ayant pour objectif de limiter l'accès à sa mémoire aux attaquants qui tenteraient d'extraire les credz. Forcefield a depuis été mis à jour corriger les faiblesses identifiées.
L'utilisation de gestionnaires de mots de passe est une pratique courante et recommandée pour des raisons de sécurité. ⚠️ Une de ses limitations ? La compromission d'un poste de travail peut entraîner le vol des secrets du gestionnaire.
Charlie Bromberg « ... @_nwodtuhs
16K Followers 660 Following Trying to hack the way we hack things 🏴☠️
mpgn @mpgn_x64
18K Followers 236 Following Flibustier du net ̿ ̿̿'̿'\̵͇̿̿\=(•̪●)=/̵͇̿̿/'̿̿ ̿ ̿ ̿ Podcast Hack'n Speak @hacknspeak / https://t.co/GyACSFg9mw
Nicolas Krassas @Dinosn
157K Followers 768 Following Head of Threat & Vulnerability Mgmt @ Henkel AG & Co. KGaA https://t.co/NC1orlKZLB Posting content that I find interesting.
Rémi GASCOU (Podalir... @podalirius_
8K Followers 713 Following Senior Security Researcher @SpecterOps | 3xMicrosoft Security MVP | Creator of opensource security tools 🎬 https://t.co/QaAENc4NcY | Views are my own
sn🥶vvcr💥sh @snovvcrash
12K Followers 494 Following Sr. Penetration Tester / Red Team Operator @ptswarm :: Author of the Pentester’s Promiscuous Notebook :: He/him :: Tweets’re my pwn 🐣
Grzegorz Tworek @0gtweet
38K Followers 2K Following My own research, unless stated otherwise. Not necessarily "safe when taken as directed". GIT d- s+: a+ C++++ !U !L !M w++++$ b++++ G-
Adam Chester 🏴�... @_xpn_
38K Followers 538 Following Hacker for Hire at @SpecterOps | Blog at https://t.co/tjfTOlmau2 | Insta at https://t.co/PqR6CZQ48T
Mayfly @M4yFly
7K Followers 790 Following Former Dev and DevOps| Pentester and red teamer at orange cyberdefense | OSCE³| Tweet are my own| discord: m4yfly
n00py @n00py1
14K Followers 966 Following Retweeter of InfoSec/Offsec/Pentest/Red Team. Occasional blogger/Independent security research.
Dirk-jan @_dirkjan
30K Followers 205 Following Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
Swissky @pentest_swissky
22K Followers 1K Following RedTeam | Pentest Author of PayloadsAllTheThings & SSRFmap https://t.co/w1ZLRqoafG
an0n @an0n_r0
14K Followers 731 Following CRT(E|O|L) | OSCP | @RingZer0_CTF 1st (for 2yrs) | HackTheBox Top10 | RPISEC MBE | Flare-On completer | GoogleCTF writeup winner | SSD research | Math MSc |🇭🇺
Dr. Nestori Syynimaa @DrAzureAD
21K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
🥝🏳️🌈 Be... @gentilkiwi
62K Followers 291 Following A kiwi coding mimikatz & kekeo github: https://t.co/eS3LVgU6i0 Head of security services @banquedefrance Tweets are my own and not the views of my employer
Mike Felch (Stay Read... @ustayready
17K Followers 2K Following Offensive @ TrustedSec | Hacking since Renegade BBS backdoors | Prior CrowdStrike/BHIS | In Christ's grip | Fighter for truth | K1HAQ
Josh @passthehashbrwn
10K Followers 296 Following Adversarial Simulation at IBM, tweets are mine etc.
Marcello @byt3bl33d3r
30K Followers 819 Following CyBeRsEcUrItY | Not afraid to put down with some THICC malware on disk | AI Research @PaloAltoNtwks | former purple team | Ex @spacex
DebugPrivilege @DebugPrivilege
41K Followers 2K Following Not active anymore on X. Problem solver with a passion for troubleshooting complex issues.
