Co-founder Detecteam | product builder | practitioner | innovator | Dad | IT/OT apologist. my opinions - make it better

Washington, USA
Fred Wilmot retweeted
🚨 LOTTunnels — LIVING OFF THE TUNNELS 🔥 🔥 Telegram: t.me/hackinarticles ✴️ Twitter: nitter.net/hackinarticles Attackers don't always need custom infrastructure. Sometimes, legitimate tunneling services can become part of the attack chain. 🌐⚔️ LOTTunnels is a community-driven project documenting digital tunnels that can be abused for: 🔹 Access 🔹 Shell Access 🔹 Data Exfiltration 🔹 Persistence 🔹 Phishing 🔹 Payload Download The catalog includes tools/services such as: ⚡ ngrok ⚡ Cloudflared ⚡ localhost.run ⚡ LocalXpose ⚡ PageKite ⚡ Pinggy ⚡ Serveo ⚡ Tmate ⚡ TunnelTo ⚡ VSCode Tunnels 🎯 Why should Red Teamers & Defenders care? Tunneling can create legitimate-looking network traffic while providing paths for remote access, command execution, or data movement. For defenders, these services should be part of attack-surface discovery, detection engineering, and network monitoring. 🔗 Explore LOTTunnels: lottunnels.github.io/ 📌 Bookmark this resource for your next Red Team / Blue Team / Threat Hunting research. ⚠️ Use these techniques only in authorized environments. ♻️ REPOST & SHARE with your cybersecurity community! #LOTTunnels #LivingOffTheLand #CyberSecurity #RedTeam #BlueTeam #ThreatHunting #Pentesting #C2 #NetworkSecurity #InfoSec
2
64
282
15,373
Fred Wilmot retweeted
🚀 x64dbg-MCP Server — fully automated, dynamic, agentic reverse engineering for x64dbg. 🧠 71 MCP tools 🤖 Fully automated & dynamic agentic RE 🔴 22 debugger event callbacks ⚡ Native Zig plugin — zero dependencies 🛠️ Breakpoints, memory, registers, tracing, xrefs, PE analysis & more 🌐 Streamable HTTP + SSE 📦 x32 + x64 Let your AI agent control, analyze, debug, and dynamically reverse engineer binaries directly through x64dbg. 🔗 github.com/duty1g/x64dbg-mcp… #x64dbg #MCP #AgenticAI #ReverseEngineering #CyberSecurity #RedTeam #MalwareAnalysis #Zig
43
485
3,430
588,296
Fred Wilmot retweeted
How much visibility does your EDR really have when persistence and C2 live inside Chromium? New research from @SpecterOps explores Chromium extensions as a C2 + persistence mechanism, turning the browser itself into an interesting red vs blue battleground. Red teamers will love this. Detection engineers should read it twice. specterops.io/blog/2026/08/1… #RedTeam #DetectionEngineering #EDR
7
91
388
23,678
Fred Wilmot retweeted
The DEF CON® Media Server - Archives of the conferences media.defcon.org/DEF%20CON%2…
1
90
398
26,641
Fred Wilmot retweeted
18 years ago today, Dan Kaminsky @dakami disclosed the DNS cache poisoning vulnerability at Black Hat USA 2008, triggering one of the largest coordinated patch efforts in internet history. Before public disclosure, Dan organized multiple vendors to fix the flaw in secret. Many more legendary stories than could fit here, like how he exposed Sony’s rootkit across more than 568,000 networks and identified critical certificate vulnerabilities. Dan followed what he cared about and his curiosity. As Michael Tiffany @kubla put it, “Only Dan thought, ‘I could fix the human eye in software.’” He built DanKam, an augmented-reality app that helped colorblind people see color. Michael hosted Dan while he built the first version and described watching a colorblind houseguest sit at the kitchen table, “crying tears of joy seeing red for the first time.” His mother, Trudy Maurer, may have said it best when she accepted his Lifetime Achievement Award at the 2025 Difference Makers. “Daniel was the catalyst for many achievements across the vast internet spectrum, and I believe Dan truly represented the intersection of technology and humanity.” @dotMudge, who presented the award, said: “The Lifetime Achievement Award isn’t about what you achieve in your lifetime. That’s part of it. It’s about how many people you influence and bring in and then take it further.” We lost Dan too early from diabetic ketoacidosis in April 2021 at age 42. Some of you are hearing the name Dan Kaminsky for the first time.  The coordinated, community-first spirit Dan modeled is the bar. If you're in Vegas this week, you're walking the streets that the legends of security who came before you walked, when they also had no idea what they were doing, facing problems nobody had solved before. They had to figure it out as they went. Just like you're going to do. Thanks to those who contributed to this tribute video: Jeff Moss @thedarktangent, @paulvixie, @gadievron, Lena Smart, Derek Hinch and the many others who shared here.
