Marc Smeets @MarcOverIP
Does a thing or two with red teaming @OutflankNL | part time race and drift car instructor Tweets in NL & EN Joined July 2009-
Tweets24K
-
Followers5K
-
Following499
-
Likes21K
Cobalt Strike 4.13 is live! Say "Hello World" to our Beacon Interpreter for native C scripting - plus an LLVM Beacon, smoother docking UX, sharper payload management and more. Read about all the new features in the release blog! cobaltstrike.com/blog/cobalt-st…
@BakkertjeJasper @UID_ Wat enorm leuk dat je je in discussie mengt Jasper, maar doe dat dan even goed ajb. Niet eens in de 4 jaar, er zijn ook EKs. En als je goed leest zeg ik dat het afneemt. Dat jij op absolute cijfers een kwalificatie plakt van ‘prima’ is subjectief en helpt niet.
ServiceNow customers are being notified after unauthorized access hit multiple tenants. The messy part? A Scripted REST endpoint reportedly shipped with authentication disabled. No token. No valid session. No real user account. Just requests landing as “Guest” in logs. The IOC: 51.159.98.241 Security teams should be checking /api/now/related_list_edit transaction logs immediately.
It’s hilarious that they made a huge deal about the cyber capabilities for months and then when they rolled it out, they’ve blocked the actual utility of the model by prohibiting cyber use 🤣 And yes this includes trusted testers. Like, what was the point in even releasing it?
Door een fout van bewindvoerders liggen de privé- en medische gegevens van mensen met schulden op straat. De organisaties wilden geen 10 euro per jaar betalen om hun oude domeinnaam te behouden, waarop nog veel gevoelige informatie binnenkwam. rtl.nl/nieuws/tech/ar…
A careless code blunder just blew the lid off Beijing’s multi-million dollar AI propaganda operation targeting the West. France's digital interference watchdog, Viginum, has officially exposed "Fawn Mianju," a covert network of 13 multilingual fake news sites running on advanced automation and generative AI. The sophisticated network was completely compromised after a computer engineer working as a Senior Project Manager at China's state-run CGTN Digital accidentally left his login credentials exposed in the code. This operation, which expanded on findings first uncovered by U.S. cybersecurity firm Graphika in 2025, operated with deep financial backing. The domains were registered in Beijing, hosted on Alibaba Cloud, and utilized expensive infrastructure alongside paid plugins to artificially manipulate search engine rankings. Using digital keys linked directly to AI language models, the network automatically scraped CGTN articles, lightly rewrote them, and republished over 2,300 articles, often within less than an hour of the original state media broadcast. Sites like the French-language "Actu Méridien" were weaponized to manipulate public opinion across 89 countries, heavily targeting Western audiences and Francophone African youth. The articles aggressively peddled pro-Beijing narratives, painting China as the undisputed leader of the Global South and green energy transition while explicitly telling Western readers that aligning with Chinese interests would bring them massive benefits. Despite the cutting-edge tech and heavy state funding, the operation was an organic flop. The articles struggled to breach 15,000 views, with nearly 40 percent of its top social media engagement traced back to fake accounts in Burundi whose sole purpose was to artificially inflate the content. While the reach was limited, French authorities warn that the operation exposes Beijing’s rapidly escalating capability to launch fully automated, stealth disinformation campaigns designed to quietly erode Western democratic alignment. #Disinformation #CyberSecurity #France #China #AIPropaganda #Geopolitics #Viginum #NationalSecurity
When you need to double check if its a parody account 😬😬
Chase. Every. Millisecond.
@wdortmans @BovenkampD1940 Daua eigenlijk zeg je dat je de oldtimer wilt laten stelen? 🙃
Ffs When do we collectively just give up on npm?
Someone hid a self-replicating worm inside 37 npm packages. Written in Rust. Hidden behind an eBPF kernel rootkit. Talking to its operator over Tor. It steals 86 environment variables. AWS keys. GCP keys. Vault secrets. Kubernetes tokens. Your Anthropic API key. Your OpenAI
Cobalt Strike 4.13 has a new Aggressor hook to support BOF cocktails. Here's a quick walkthrough: rastamouse.me/bof-cocktails-…
The Saint Petersburg International Economic Forum of 2026 (SPIEF 2026) in Russia has started with a very fiery keynote speech by the Ukrainian surprise guests.