Panda Lys @PandaLys18830
9 Followers 290 Following
lgandx @lgandx
20 Followers 22 Following Been collecting your credentials for more than a decade. Now on the AI train.
Z3r0iz3 @z3r0iz3
0 Followers 49 Following
Mike Zylb @MikeZylb
317 Followers 4K Following
Aguf Florance @FloranceAg4763
4 Followers 524 Following
wackaid @wackaid
32 Followers 2K Following ai - security researcher - 👕🐀- friendly neighborhood nerd & starter builder
DevHunter_Sec 🔍 @dronefolie
4 Followers 170 Following 🛡️ Security Researcher | Bug Bounty Hunter @YesWeHack & @Hacker0x01 💻 Senior Dev mindset | Breaking logic for fun & profit 🔍 Deep diving into API Security &
cloud @cloudappai
1 Followers 56 Following
Scørpīøň Dēltā @_Delta_54
33 Followers 301 Following
Judo Judo @JudoJudo336474
0 Followers 102 Following
Zaynor @Zaynor165716
0 Followers 99 Following
Guihack @Guihackap
1 Followers 65 Following
Ahmed Faisal @Loverboyrando_1
0 Followers 5 Following
Json Todd 🏴🚩 @json_todd
5 Followers 55 Following Les fachos ne l'aime pas, mais lui aime les enquiquiner. CyberAfa ⛩️
Maurice LAMBERT @LmbrtMaurice
0 Followers 28 Following
Babbz @Babbzito
0 Followers 48 Following
nsix0 @nsix038556
0 Followers 23 Following
Yehia Gouda @acelxrd
16 Followers 154 Following 👨💻 Pentester | CTF Player | Web Developer | Programmer | Gamer
amir amir @amirami88385425
7 Followers 534 Following
T0bbyC0rn @0t0bby
4 Followers 422 Following
Alrxche @Alrxche
27 Followers 319 Following
Spork @SporkCodes
25 Followers 187 Following Programmer for Java | Python | JS ▫️ sometimes Webdeveloper▫️ Working on @playlegendnet▫️ Been there, done that.
R 1 @zupiango
4 Followers 1K Following
ethixcz. @ethicxz
241 Followers 135 Following
Frc @Frc12451
0 Followers 64 Following
pentestTeam @TeamPentest
5 Followers 168 Following The essential tool for penetration testers - over 3000 documented commands. https://t.co/6UL2xhTFDv
Sudoku @SudokusFull
0 Followers 2K Following
achillle @achillllllllle
0 Followers 50 Following
Akashi @TrollerHD1
253 Followers 81 Following HTB Addict | CS Student | CRTO| CRTP | CWES | eCPPTv2 | eJPT | CAPT
isenhu @isenhu
33 Followers 3K Following
theonexc @theonexc1
0 Followers 5K Following
kirito_55768 @K557689926
0 Followers 29 Following
Abdeslem A @h4nz0x7
0 Followers 155 Following
Charlie Bromberg « ... @_nwodtuhs
16K Followers 660 Following Trying to hack the way we hack things 🏴☠️
Florian Hansemann @CyberWarship
88K Followers 46 Following Father, Founder @HanseSecure, Pentesting, Student, ExploitDev, Redteaming, InfoSec & CyberCyber; -- Mastodon: https://t.co/KFSKYUN98M
mpgn @mpgn_x64
18K Followers 236 Following Flibustier du net ̿ ̿̿'̿'\̵͇̿̿\=(•̪●)=/̵͇̿̿/'̿̿ ̿ ̿ ̿ Podcast Hack'n Speak @hacknspeak / https://t.co/GyACSFg9mw
Nicolas Krassas @Dinosn
157K Followers 768 Following Head of Threat & Vulnerability Mgmt @ Henkel AG & Co. KGaA https://t.co/NC1orlKZLB Posting content that I find interesting.
ippsec @ippsec
123K Followers 365 Following
Rémi GASCOU (Podalir... @podalirius_
8K Followers 713 Following Senior Security Researcher @SpecterOps | 3xMicrosoft Security MVP | Creator of opensource security tools 🎬 https://t.co/QaAENc4NcY | Views are my own
DirectoryRanger @DirectoryRanger
37K Followers 102 Following This account assembles and disseminates information related to Active Directory and Windows security.