21
116
577
46,888
Fred Wilmot retweeted
Three zero-days in Windows 11 and Microsoft Entra ID. Over 20 novel attack techniques against passkeys. Toolkit open sourced. Microsoft declined to fix one of them. Passkeys were supposed to be unphishable. @MGrafnetter from @SpecterOps just presented Pass-the-Passkey at Black Hat. Global Admin impersonation from a standard user account. No user interaction. Bypasses phishing-resistant MFA Conditional Access policies. Zero alerts from Defender for Identity or Entra Identity Protection on M365 E5. Windows Hello passkeys are still vulnerable after the patches because they always send signature counter 0. Microsoft scored it 6.5 Medium and paid $1,000. The researcher scored it 8.6 High. Their advisory described it as 'could potentially read small portions of heap memory.' This is the same team behind BloodHound, Certified Pre-Owned (AD CS), Rubeus, Certify, Seatbelt, SharpDPAPI, SharpUp, Ghostwriter, Nemesis, SharpSCCM, and CuddlePhish. They consistently ship research that changes how the industry thinks about Active Directory and identity security. If you do red teaming, pentesting, identity security, Entra ID, FIDO2, WebAuthn, Windows Hello, phishing-resistant MFA, or detection engineering, this is the most important identity research to drop this year. Pass-the-Hash for the passwordless era. i.blackhat.com/BH-USA-26/Pre… #Infosec #RedTeam #DetectionEngineering
7
125
553
28,832
Crazy New attack vector : U.S. Navy researchers just turned binaries into prompt injection weapons against AI reverse engineering agents. Ghidra, and Qwen3-8B - injecting prompts using a small C program. Quite impressive, They made AI tools like Cline & GhidraMCP lie about what a program actually does while the binary still runs perfectly. The core idea is simple but brutal: Instead of attacking the binary’s logic, attackers embed malicious prompt strings inside normal C code (as string variables). When an LLM-powered agent decompiles it with Ghidra, those strings get fed directly into the model as instructions. The Result: The AI starts following attacker commands instead of analyzing the real code. Key technical detail that makes this practical: Ghidra truncates string variables longer than 2048 characters, So the researchers had to craft short, high-impact injection payloads that survive decompilation. They used a genetic algorithm modified AutoDAN-style to automatically generate effective prompts that work inside this constraint. Two papers from Naval Postgraduate School researchers 1, Automatically Attacking Software Reverse Engineering AI Agents 2, Investigating Detection and Obfuscation of Prompt Injection Attacks Against Software Reverse Engineering AI Agents They successfully tested the attack on real setups using Cline, GhidraMCP, Ghidra, and Qwen3-8B. interesting examples in the research shows,The AI just gets gaslit. - Claiming it completed analysis with wrong information - Restarting its reasoning from a poisoned state Ai doing gasliting
33
202
854
56,898
Milla Jovovich (actress from The Fifth Element) created a world-beating Claude memory system with @bensig?! - 100% on LongMemEval — first perfect score ever recorded. Free and 100% open source. Github link in the quoted post from Ben. I'm keen to hear how it works for you.
