Offensive Security
296 subscribers
128 photos
13 videos
27 files
159 links
we are not .
Download Telegram
Forwarded from vx-underground
i really like malware
CVE-2026-21508 - Windows LPE via arbitrary COM object initialization

The vulnerability essentially works by forcing a process running as system and that uses the undocumented function Windows_Storage!_SHCoCreateInstance, to create an arbitrary COM object of our choice. For this to happen the object must be associated with an already registered COM class that supports CLSCTX_INPROC_SERVER. Arbitrary COM object creation is archived by manipulating a CoCreateInstance call first argument

@GoSecurity
#CVE #LPE #DFIR #blueteam
A custom Linux beacon for Cobalt Strike

While official Cobalt Strike does not natively support generating Linux beacons, the author says that it is possible to build custom implants for Cobalt Strike on virtually any platform. The only requirement is that the implant communicates correctly with the teamserver

https://github.com/EricEsquivel/CobaltStrike-Linux-Beacon

@GoSecurity
#dfir #blueteam #threathunting #c2 #redteam #cobalt
A comprehensive systems programming toolkit implementing low-level concepts in C, from memory management to OS internals. Features practical implementations of computer architecture concepts with a focus on performance and hardware interaction.

https://github.com/mohitmishra786/BitsAndBytes

@GoSecurity
#C #toolkit #memory
Forwarded from vx-underground
Hello

I have collected more malware. It's like, ... 200,000 malware, I think. I don't know. I've stopped counting.

It is enough malware for your friends, family, extended family, neighbors, and co-workers.

Please download it. The malware is lonely.

https://vx-underground.org/Updates
ReverseShell with AI behaviour analysis bypass (prompt injection targeting sandbox analysis).

https://github.com/tihanyin/PSSW100AVB/blob/main/ReverseShell_2026_05.ps1

@GoSecurity
درود به همه🌹
خواستم بگم خودتونو دست کم نگیرید و خودتونو نبازید، ادامه بدید و مطمئن باشید یه روزی یه اتفاق مثبت میفته و مسیر زندگی‌تون تغییر خواهد کرد.
الان در برهه‌ایی از تاریخ هستیم که تقریبا یادگیری و آموزش به حداقل‌ترین حالت خودش رسیده، سعی کنید خودتونو اپدیت نگه دارید و چیزای جدید یادبگیرید.

ارادت❤️
Orange Tsai (https://x.com/orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange

https://x.com/thezdi/status/2055281643984683475?s=46
#Pwn20wn #Tournament #zdi
@GoSecurity
leaker is a leak discovery tool that returns valid credential leaks using passive online sources. It supports searching by email, username, domain, keyword, and phone number.

https://github.com/vflame6/leaker

@GoSecurity
#Osint #Leaker #Recon
استخدامی ردتیم دولوپر

jobvision.ir

@GoSecurity
2026_02_17_Process_Preluding_Child_Process_Injection_Before_The.pdf
499.7 KB
Process Preluding: Child Process Injection Before The Story Begins

@GoSecurity
This media is not supported in your browser
VIEW IN TELEGRAM
Whats the best piece of advice you've ever received?
New banking malware campaigns are targeting both Windows and Android users.

Researchers uncovered updated versions of the Grandoreiro banking trojan and the BTMOB Android RAT, capable of stealing banking credentials, abusing Accessibility services, keylogging, and remotely controlling infected devices.

The malware spreads through phishing emails, fake apps, and DLL side-loading techniques, showing how financial cyberattacks are becoming more automated and cross-platform.

Read more:
https://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.html

@GoSecurity
#Malware #AndroidSecurity #WindowsSecurity #BankingTrojan #InfoSec
Successful backups don’t always mean safe ransomware recovery.

Security experts warn that restoring infected backups can bring malware back into the network. The report recommends testing recovery in isolated environments and validating backups before restoration.

Read more:
https://thehackernews.com/expert-insights/2026/05/how-to-test-ransomware-recovery-without.html

@GoSecurity
#Ransomware #BackupSecurity #DataRecovery #InfoSec