I wanted to address the speculation about the recently introduced Device Bound Session Credentials (DBSC) security feature in Google Chrome. Does it help increase the security of session cookies against infostealer malware and MFA phishing? The feature has been available and enabled by default since the Chrome 146 update (April 2026), if you're running Windows with a hardware-backed TPM security module (macOS support is coming in future updates). DBSC allows the browser to upgrade session cookies from long-lived to short-lived, requiring the browser to refresh them approximately every 10 minutes to maintain access to the user's account. > Does DBSC prevent account takeover by threat actors using a stolen session cookie obtained from the user's browser via infostealer malware? Yes (kind of). The extracted session cookie will be valid for up to 10 minutes from the time it is extracted. The attacker will be unable to maintain long-term access to the user's account. Still, the timeframe may be sufficient, for example, to exfiltrate the inbox if the attack is automated. The attacker cannot refresh the short-lived session cookie because it requires the private key (stored in the TPM) assigned to the account to sign the challenge. The malware cannot access the private keys stored in the TPM. > Does DBSC prevent account takeover by threat actors during a phishing attack? No. Servers need to provide legacy support for the browsers that do not yet support DBSC. By default, the server registers and sends a long-lived session cookie to the browser. If the server supports DBSC, it will announce the DBSC API endpoint URL in the `Secure-Session-Registration` HTTP header of the response packet that contains the long-lived session cookies. Only after the short-lived session cookie is registered via the DBSC API endpoint is the long-lived session cookie invalidated. When the attacker removes the `Secure-Session-Registration` HTTP header retrieved from the server during a phishing attack, the browser will continue using long-lived session cookies and assume the server does not support DBSC. In short, removing that HTTP header while proxying traffic during a phishing attack allows the attacker to maintain long-term access to the user's account using the stolen long-lived session cookie. I hope I've managed to clear up some confusion. On a related note, you will soon be able to simulate phishing attacks against Google Workspace accounts (and other websites) that bypass DBSC and MFA protections using Evilginx Pro with the Phishlets 2.0 update.
Google Chrome is rolling out device-bound session credentials to all users. Session cookies get cryptographically tied to your device, so stolen cookies can't be replayed from a different machine. Attackers who exfiltrate your cookie database get nothing usable.
Everyone except me ? We are in fact still in court over this.
Over the past several days, we have been listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical and, at times, fragile. We deeply value the security community,
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Adam Chester 🏴�... @_xpn_
38K Followers 538 Following Hacker for Hire at @SpecterOps | Blog at https://t.co/tjfTOlmau2 | Insta at https://t.co/PqR6CZQ48T
Jean @Jean_Maes_1994
12K Followers 1K Following @sansoffensive Certified instructor/SEC565 author/SEC699 co author https://t.co/cp5DerI3g4
Mike Felch (Stay Read... @ustayready
17K Followers 2K Following Offensive @ TrustedSec | Hacking since Renegade BBS backdoors | Prior CrowdStrike/BHIS | In Christ's grip | Fighter for truth | K1HAQ
Josh @passthehashbrwn
10K Followers 296 Following Adversarial Simulation at IBM, tweets are mine etc.
b33f | 🇺🇦✊ @FuzzySec
33K Followers 1K Following 意志 / mobile research @ ▓▓▓▓▓ / Team 501 / ex IBM Capability Lead & FireEye TORE / I rewrite pointers and read memory / AI Psychoanalyst / Teaching @CalypsoLabs
mgeeky | Mariusz Bana... @mariuszbit
14K Followers 950 Following 🔴 Offensive Security Developer @ Outflank, Red Team operator, ex-AV dev, ex- malware researcher 🫖 Green tea lover
Florian Hansemann @CyberWarship
88K Followers 46 Following Father, Founder @HanseSecure, Pentesting, Student, ExploitDev, Redteaming, InfoSec & CyberCyber; -- Mastodon: https://t.co/KFSKYUN98M
Rad @rad9800
10K Followers 708 Following ex-founder. building solutions to secure organizations. prev @deceptiq_ (acq.), now at @thinkstcanary All thoughts / opinions (if at all) are my own.
Dominic Chell 👻 @domchell
18K Followers 551 Following Just your friendly neighbourhood red teamer @MDSecLabs @nighthawk_c2 | Creator of /r/redteamsec | https://t.co/3k3EBAZqGd | https://t.co/KwO2OwDOkl
SEKTOR7 Institute @SEKTOR7net
17K Followers 350 Following Homo Aptus. Vincit qui se vincit - Publilius Syrus. Consulting, Training, Technology, Cyber domain, and more... @x33fcon founder.
