Offensive Security
295 subscribers
128 photos
13 videos
27 files
159 links
we are not .
Download Telegram
A comprehensive systems programming toolkit implementing low-level concepts in C, from memory management to OS internals. Features practical implementations of computer architecture concepts with a focus on performance and hardware interaction.

https://github.com/mohitmishra786/BitsAndBytes

@GoSecurity
#C #toolkit #memory
Forwarded from vx-underground
Hello

I have collected more malware. It's like, ... 200,000 malware, I think. I don't know. I've stopped counting.

It is enough malware for your friends, family, extended family, neighbors, and co-workers.

Please download it. The malware is lonely.

https://vx-underground.org/Updates
ReverseShell with AI behaviour analysis bypass (prompt injection targeting sandbox analysis).

https://github.com/tihanyin/PSSW100AVB/blob/main/ReverseShell_2026_05.ps1

@GoSecurity
درود به همه🌹
خواستم بگم خودتونو دست کم نگیرید و خودتونو نبازید، ادامه بدید و مطمئن باشید یه روزی یه اتفاق مثبت میفته و مسیر زندگی‌تون تغییر خواهد کرد.
الان در برهه‌ایی از تاریخ هستیم که تقریبا یادگیری و آموزش به حداقل‌ترین حالت خودش رسیده، سعی کنید خودتونو اپدیت نگه دارید و چیزای جدید یادبگیرید.

ارادت❤️
Orange Tsai (https://x.com/orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange

https://x.com/thezdi/status/2055281643984683475?s=46
#Pwn20wn #Tournament #zdi
@GoSecurity
leaker is a leak discovery tool that returns valid credential leaks using passive online sources. It supports searching by email, username, domain, keyword, and phone number.

https://github.com/vflame6/leaker

@GoSecurity
#Osint #Leaker #Recon
استخدامی ردتیم دولوپر

jobvision.ir

@GoSecurity
2026_02_17_Process_Preluding_Child_Process_Injection_Before_The.pdf
499.7 KB
Process Preluding: Child Process Injection Before The Story Begins

@GoSecurity
This media is not supported in your browser
VIEW IN TELEGRAM
Whats the best piece of advice you've ever received?
New banking malware campaigns are targeting both Windows and Android users.

Researchers uncovered updated versions of the Grandoreiro banking trojan and the BTMOB Android RAT, capable of stealing banking credentials, abusing Accessibility services, keylogging, and remotely controlling infected devices.

The malware spreads through phishing emails, fake apps, and DLL side-loading techniques, showing how financial cyberattacks are becoming more automated and cross-platform.

Read more:
https://thehackernews.com/2026/05/grandoreiro-malware-and-btmob-rat.html

@GoSecurity
#Malware #AndroidSecurity #WindowsSecurity #BankingTrojan #InfoSec
Successful backups don’t always mean safe ransomware recovery.

Security experts warn that restoring infected backups can bring malware back into the network. The report recommends testing recovery in isolated environments and validating backups before restoration.

Read more:
https://thehackernews.com/expert-insights/2026/05/how-to-test-ransomware-recovery-without.html

@GoSecurity
#Ransomware #BackupSecurity #DataRecovery #InfoSec
A new zero-day vulnerability in the self-hosted Git service Gogs can let attackers achieve remote code execution (RCE) on exposed servers.

The flaw impacts internet-facing Gogs instances and could allow hackers to execute arbitrary commands remotely before a patch is available.

Read more:
https://www.bleepingcomputer.com/news/security/new-gogs-zero-day-flaw-lets-hackers-get-remote-code-execution/

@GoSecurity
#ZeroDay #RCE #Gogs #InfoSec
A new threat intelligence report highlights the growing cyber threat landscape in Iran during H2 2024 – H1 2025.

According to the report, financial institutions, transportation, and critical infrastructure were among the most targeted sectors. Researchers observed a rise in ransomware, DDoS attacks, hacktivist activity, and attacks aimed at disrupting services and public trust during regional geopolitical tensions.

Read more:
https://global.ptsecurity.com/en/research/analytics/cybersecurity-threatscape-iran-h2-2024-h1-2025/

@GoSecurity
#Iran #Ransomware #Hacktivism #InfoSec
یک آسیب‌پذیری جدید با شناسه CVE-2026-40369 در کرنل ویندوز کشف شده که می‌تواند به مهاجمان اجازه ارتقای دسترسی (Privilege Escalation) تا سطح SYSTEM را بدهد.

این نقص از طریق تابع
NtQuerySystemInformation

قابل سوءاستفاده است و روی نسخه‌های جدید Windows 11 و Windows Server 2025 تأثیر می‌گذارد.

اکسپلویت:
https://github.com/orinimron123/CVE-2026-40369-EXPLOIT

اطلاعات بیشتر:
https://core-jmp.org/2026/05/cve-2026-40369-arbitrary-kernel-address-increment/

@GoSecurity
#Windows #PrivilegeEscalation #ZeroDay #InfoSec
Media is too big
VIEW IN TELEGRAM
SecTor 2025 | EDR Bypass Testing: A Systematic Approach to Validating Endpoint Defenses

Black Hat
Conference
Speaker:

https://x.com/jgajek

@GoSecurity
#EDR #BlackHat #SECTOR