Targeted Ops @TrustedSec. Hacker, lock picker, writer of bad prompts. This is our world now... the world of the electron and the switch, the beauty of the baud.

North Wales, United Kingdom
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
PoC is public. Internet-facing MikroTik SSH → full admin. No password. No key. MikroTrick: CVE-2026-67279 + CVE-2026-86060. Fresh on CISA KEV. Chain: password auth as `-2` (rejected but left sticky) → pre-auth rekey drops the auth gate → `/nova/bin/login` treats `-2` as “read identity + policy from fd 2” → all-ones mask = full admin. IoC: `login failure for user -2 via ssh` then `user added by ssh:-2@…` PoC: github.com/digiprosec/MicroT… Writeup: cert.pl/en/posts/2026/09/mik… Patch: 7.23.4 / 7.24.2 / 6.49.21 - then hunt `ops` + Flagged. #MikroTik #RouterOS #CVE #PoC #InfoSec #CyberSecurity
12
120
511
38,524
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
notRDP - A Havoc C2 plugin that creates an invisible alternate Windows desktop, streams it to a browser-based viewer, and supports full mouse/keyboard interaction like RDP, but invisible to the target user github.com/dagowda/notRDP
4
82
408
18,232
New ink day. Name the film
4
212
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
I was once onsite at a client, where Accenture consultants were finishing up another pentest readout, same room. “In this critical finding, your passwords are stored plaintext, here look” Barely competent client: “but… you’re in burp suite… and this is HTTPS” Accenture: “uh well uh if someone breaks https, then the password leaks, so ahh it should be encrypted… again” One billion dollars
Okay we’re all going to die
57
65
1,864
193,052
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
Your LG OLED is watching your living room while you sleep. Gamers Nexus just ran 135 minutes of bench tests. Retail LG OLED TVs. Including the G5. Microphone stays active in standby. Screen is dark. Remote is down. Microphone is still on. Recording clear audio. Storing it locally. Uploading it when the internet comes back. The TV was disconnected from Ethernet. Still kept recording. The researchers put audio near the mic. The TV logged it. Stored the file. Uploaded it the moment connectivity returned. Plain text voice logs sitting on the device. LG says it has sold 216 million smart TVs globally. LG's advertising arm claims access to 363 million secondary devices in the US. Secondary. Meaning devices that aren't the TV. Your phone. Your partner's smartwatch. Your kid's laptop. The TV scans your entire network in standby. Maps every device. Gets their IP addresses. Logs nearby Wi-Fi networks. Signal strengths. Location data. Then feeds it to LG Ad Solutions. Automatic Content Recognition catches what's on screen. Even your HDMI input. Your Apple TV. Your gaming console. All logged. But the microphone in standby is the part that hits different. Because standby means off to you. To LG it means the listening device is still powered. Just not telling you. Researchers found remote code execution vulnerabilities in webOS. So your network-scanning, audio-recording, data-harvesting television is also potentially hackable by anyone on your Wi-Fi. LG says nothing. No comment. No response. No explanation. Just microphones in 216 million living rooms. All quietly working while the owner thinks the TV is asleep.
What the TV does by design: — scans your entire home network continuously. in their test: one TV identified 38 unrelated devices including phones, smartwatches, printers, and thermostats belonging to people not involved in the test. — collects the names and signal strengths of every nearby WiFi network, plus location data. all sent to LG Ad Solutions. — runs ACR (Automatic Content Recognition) on everything displayed on screen. including HDMI inputs. your laptop, gaming console, or work monitor connected to the TV is being fingerprinted. — one TV exchanged roughly 4GB of ACR-related data per month. What the TV does that LG says it doesn't: LG publicly stated their TVs "do not collect, record, or store ambient conversations." Gamers Nexus found: — the TV converts speech to plain text and stores it in on-device logs — the microphone window stays open 10 to 15 seconds after talking stops, capturing bystanders who never addressed the TV — the TV recorded room audio while the screen appeared off and the Ethernet cable was unplugged, then exfiltrated the file the moment it reconnected The security vulnerabilities on top: Beyond the designed behavior, researchers found remote code execution vulnerabilities in webOS that could allow a compromised TV to be weaponized as a covert listening device. these sets are in hospitals. waiting rooms. boardrooms. hotels. a surgeon asked Gamers Nexus where that leaves patient confidentiality. Gamers Nexus has no answer. neither does LG. What to do right now: — disconnect your LG TV from your network entirely. route streaming through an Apple TV, Roku, or Fire Stick instead. — if you must keep it connected: put it on a separate IoT VLAN or guest network so it cannot reach your other devices. — disable the built-in microphone in settings. — check your privacy dashboard and opt out of ACR and ad personalization. — after every firmware update: recheck all of the above. Credit to Gamers Nexus, Level1Techs, and other independent researchers.
572
4,871
32,745
2,201,236
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
TOM NOOOOOOO
FalconFlank : Crowdstrike Falcon 0day LPE is now public github.com/MSNightmare/Falco…
3
24
2,822
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
I think the red team community has placed too much emphasis on "getting DA". Getting admin access should prove useful to a much larger objective. An attacker can likely achieve extensive impact to an organization by leveraging the access of a sales representative, let alone an administrator
3
4
21
4,372
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
6
58
246
7,163
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
#x33fcon 2026 talks: @mrgretzky - Downgrading FIDO MFA With AI Slop > piped.video/dNtqZJmtIpw
1
5
18
864
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
62
296
7,725
82,387
My @x33fcon talk is out
#x33fcon 2026 talks: @two06 - Continuous Social Engineering > piped.video/T7lKFDta530
1
10
26
4,464
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
Somewhere there is a pentester trying to get this into a report or a team reviewing it as CTI.
PussyBlocker-UndefendV2 - Security Update Disruption tool: Targets: ✅ Windows Defender ✅ Windows Update ✅ Kaspersky ✅ ESET github.com/WeedHashPeddler/P…
3
5
55
7,050
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
Want to run an entire Tailscale daemon from memory inside a C2 implant with zero disk artifacts, no kernel drivers, traffic indistinguishable from HTTPS to a CDN, and relay connections from the victim network back through the tailnet. Now you can. Enjoy! netspi.com/blog/technical-bl…
15
197
753
67,653
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
"Let's steal all the data from the internet and then add a watermark to it"
We’ve written an FAQ to answer some of the questions we've received about watermarking. In summary: • We’re implementing watermarking to comply with the EU AI Act. Other major model developers have signed the same Code of Practice and will also be implementing watermarking; • Our watermarking method doesn’t have any practical impact on the quality or content of Claude’s outputs; • The difference between watermarked and un-watermarked text will not be distinguishable to readers; • Nothing is added to the text and there are no hidden characters; • Watermarking doesn’t require extra tokens, and will not be more expensive; • Watermarks can’t be traced to a specific person, organization, or chat. Read more: anthropic.com/news/claude-te…
59
472
4,458
168,736
James 🏴󠁧󠁢󠁷󠁬󠁳󠁿 retweeted
200
1,134
23,287
433,896
Two of these, to tell me that dry stuff might catch fire. 🥴
7
1
4
261
Instructions unclear.
1
1
7
775