Marcello @byt3bl33d3r
30K Followers 819 Following CyBeRsEcUrItY | Not afraid to put down with some THICC malware on disk | AI Research @PaloAltoNtwks | former purple team | Ex @spacex
DebugPrivilege @DebugPrivilege
41K Followers 2K Following Not active anymore on X. Problem solver with a passion for troubleshooting complex issues.
x86matthew @x86matthew
23K Followers 203 Following system emulation / reverse-engineering / binary analysis. @the_secret_club
mRr3b00t @UK_Daniel_Card
123K Followers 8K Following Department of Cyber WAR. Member of the Counter Spider Collective. Wielder of AI to defend in Cyber Space. Ralph Vibe Specialist. VibeOps Operator!
Dirk-jan @_dirkjan
30K Followers 205 Following Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
John Smith @JohnSmithhmw8
5 Followers 269 Following
1776-Cerberus @1776Cerberus
92 Followers 2K Following
VioletSeer @ThevioletSeer
268 Followers 1K Following 🪻 There is nothing to save, now all is lost, but a tiny core of stillness in the heart like the eye of a violet 💜💜 - Freelancer - Base Europe/USA
Emma velvet sky @vemmag989
50 Followers 1K Following tiny heart, giant imagination ☁️ follow back guaranteed
David Perez @anakinswal
303 Followers 2K Following |#CC |#CTIA |#ECIH |#eCTHP|#eCIR |Intel Ops Padawan |All systems are vulnerable (People2) |PurpleTeam addict👾 |Retrato atardeceres 🌅 |Destilo gin🍸|Cultivo 🍄
XD @L0rdMrcS
100 Followers 754 Following Um cara duma cidade numa ilha dum mundo que está deixando de ser azul. ;)
Harsh Thakur @hthakur6293
35 Followers 2K Following
wackaid @wackaid
33 Followers 2K Following ai - security researcher - 👕🐀- friendly neighborhood nerd & starter builder
cr3ghost @cr3ghost
1K Followers 296 Following A student passionate about reverse engineering, windows internals, anti-cheat research, malware research, and exploit research. Aspiring red teamer.
papx zobo @PapxZobo72735
2 Followers 408 Following
Ghost Byte @PickettTon18807
8 Followers 1K Following
Jakob @virtualloc
236 Followers 65 Following
Paul Robinson @itsmetempus
5 Followers 556 Following Helping organizations save time and stay secure
Judo Judo @JudoJudo336474
0 Followers 102 Following
ypsehlig @ypsehlig
174 Followers 518 Following Father of two boys. Teacher, researcher - offensive security. Staff at https://t.co/NDhANBwWt0
isenhu @isenhu
33 Followers 3K Following
MAk @BugBountyBeast
7 Followers 1K Following
Dunno @HashDunno
1 Followers 56 Following
DRS Unlocked @DRSunlocked
5K Followers 479 Following Inside F1 performance. Data. Trends. What teams are really doing and why it matters. 🏎️📊
/𝚌𝚛𝚔/.𝚓�... @JamRoot0
70 Followers 5K Following Mail Cracker | Tech Enthusiast | RedDevil | MAKE AMERICA GREAT AGAIN!!!🇺🇸 📷♟️♞🎲⚽🏀🎱🎳🏑🛹🎾🏸🏏🏓👨💻💻👾🎭🍾🥃🥂🍻🎸 🎶 🎵🎻🎹🦅🐦🔥🦇🕷️🐞🏴☠️🃏🎩
Arth @arth_is_here
2 Followers 26 Following Reverse Engineering & Exploit Dev. Living in Ring 0. Sharing research at https://t.co/jhoVgLgjlX Incoming UK MSc Student (Sept '26)
darko.breznjak @darkobreznjak
0 Followers 28 Following
Dice312 @Dice3121355561
2 Followers 555 Following
sin @S1nB4dR
12 Followers 494 Following
m00zh33 @m00zh33
420 Followers 5K Following
Rémi GASCOU (Podalir... @podalirius_
8K Followers 713 Following Senior Security Researcher @SpecterOps | 3xMicrosoft Security MVP | Creator of opensource security tools 🎬 https://t.co/QaAENc4NcY | Views are my own
crusher @chryzsh
1K Followers 103 Following
punt4n0 @punt4n0
107 Followers 5K Following
∆®€dDy@4 @dyoggofo
55 Followers 2K Following
bill fairway @kipkip6
3 Followers 176 Following
H4rm0ny @mared_washwesh
192 Followers 2K Following إِنَّ اللّهَ لاَ يُغَيِّرُ مَا بِقَوْمٍ حَتَّى يُغَيِّرُواْ مَا بِأَنْفُسِهِمْ
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Adam Chester 🏴�... @_xpn_
38K Followers 538 Following Hacker for Hire at @SpecterOps | Blog at https://t.co/tjfTOlmau2 | Insta at https://t.co/PqR6CZQ48T
Grzegorz Tworek @0gtweet
38K Followers 2K Following My own research, unless stated otherwise. Not necessarily "safe when taken as directed". GIT d- s+: a+ C++++ !U !L !M w++++$ b++++ G-
chompie @chompie1337
89K Followers 1K Following hacker, exploit developer/weird machine mechanic head of X-Force Offensive Research (XOR) @IBM
Jean @Jean_Maes_1994
12K Followers 1K Following @sansoffensive Certified instructor/SEC565 author/SEC699 co author https://t.co/cp5DerI3g4
Josh @passthehashbrwn
10K Followers 296 Following Adversarial Simulation at IBM, tweets are mine etc.
