Root Access Club
246 subscribers
65 photos
1 video
80 links
RootAccessClub ๐Ÿ’Ž

Security knowledge & research ๐Ÿ”Ž

Understanding systems, not abusing them โ›”๏ธ

โš ๏ธ Educational purposes only
Download Telegram
AI Agent Security Cheat Sheet ๐Ÿคทโ€โ™‚๏ธ

AI agents are autonomous systems powered by Large Language Models (LLMs) that can reason, plan, use tools, maintain memory, and take actions to accomplish goals. This expanded capability introduces unique security risks beyond traditional LLM prompt injection. This cheat sheet provides best practices to secure AI agent architectures and minimize attack surfaces ๐Ÿค–

Github ๐Ÿ“ฑ

#Cheat_sheet #llm #cybersecurity #infosec #ai

๐Ÿท @RootAccessClub
๐Ÿท @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
burp ai agent - The bridge between Burp Suite and modern AI โŒจ๏ธ

Burp Suite extension
that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

๐Ÿ’ค59 MCP Tools
๐Ÿ’ค62 Vulnerability Classes
๐Ÿ’คBurp Scan Skill
๐Ÿ’ค3 Privacy Modes
๐Ÿ’ค11 AI Backends
๐Ÿ’คAvailable on the BApp Store

Github ๐Ÿฑ

#BurpSuite #Ai #Pentesting #pentest #BugBounty #Burp_plugin

๐Ÿ›ฉ @BugCod3
๐Ÿ›ฉ @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
1
WebVM ๐Ÿค”

Run a Linux virtual machine in your browser ๐Ÿ’ธ

GitHub ๐Ÿฑ

#linux

โœˆ๏ธ @RootAccessClub
โœˆ๏ธ @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ1
Ethical Hacking Labs โ˜‘๏ธ

This is a collection of tutorials and labs made for ethical hacking students, cybersecurity students, network and sys-admins. These tutorials accompany the resources of CEH content and different resources across the internet ๐Ÿ”–

Github ๐Ÿฑ

#CEH #learning

๐Ÿ’Ž @RootAccessClub
๐Ÿ’Ž @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
Certified Penetration Tester (CPENT) Collection ๐Ÿ‘‘

Download โฌ‡๏ธ

#free #CPENT #learning #Pentesting

โšก๏ธ @RootAccessClub
โšก๏ธ @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ3โคโ€๐Ÿ”ฅ1โšก11
OASIS โ€“ Ollama Automated Security Intelligence Scanner ๐Ÿง 

An AI powered security auditing tool that leverages Ollama models to detect and analyze potential security vulnerabilities in your code

GitHub ๐Ÿง‘โ€๐Ÿ’ป

#Ai #Ollama #CyberSecurity
#Tools

๐ŸŒŸ@RootAccessClub
๐ŸŒŸ@BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ3๐Ÿ”ฅ2โšก1
nRFBOX ๐Ÿ“ฑ

Open source ESP32 powered tool to scan, jam, spoof, and master BLE, Wi-Fi, and 2.4GHz networks ๐Ÿค”

GitHub ๐Ÿ’ป

๐Ÿ’Ž @RootAccessClub
๐Ÿ’Ž @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ2
VICE ๐Ÿค”

VICE is a security auditing CLI tool that finds vulnerabilities in your web applications ๐Ÿค”

GitHub ๐Ÿฑ

#Tools #CyberSecurity

๐Ÿณ๏ธ @RootAccessClub
๐Ÿณ๏ธ @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
1
Microsoft Activation Scripts (MAS) ๐Ÿ’ป

Open source Windows and Office activator featuring HWID, Ohook, TSforge, and Online KMS activation methods, along with advanced troubleshooting ๐Ÿ—

How to Activate โ“

1๏ธโƒฃClick the Start Menu, type PowerShell and open it

2๏ธโƒฃCopy and paste the code below and press Enter

irm https://get.activated.win | iex 

If the above is blocked (by ISP/DNS), try this (needs updated Windows 10 or 11):

iex (curl.exe -s --doh-url https://1.1.1.1/dns-query https://get.activated.win | Out-String)


Github ๐Ÿ“ฑ

#windows #microsoft #Office

๐Ÿท @RootAccessClub
๐Ÿท @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ2
Kali Linux 2026.2 Release ๐Ÿ’ 

๐Ÿ”ฅ Desktop Environments - Bump to GNOME 50 and KDE Plasma 6.6

๐Ÿ”ฅ Helper Scripts Consistency - Consistency to our little launches at starting services

๐Ÿ”ฅ APT Format - Goodbye sources.list, hello sources.list.d/kali.source

๐Ÿ”ฅ VM Boot Optimisation - Smaller initrd + faster boot times = happy virtual machine users

๐Ÿ”ฅ Reboot Warning - Heads-up, polkit and xrdp upgrades require a system reboot

๐Ÿ”ฅ Kali Kernel Incoming - Staying with 6.19 for now, how to get 7.0 early

๐Ÿ”ฅ Build Scripts Incoming - Heads-up with some changing on the way

๐Ÿ”ฅ New Tools - As always, various new shiny packages have been added

Using Kali alreadyโ“ Great You can keep it up to date by doing:

โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~]
โ””โ”€$
sudo tee /etc/apt/sources.list.d/kali.sources << 'EOF'
Types: deb
URIs: http://http.kali.org/kali/
Suites: kali-rolling
Components: main contrib non-free non-free-firmware
Signed-By: /usr/share/keyrings/kali-archive-keyring.gpg
EOF
[...]

โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~]
โ””โ”€$
sudo apt update && sudo apt -y full-upgrade
[...]

โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~]
โ””โ”€$
cp -vrbi /etc/skel/. ~/
[...]

โ”Œโ”€โ”€(kaliใ‰ฟkali)-[~]
โ””โ”€$
sudo reboot -f

#linux #kali #kali_linux

๐Ÿ’Ž @RootAccessClub
๐Ÿ’Ž @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
BladeRecon ๐Ÿ—ก

BladeRecon is a lightweight reconnaissance framework for bug bounty, web pentesting, and reporting focused attack surface discovery ๐Ÿค•

Github ๐Ÿ’ป

#Pentesting #Bugbounty

๐Ÿ˜Ž @RootAccessClub
๐Ÿ˜Ž @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
1
arsenal-ng ๐Ÿ”ป

Modern pentest command launcher written in Go ๐Ÿ‘ฉโ€๐Ÿ’ป

The classic launcher, evolved. Fast, Go-based command library equipped with 200+ cybersecurity cheat-sheets. Just install and start hacking ๐ŸŸข

Github ๐Ÿฑ

#golang #go #pentesting #pentest

๐Ÿ’Ž @RootAccessClub
๐Ÿ’Ž @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
Full Bug Bounty Hunting & Red Teamers Methodology 2๏ธโƒฃ0๏ธโƒฃ2๏ธโƒฃ6๏ธโƒฃ

Created by Cybernote, aspiring Red Team Operator and Bug Bounty Hunter. This repository documents my methodology, notes and workflow for web application security testingโšก๏ธ

GitHub ๐Ÿฑ

#bug_bounty #bugbounty #RedTeam

๐Ÿ›ซ@RootAccessClub
๐Ÿ›ซ@BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
Netryx Astra V2 โšก๏ธ

Find Any Location from a Single Image with AI โณ

Github โ˜๏ธ

#Ai #Tools

๐ŸŸฃ @RootAccessClub
๐ŸŸฃ @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
2
SpideyX ๐Ÿ•ท

SpideyX a multipurpose Web Penetration Testing tool with asynchronous concurrent performance with multiple mode and configurations ๐Ÿคฉ

Github ๐Ÿฑ

#Tools #Pentest #pentesting

๐Ÿ•ท๏ธ@RootAccessClub
๐Ÿ•ท๏ธ@BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ3
๐Ÿ“ถ WEF โ€” WiFi Exploitation Framework

An open-source framework for WiFi security testing, combining manual and automated techniques for assessing WPA/WPA2, WPS and WEP networks across 2.4GHz and 5GHz bands ๐Ÿ›œ

๐Ÿฑ GitHub

๐Ÿ’Ž @RootAccessClub
๐Ÿ’Ž @BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
Complete cybersecurity course ๐Ÿ˜Ž

Download โฌ‡๏ธ

#Free #CyberSecurity

๐ŸŒŸ@RootAccessClub
๐ŸŒŸ@BugCod3
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ2
LegacyHive โ€“ Windows user profile service arbitrary hive load elevation of privileges vulnerability โ˜‘๏ธ

The PoC requires another standard user credentials and a third username (which can be an administrator account), if the PoC is successful, it will end up mounting the target user hive in current user classes root ๐Ÿ”น

Github ๐Ÿ“ฑ

โœˆ๏ธ @RootAccessClub
โœˆ๏ธ @IRSentinels
Please open Telegram to view this post
VIEW IN TELEGRAM
3
This media is not supported in your browser
VIEW IN TELEGRAM
CVE-2026-63030: wp2shell โš ๏ธ

a critical remote code execution vulnerability in WordPress core ๐ŸŒ

๐Ÿ’Ž@RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
โคโ€๐Ÿ”ฅ4
Root Access Club
CVE-2026-63030: wp2shell โš ๏ธ a critical remote code execution vulnerability in WordPress core ๐ŸŒ ๐Ÿ’Ž@RootAccessClub
wp2shell poc โ›”๏ธ
โž–โž–โž–โž–โž–โž–
Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory โบ
โž–โž–โž–โž–โž–โž–โž–โž–โž–
GitHub ๐Ÿฑ
โž–โž–โž–โž–โž–โž–โž–โž–โž–
For educational purposes only. Use at your own risk โš ๏ธ
โž–โž–โž–โž–โž–โž–โž–โž–โž–
โœˆ๏ธ @RootAccessClub
Please open Telegram to view this post
VIEW IN TELEGRAM
2