AfroSec
606 subscribers
316 photos
22 videos
6 files
161 links
hello friend
am AfroSec | AASTU dropout | cybersecurity enthusiast | CRTOM | CRTA | passionate abt Red Teaming :)))

portifolio : soon....
file : @Afr0Files
Download Telegram
Forwarded from Genesis (ISRAฦŽL)
Risk is always better than regret
๐Ÿ”ฅ6
แŠฅแŠ•แŠณแŠ• แˆˆแ‰ฅแˆญแˆƒแА แˆแ‹ฐแ‰ฑ แ‰ แˆฐแˆ‹แˆ แŠ แ‹ฐแˆจแˆณแ‰ฝแˆ !

@AfroSec
3โค20๐Ÿฅฐ2
hey yall how is holiday goinn' ?

@AfroSec
๐Ÿ‘Œ8โค1
This media is not supported in your browser
VIEW IN TELEGRAM
can we make it anonymous seriously like by changing the bios chip firmware and stuff like that ?

@AfroSec
โœ2๐Ÿค”2
Some people think that when I quit uni I just went dumb, quit life, and rot in bed. Bruh can u relax ?๐Ÿ˜‚
every time I open my PC and connect to the internet, Iโ€™m learning
letโ€™s be honest ena malet in uni most of us only read modules for exams and forget them right after,๐Ÿ™„
In tech ? every hour, every minute, youโ€™re googling, low-key abusing AI lol ๐Ÿ˜…

anyways if anyone who think like this please แŠจแ‹ตแˆญแŒŠแ‰ณแ‰ฝแˆ แ‰ฐแ‰†แŒ แ‰ก๐Ÿ˜‚

@AfroSec
๐Ÿ˜16๐Ÿคฃ5๐Ÿ‘3
Forwarded from AXUM SEC
CVE-2025-53770: When SharePoint Zero-Days Proved Perimeter
Security Isnโ€™t Enough
In July 2025, attackers actively exploited a critical SharePoint zero-day to gain unauthenticated RCE, deploy web shells, steal machine keys, and persist even after patching.

The hard truth?
Patching closes the door, but it doesnโ€™t tell you who already walked in.
Modern attacks blend into normal operations and stay quiet. Defending against them takes more than alerts it takes continuous validation and real exposure visibility.
Thatโ€™s where AxumSec comes in.
Because modern threats donโ€™t wait and security shouldnโ€™t either.

๐Ÿ’ฌ What cyber risk do you think organizations still underestimate?

๐Ÿ”— https://preregister.axumsec.com
๐Ÿ”ฅ3
my shaylaaa ๐Ÿ™ƒ

@AfroSec
๐Ÿฅฐ10โค7๐Ÿ˜2
#random
istg cybersec taught me patience more than any thing ๐Ÿฅฒ

@AfroSec
๐Ÿ’ฏ10๐Ÿ™1๐Ÿ˜ญ1
life of a tech dude and gamer lol๐Ÿ˜‚

@AfroSec
๐Ÿคฃ10๐Ÿ˜5๐Ÿ”ฅ4
do u want some ๐Ÿ™ƒ?

@AfroSec
๐Ÿฅฐ7๐Ÿ˜3๐Ÿ˜ญ3
Forwarded from Robi makes stuff (Robi)
the central dick of ethiopia
๐Ÿคฃ18๐Ÿ˜4๐Ÿ˜ญ2
mimipenguin yk ths tool ? eski guess gn dont look up on google or AI

cool name tho :)

@AfroSec
๐Ÿค”4๐Ÿ”ฅ1
The Hacker News
Researchers uncovered SHADOW#REACTOR, a multi-stage campaign delivering Remcos RAT. It starts with an obfuscated VBS launcher, moves through PowerShell, and rebuilds fragmented text payloads in memory. The defining trait is text-only stagers and LOLBin abuseโ€ฆ
First time seeing text-based stagers in the wild ๐Ÿ˜ฎโ€๐Ÿ’จ These guys are creative as hell fr

their Attack chain was like :
> Obfuscated VBS โ†’ PowerShell โ†’ Text payload fragments โ†’ .NET Reactor loader โ†’ MSBuild.exe โ†’ Remcos RAT
> All in-memory reconstruction (fileless where possible)
> Self-healing downloaders that retry if payloads fail

The whole "access-as-a-service" economy is wild rn ๐Ÿ˜‚

They did slip up tho large .txt files being processed by powerShell would raise SOC eyebrows but their evasion game was strong good

Text-based payloads avoid signature detection
.NET Reactor obfuscation breaks static analysis
Living-off-the-land with MSBuild.exe
Memory-only execution avoids file scanning

Overall rating: 8.5/10 ๐Ÿ˜‚๐Ÿ˜‚
solid OPSEC, creative TTPs, but that PowerShell + .txt combo is a bit loud for sustained stealth ๐Ÿ™ƒ

@AfroSec
๐Ÿคฏ2โšก1๐Ÿค“1
when chatgpt got surprised ๐Ÿ˜‚

he thought am just dum this whole time (actually i am on specific stuff tho :) ) lol

@AfroSec
1๐Ÿ˜11๐Ÿคฃ5๐Ÿ˜ญ1
This media is not supported in your browser
VIEW IN TELEGRAM
แˆ›แˆˆแ‰ต แАแ‰ แˆญ ๐Ÿ‘Š

@AfroSec
๐Ÿ’ฏ6๐Ÿคฃ5
This media is not supported in your browser
VIEW IN TELEGRAM
Rest in Peace Netsanet Werkineh ๐Ÿ˜ข๐Ÿฅ€๐Ÿฅ€๐Ÿฅ€๐Ÿฅ€

@AfroSec
๐Ÿ’”12๐Ÿ˜ญ1