b33f | 🇺🇦✊ @FuzzySec
33K Followers 1K Following 意志 / mobile research @ ▓▓▓▓▓ / Team 501 / ex IBM Capability Lead & FireEye TORE / I rewrite pointers and read memory / AI Psychoanalyst / Teaching @CalypsoLabs
mgeeky | Mariusz Bana... @mariuszbit
14K Followers 950 Following 🔴 Offensive Security Developer @ Outflank, Red Team operator, ex-AV dev, ex- malware researcher 🫖 Green tea lover
Rad @rad9800
10K Followers 708 Following ex-founder. building solutions to secure organizations. prev @deceptiq_ (acq.), now at @thinkstcanary All thoughts / opinions (if at all) are my own.
Dominic Chell 👻 @domchell
18K Followers 551 Following Just your friendly neighbourhood red teamer @MDSecLabs @nighthawk_c2 | Creator of /r/redteamsec | https://t.co/3k3EBAZqGd | https://t.co/KwO2OwDOkl
SEKTOR7 Institute @SEKTOR7net
17K Followers 350 Following Homo Aptus. Vincit qui se vincit - Publilius Syrus. Consulting, Training, Technology, Cyber domain, and more... @x33fcon founder.
Charlie Bromberg « ... @_nwodtuhs
16K Followers 660 Following Trying to hack the way we hack things 🏴☠️
Marcello @byt3bl33d3r
30K Followers 819 Following CyBeRsEcUrItY | Not afraid to put down with some THICC malware on disk | AI Research @PaloAltoNtwks | former purple team | Ex @spacex
DebugPrivilege @DebugPrivilege
41K Followers 2K Following Not active anymore on X. Problem solver with a passion for troubleshooting complex issues.
x86matthew @x86matthew
23K Followers 203 Following system emulation / reverse-engineering / binary analysis. @the_secret_club
Dirk-jan @_dirkjan
30K Followers 205 Following Hacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
PIN DORIANE @DorianePin
49K Followers 159 Following 2025 F1 Academy Champion 🏆 @mercedesamgf1 Development Driver @elms_official & @24heuresdumans 2026 - LMP2 @peugeotsportofficial hypercar development driver
Nightmare Eclipse @ChaoticEclipse0
10K Followers 575 Following
GAZOO Racing Global @en_toyota
171K Followers 48 Following Official global X account of GAZOO Racing
M5Stack @M5Stack
43K Followers 917 Following Leading the way in modular and open-source IoT hardware for scalable innovation.
cr3ghost @cr3ghost
1K Followers 296 Following A student passionate about reverse engineering, windows internals, anti-cheat research, malware research, and exploit research. Aspiring red teamer.
Huib Modderkolk @huibmodderkolk
24K Followers 883 Following Onderzoeksjournalist Volkskrant. Schrijver. Boek Dit wil je écht niet weten / docu Niemand die het ziet / [email protected] / Signal: hmodderkolk.20
maya_weug @WeugMaya
7K Followers 100 Following 🏎️ F1 Academy Driver from 🇳🇱 🇧🇪 🇪🇸 🏁 Racing & sushi lover ❤️ Scuderia Ferrari Driver Academy 📲Follow me on my motorsport journey
Jakob @virtualloc
236 Followers 65 Following
Zero-Point Security @_ZeroPointSec
14K Followers 6 Following
Verstappen Sim Racing @VerstappenSim
58K Followers 212 Following For the love of racing. Powered by @VerstappenCOM, @redbull, @Simucube & Ascher Racing
Advance-sec @advance_sec0
973 Followers 711 Following Advance-sec platform: is leader in acquisition of vulnerabilities and 0day exploits. Email: [email protected] Wire: @advance_sec Telegram: @advance_secur
Armadin @ArmadinSecurity
412 Followers 1 Following Armadin is an AI-native cybersecurity company focused on building the ultimate attacker.
l33tdawg @l33tdawg
7K Followers 2K Following That HITB guy (@hackinthebox @HITBSecConf) and now OOTB guy (@OOTBconf), Music Producer @dhankasounds, & VP of Global Strategy and Growth @verichains
Marvin Baumann @MarvinTBaumann
10K Followers 2K Following Bachelor Physics & AI, Master Economics. Passion for Geopolitics, Existentialism, Psychology, & VC. I care about growing European strength, wealth and beauty.