My friend Milla Jovovich and I spent months creating an AI memory system with Claude. It just posted a perfect score on the standard benchmark - beating every product in the space, free or paid. It's called MemPalace, and it works nothing like anything else out there. Instead of sending your data to a background agent in the cloud, it mines your conversations locally and organizes them into a palace - a structured architecture with wings, halls, and rooms that mirrors how human memory actually works. Here is what that gets you: → Your AI knows who you are before you type a single word - family, projects, preferences, loaded in ~120 tokens → Palace architecture organizes memories by domain and type - not a flat list of facts, a navigable structure → Semantic search across months of conversations finds the answer in position 1 or 2 → AAAK compression fits your entire life context into 120 tokens - 30x lossless compression any LLM reads natively → Contradiction detection catches wrong names, wrong pronouns, wrong ages before you ever see them The benchmarks: 100% recall on LongMemEval — first perfect score ever recorded. 500/500 questions. Every question type at 100%. 92.9% on ConvoMem — more than 2x Mem0's score. 100% on LoCoMo — every multi-hop reasoning category, including temporal inference which stumps most systems. No API key. No cloud. No subscription. One dependency. Runs on your machine. Your memories never leave. MIT License. 100% Open Source. github.com/milla-jovovich/me…
Community note
The claimed 100% LongMemEval score uses targeted fixes for the 3 failing questions and LLM reranking (held-out score: 98.4%). The 100% LoCoMo score uses top-k=50 exceeding session count with reranking (honest top-10 no rerank: 88.9%). github.com/milla-jovovich…
226
749
6,749
1,724,343
Can AI agents conduct advanced cyber-attacks autonomously? We tested seven models released between August 2024 and February 2026 on two custom-built cyber ranges designed to replicate complex attack environments. Here’s what we found🧵
19
89
386
103,169
Fred Wilmot retweeted
Space Force Chief Master Sergeant Ron Lerch: "The Chinese have published papers as far back as 2019 talking about the need to do light detection and ranging from space — LiDAR. That graphic is straight out of their research paper, and what its showing there is the ability to use potentially LiDAR to see under the water. So there’s obvious implications there for submarine hunting. Not just necessarily a civil application, but defense applications if that becomes a capability that becomes real here in the next five years. Like I said, they’ve been researching stealth on orbit for decades. They actually published in a research paper this "Olive B" test article. And they believe that this would be sort of the future of what stealthy objects — stealthy microsatellites, specifically — could potentially look like on orbit. Because not only are they difficult to visually acquire, but that shape, they believe, would be incredibly beneficial in terms of masking their radar cross-section. They’ve released a lot of research papers lately that are talking about how they could use satellites to negate the effects and the positive benefits that proliferated LEO constellations give you. And they’ve also talked about just using a swarm of drones that are just flooding say, the Taiwanese Straight, and just jamming, thereby preventing any subscribers to be able to access even pLEO. Because again, it’s a home game for them. They don’t necessarily need to be worried about jamming other parts of the globe in the event that there was some sort of conflict to kick off on their home turf." Link: piped.video/shorts/QXBTtDjbW…
China’s "Olive-B" Stealth Micro-Satellite Link: mdpi.com/2226-4310/9/12/815
19
192
1,275
368,514
Fred Wilmot retweeted
🚨Alert🚨:CVE-2025-68613(CVSS 10.0): A Critical Remote Code Execution (RCE) Vulnerability in n8n. 📊905.9K Services are found on the hunter.how yearly. 🔗Hunter Link:hunter.how/list?searchValue=… 👇Query HUNTER : product.name="N8n" 📰Refer:securityonline.info/n8n-unde… github.com/n8n-io/n8n/securi… #hunterhow #infosec #infosecurity #OSINT #Vulnerability
8
89
316
27,507
Fred Wilmot retweeted
CheckFirst: OSINT & Phaleristics: Unveiling FSB’s 16th Center SIGINT Capabilities checkfirst.network/wp-conten…
6
96
427
47,818
Fred Wilmot retweeted
Chat, we are cooked Discord is being extorted by the people who compromised their Zendesk instance They've got 1.5TB of age verification related photos. 2,185,151 photos tl;dr 2.1m Discord users drivers license and/or passport might be leaked. Unknown number of e-mails
336
1,121
11,111
905,225
Fred Wilmot retweeted
We are focused on reducing the gatekeeping, minimizing the Detection Engineering plight, and maximizing the time to value of quality tested detections in minutes with @devo_Inc
There's no gatekeeping detection rules here. We upload detection rules from the Devo + @DetecteamInc solution into Devo Exchange, our community-based app, so that all of our users can benefit from it and keep their organizations secure. Learn more: bit.ly/4lfEMeA
2
1
95
Great takes on the impacts of such a large acquisition for the industry. Really enjoyed the dialogue on cyber risk impacts of what Clorox is doing. Shared responsibility? What do you think?
Tech news alert! The newest episode of the Techstrong Gang is here on this lovely Friday. We unpacked the latest big moves in the world of cybersecurity and discussed Palo Alto Networks’ acquisition of CyberArk for $25B! Plus, we dish on the insecure truth about "vibe coding" and Clorox's lawsuit against Cognizant over shady password reset practices.Ultimately when bad things happen, companies must be accountable and transparent to maintain customer trust and preserve brand reputation. Tune in to the latest Techstrong Gang episode to stay on top of the latest tech news and trends! @TechstrongTV @TechstrongGroup @jswartz @fewdisc @irawinkler #TechstrongGang #Cybersecurity #TechNews #Innovation #PaloAltoNetworks #VibeCoding #Security #Cognizant #Clorox #Crowdstrike
1
80