Adam Chester 🏴�... @_xpn_
38K Followers 538 Following Hacker for Hire at @SpecterOps | Blog at https://t.co/tjfTOlmau2 | Insta at https://t.co/PqR6CZQ48T
Mayfly @M4yFly
7K Followers 790 Following Former Dev and DevOps| Pentester and red teamer at orange cyberdefense | OSCE³| Tweet are my own| discord: m4yfly
n00py @n00py1
14K Followers 966 Following Retweeter of InfoSec/Offsec/Pentest/Red Team. Occasional blogger/Independent security research.
Dirk-jan @_dirkjan
30K Followers 205 Following Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
Swissky @pentest_swissky
22K Followers 1K Following RedTeam | Pentest Author of PayloadsAllTheThings & SSRFmap https://t.co/w1ZLRqoafG
Dr. Nestori Syynimaa @DrAzureAD
21K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
Synacktiv @Synacktiv
21K Followers 274 Following Offensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
Binni Shah @binitamshah
141K Followers 165 Following Linux Evangelist, Malwares, Security enthusiast ,Investor,World Economy, Finance,Contrarian , Philanthropist , Reformist , Sigma female [email protected]
🥝🏳️🌈 Be... @gentilkiwi
62K Followers 291 Following A kiwi coding mimikatz & kekeo github: https://t.co/eS3LVgU6i0 Head of security services @banquedefrance Tweets are my own and not the views of my employer
Tejas Kumar @TejasKumar_
38K Followers 1K Following working on ai at @ibm • investor • advisor • international keynote speaker • podcast host • i dont speak on behalf of ibm
ClaudeDevs @ClaudeDevs
485K Followers 3 Following Official updates for developers building with @ClaudeAI
Alican Kiraz @AlicanKiraz0
34K Followers 3K Following LLM Craftsman & Agentic AI Systems Architect & Cybersecurity Sr. Staff | Exploring Robotics & Biohacking
Anthropic @AnthropicAI
1.4M Followers 2 Following We're an AI safety and research company that builds reliable, interpretable, and steerable AI systems. Talk to our AI assistant @claudeai on https://t.co/FhDI3KQh0n.
Claude @claudeai
1.5M Followers 2 Following Claude is an AI assistant built by @anthropicai to be safe, accurate, and secure. Talk to Claude on https://t.co/ZhTwG8d1e5 or download the app.
Hugow @hugow_vincent
973 Followers 1K Following Red Team and research @synacktiv @rustyphasm.bsky.social
Callum Stewart @stewart_sec
218 Followers 1K Following penetration tester, salt & vinegar crisp addict
Secorizon @secorizon
809 Followers 105 Following Home of Responder, Pcredz, SecorizonAI, etc Red team ops, offensive pentests. Back then, your 0days were your certs.
Matthieu Barjole @matthieubjl
114 Followers 101 Following
Rauxam @Rauxam_
16 Followers 73 Following
Franso @Fransosiche
1K Followers 311 Following Pentester & Content Creator @rootme_org | Vulga Cyber https://t.co/3pgcxclBjh https://t.co/INGswbIHrv
Yuval Gordon @YuG0rd
1K Followers 426 Following Security Researcher at Palo Alto Networks. Opinions are my own.