DRS Unlocked @DRSunlocked
5K Followers 479 Following Inside F1 performance. Data. Trends. What teams are really doing and why it matters. 🏎️📊
EUvsDisinfo @EUvsDisinfo
79K Followers 761 Following We counter Kremlin information warfare, one claim at a time | Not official EU position
Patrick Moeke @PatrickMoeke
5K Followers 534 Following ✍ Redacteur @NUsport |🎙 Podcast @DeBoordradio | 📥 [email protected] | #F1 | Instagram: patrick.moeke
Xander Davies @alxndrdavies
4K Followers 879 Following red team lead @AISecurityInst PhD student @OATML_Oxford, prev @Harvard (https://t.co/695XYMJSua)
𝙶𝚊𝚕𝚕𝚊�... @DanielGallagher
18K Followers 454 Following Threat Intel | OSINT | Incident Response | Security Automations | Cat Memes 🥔 @[email protected]
x0rz @x0rz
95K Followers 417 Following Cybersecurity & Threat Intelligence. Knowledge is power, France is bacon 🥓
Bluesky @bluesky
428K Followers 1 Following The conversation is better on Bluesky. Sign up now: https://t.co/rC9PCGfQVx
French Response @FrenchResponse
208K Followers 8 Following Official response account of the French MFA 🇫🇷🇪🇺 (🏏) @francediplo_EN
Rory Stewart @RoryStewartUK
593K Followers 1K Following Author The Middleland https://t.co/MPlyEWbdCD, PlacesinBetween, Jackson/Yale. PoliticsOnTheEdge. @Restispolitics podcast w Alastair Campbell.
PROTOTYPE 🦾 @prototype_cap
1K Followers 1 Following It only takes a few crazy ones to fix a continent. Let's be crazy. We invest in hyperambitious European frontier tech founders – and push Europe forward. 🚀
EU–INC @euinc_petition
11K Followers 31 Following Pushing for a pan-European, digital-first and standardised legal entity to remove friction from scaling across borders.
Andreas Klinger 🦾 @andreasklinger
70K Followers 4K Following Mad-scientist investor main-questing Europe 🇪🇺 @prototype_cap 🦾 @euinc_petition 🇪🇺 🔧-prev: @producthunt @angellist @coinlist @beondeck ❤️ @susanneknoll
Tim Sweijs @TimSweijs
939 Followers 64 Following Director of Research at The Hague Centre for Strategic Studies
Halvar Flake @halvarflake
45K Followers 3K Following Choose disfavour where obedience does not bring honour. I do math. And was once asked by R. Morris Sr. : "For whom?" @[email protected]
Anne Applebaum @anneapplebaum
583K Followers 853 Following @TheAtlantic and @SNFAgoraJHU Author of Gulag, Iron Curtain, Red Famine, Twilight of Democracy and now AUTOCRACY INC find me more often on the blue site
IISS News @IISS_org
220K Followers 782 Following The International Institute for Strategic Studies is a world-leading authority on global security, political risk and military conflict.
Pepijn van der Stap /... @x_stplanet
82 Followers 250 Following building to secure organizations. reformed blackhat. does security @ https://t.co/VgwssgBYBl writes on personal title.
Dick Berlijn @DickBerlijn
19K Followers 82 Following Cyber security, leiderschap, strategie, crisismanagement, veiligheidsvraagstukken en Defensie
Marietje Schaake @MarietjeSchaake
67K Followers 24K Following Proud European 🇪🇺[email protected] 👾 @StanfordHAI 💻 Columnist @FT 🗞️ MEP 2009-2019 📕Author of The Tech Coup 🌎
tom square @harold9850
238 Followers 336 Following
Derk Boswijk @DefensieStas
9K Followers 72 Following Staatssecretaris van Defensie | Redactie door @Defensie
Ministerie van Defens... @Defensie
59K Followers 227 Following Officieel account van het ministerie van Defensie | Official account of the Dutch Ministry of Defence | Pers: [email protected]
Mechanical Knowledge @mechanical_4u
133K Followers 2 Following ⚙️⚙️⚙️ Mechanical breakdowns | Daily engineering wisdom | Learn how machines really work every day.Content belongs to respectful owners .⚙️⚙️⚙️
















































