Music, cybersecurity, open source and AI • Author of bettercap, pwnagotchi, opensnitch, bleah, legba and a few other things.
Co-founder & CTO @ @usemilgram
PoC is public. Internet-facing MikroTik SSH → full admin. No password. No key.
MikroTrick: CVE-2026-67279 + CVE-2026-86060. Fresh on CISA KEV.
Chain: password auth as `-2` (rejected but left sticky) → pre-auth rekey drops the auth gate → `/nova/bin/login` treats `-2` as “read identity + policy from fd 2” → all-ones mask = full admin.
IoC: `login failure for user -2 via ssh` then `user added by ssh:-2@…`
PoC: github.com/digiprosec/MicroT…
Writeup: cert.pl/en/posts/2026/09/mik…
Patch: 7.23.4 / 7.24.2 / 6.49.21 - then hunt `ops` + Flagged.
#MikroTik#RouterOS#CVE#PoC#InfoSec#CyberSecurity
We have found one zeroday that preauth RCE'd Debian 13, Google, Meta, Roundcube, Plesk, Wikimedia, Box, Dropbox, Zoom, Forminator, Elementor, WordPress Core, among many more. Details soon!
We can use our Ghostscript exploits to directly attack KDE's file manager from a single link click in Chrome.
This PoC Downloads the file, then pops open the file manager for unsandboxed RCE
(lovingly refered to as the full chain from temu)
Had some fun finding and exploiting state machine logic bug in af_alg_sendmsg last year, it leads to OOB access, arbitrary write then container escape that unnoticed since 2011
kernelCTF writeup: github.com/star-sg/security-…
Fix commit: git.kernel.org/pub/scm/linux…
We're likely 1st to publicly exploit crypto: af_alg as a new attack surface in kernelCTF. Our members @n0psledbyte & @st424204 started poking it in Sep 2025, finding a 0-day container escape unnoticed since 2011. @AnthropicAI@OpenAI: interested in collaborations? We are all ears
Anduril Armory. The global storefront for commercial-off-the-shelf capabilities is live. Every item ready to deploy.
"We have the demand coming in, orders are booked." - Matthew Steckman, President and Chief Business Officer at Anduril Industries.
Armory.Anduril.com
🚨 CISA KEV — WSO2 MULTIPLE PRODUCTS CVE-2026-5430 (CRITICAL AUTH BYPASS / ACCOUNT TAKEOVER)
CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities (KEV) Catalog on September 24, 2026, based on evidence of active exploitation.
Products (vendor advisory WSO2-2026-5328):
• WSO2 API Control Plane 4.6.0, 4.5.0
• WSO2 API Manager 4.6.0–4.1.0
• WSO2 Traffic Manager 4.6.0, 4.5.0
• WSO2 Universal Gateway 4.6.0, 4.5.0
Vendor severity: Critical — CVSS 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H); adjusted to 9.8 for single-tenant deployments
Vendor overview: JWT authentication can be bypassed when a token is signed using an unsupported algorithm, enabling unauthorized access and potential admin account takeover
CWE (KEV): CWE-347 (Improper Verification of Cryptographic Signature)
Federal due date: September 27, 2026 (BOD 26-04); forensic triage: Yes
⚠️ Analyst Note:
This is an official CISA KEV addition (catalogVersion 2026.09.24; count 1723; dateReleased 2026-09-24T19:00:55Z) plus WSO2’s official security advisory. Prefer those primaries over secondary media.
CISA’s KEV shortDescription labels this a “path traversal” that could enable unrestricted file upload / RCE, while the linked vendor advisory WSO2-2026-5328 and CWE-347 describe JWT authentication bypass / account takeover. Post from the vendor technical description; note CISA’s active-exploitation signal and due date.
CISA has not published a detailed exploitation-campaign narrative in the KEV entry; treat “known exploited” as the authoritative urgency signal and apply vendor fixes / BOD 26-04 guidance.
Official vendor advisory:
security.docs.wso2.com/en/la…
CISA alert (two-KEV add):
cisa.gov/news-events/alerts/…
CISA KEV catalog:
cisa.gov/known-exploited-vul…#DDW#DarkWeb#CISA#KEV#WSO2#CVE20265430#APISecurity#ThreatIntelligence#CyberSecurity
My @x33fcon talk about Credential Relay Phishing is finally out!
Watch me struggle through the live Google phishing demo, a day after the pirate ship party, which deprived me of my last few brain cells. 😜
Wrath of demo gods and AI lulz included. 🥳
piped.video/dNtqZJmtIpw
Using Apple's Corelocation you can identify network devices in areas where Wigle simply doesn't have coverage.
This is Pine Gap, a joint Australian and United States satellite communications and signals intelligence surveillance base.
You cannot get within 25KM before getting stopped.
Using Apple's own infrastructure you can map out the location of over 140 Fortinet devices on the base.
🚨 PUBLIC EXPLOIT RELEASED FOR LINUX KERNEL CONTAINER ESCAPE — CONTAINER USER CAN REACH ROOT ON HOST
DepthFirst has published technical details and exploit code for CVE-2026-80521, a Linux kernel AF_UNIX use-after-free that can break the container security boundary.
• Exploitation starts from unprivileged code inside a container and can yield root on the underlying host
• The vulnerable AF_UNIX functionality is reachable through syscalls allowed by default Docker/Kubernetes seccomp profiles
• DepthFirst used the bug to compromise a Google kernelCTF target in July
• The flaw was reported to kernel.org in August; researchers learned it had independently been reported by Kyle Zeng of OpenAI
• An upstream Linux kernel fix was released August 6
• DepthFirst published its full research and exploit on September 22
• Ubuntu tracks CVE-2026-80521 as affecting relevant releases; downstream patch status should be checked rather than assuming the upstream fix is already deployed
• No confirmed in-the-wild exploitation has been identified
⚠️ Analyst Note:
This is especially relevant to multi-tenant container infrastructure. Containers share the host kernel, so a kernel escape can turn compromise of one workload into root access to the underlying node and potentially expose neighboring workloads.
The availability of public exploit material materially lowers the barrier for reproduction. Operators running untrusted or internet-facing container workloads should verify their actual host-kernel build and patch state now.
Primary: depthfirst.com/research/cont…#Linux#CVE202680521#ContainerEscape#Docker#Kubernetes#Kernel#CloudSecurity#PoC#ThreatIntel#DDW#DarkWeb
We all have a different sense of aesthetics. Personally I love how Rust code looks like, but I’d never push my personal view as a generally accepted fact while on a stage looking like Temu Jesus on cocaine.