Scaum @SScaum
29 Followers 25 Following
Quentin Roland @croco_byte
341 Followers 37 Following Pentester @Synacktiv 🤖 https://t.co/FhHN2RnPym
Simone Margaritelli @evilsocket
48K Followers 2K Following Music, cybersecurity, open source and AI • Author of bettercap, pwnagotchi, opensnitch, bleah, legba and a few other things. Chief Architect @ 🥷
Volker @volker_carstein
588 Followers 613 Following Hacker 💻 speaker 📣 Jack of All Trades 🃏 Social Engineering, OSINT, AD, TTRPG Pentester / Red Team Operator @ Bsecure / Parabellum Services
Mounir Laggoune @moonlaggoune
46K Followers 709 Following CEO @finaryhq - Rejoignez 1 million investisseurs, suivez votre patrimoine, gérez votre budget et investissez. Mon livre pour investir👇
wrongbaud @wrongbaud
5K Followers 1K Following Cars, Bikes, Coffee and Embedded Systems Security | Founder @voidstarsec Training and Consulting https://t.co/0ib8fK31Ib https://t.co/YzN9K2LaST
T. @trendytofu
983 Followers 664 Following something something Cyber, something something security something.
OtterHacker @OtterHacker
8K Followers 77 Following Professional redteamer and malware development enthusiast ! I will share some tips and experiences. Look at my work here : https://t.co/cxLBvW7pcI
Finary @finaryhq
25K Followers 9 Following Finary est l'application qui vous aide à suivre, optimiser et investir votre argent. 💸
k1nd0ne @k1nd0ne
605 Followers 213 Following
RandoriSec @RandoriSec
2K Followers 152 Following Cybersecurity company founded by security experts providing the following services: Security audits, Vulnerability research, SecOps, SecArch and Trainings
Fahad @Pwn3dx
2K Followers 413 Following Adversary Emulation | #OSEP | #CRTL | #eCPTXv2 | #CRTE | #CRTO | #CRTP | #eCPPTv2 | #eWPT | #APTLabs | #ZEPHYR
Jim Sykora @JimSycurity
3K Followers 2K Following I enjoy security, technology, learning, books, & the great outdoors. Trying to be human & kind. Opinions = mine. He/Him/Hän
Nathan Blondel @slowerzs
802 Followers 123 Following
Akamai Security Intel... @akamai_research
26K Followers 108 Following All security research, all the time. Bringing you the latest insights from @Akamai’s research teams across the globe.
Aurélien Chalot @Defte_
4K Followers 484 Following Hacker, sysadmin and security researcher @OrangeCyberdef 💻 Calisthenic enthousiast 💪 and wannabe philosopher https://t.co/SqDDhIGGGh 📖 🔥 Hide&Sec 🔥
Gateway @intogateway
1K Followers 6 Following The Web3 Security University, incubated by @guardianaudits
Jason Lang @curi0usJack
16K Followers 204 Following @TrustedSec Red Team lead | Hi-Fidelity trolling | Liberty/Privacy Enthusiast | Linux | Putting the "no" in nano | Avatar: https://t.co/3XHmKR8nCk
d1rkmtr @d1rkmtr
9K Followers 464 Following
Daniel Avinoam @daniel_avinoam
109 Followers 62 Following
wwwGeneral @wwwGeneralFR
21 Followers 137 Following Pentester @Holiseum Part-Time Teacher @ESIEEParis Staff @HackDayfr CTF Player Active Directory breaker Blog : https://t.co/tzZUgyKrpa
DEFCON GROUP Paris @dcgparis
2K Followers 11 Following A reboot of the DEFCON GROUP Paris group. Free bimonthly meetups. If you would like to give a talk, contact us here: [email protected]
Vincent Yiu @vysecurity
32K Followers 345 Following Director, Red Team / Offensive Security. Help organizations safeguard their businesses from the bad guys.
Snowball @snowball
5K Followers 0 Following 👨🏫 Apprends les rouages de l'éco, de la finance et des cryptos en toute simplicité. pas de « get rich quick » ici.
Caroline Jurado @CarolineJurado
2K Followers 539 Following Vulgarisatrice crypto, Autrice, Conférencière. Je rends les cryptos simples. Ma newsletter crypto n°1 en 🇫🇷 ⎥Rejoins-nous !







































