Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
OIHK – Sistema operativo OSINT local-first open source + motor de pentesting multiagente
https://www.reddit.com/r/Pentesting/comments/1vz7hj0/oihk_sistema_operativo_osint_localfirst_open/

<!-- SC_OFF -->Compartiendo dos herramientas open source que he estado construyendo bajo el proyecto OIHK: \*\*OIHK Basic\*\* → Espacio de trabajo para investigar OSINT local-first (gestión de evidencias, grafos de inteligencia, modelos de IA locales solamente). App de escritorio hecha con Tauri. \*\*OIHK-pentesting\*\* → Motor de pruebas de penetración autónomas multiagente. Incluye un planificador “root” y agentes especializados para reconocimiento, descubrimiento, validación y reporte. Los hallazgos solo se aceptan cuando hay evidencia real de ejecución de herramientas + un paso de validación separado. Tiene funciones de aplicación exacta del alcance, sandboxing y controles de salida (egress). Todo corre completamente local (LM Studio / Ollama). No hace falta la nube. Diseñado solo para evaluaciones autorizadas. Repos (licencia MIT): \- Basic → https://github.com/Broskigx/OIHK-Basic \- Pentesting → https://github.com/Broskigx/Oihk-pentesting El proyecto todavía está en desarrollo activo (beta). Hay bugs y partes incompletas. Si lo pruebas y encuentras errores o comportamientos inesperados, por favor abre un issue o repórtalos — de verdad ayuda a mejorar las herramientas. Se agradece muchísimo el feedback de la comunidad open source y de seguridad. <!-- SC_ON --> submitted by /u/Broskigx (https://www.reddit.com/user/Broskigx)
[link] (https://www.reddit.com/r/Pentesting/comments/1vz7hj0/oihk_sistema_operativo_osint_localfirst_open/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vz7hj0/oihk_sistema_operativo_osint_localfirst_open/)
Why an LLM can't reliably tell an authorized pentester from an attacker using copyable context
https://www.reddit.com/r/Pentesting/comments/1vzcpoe/why_an_llm_cant_reliably_tell_an_authorized/
WINFLESHER - Attack Surface Security Framework
https://www.reddit.com/r/Pentesting/comments/1vzdz4c/winflesher_attack_surface_security_framework/

<!-- SC_OFF -->Hey everyone, just dropped a tool called winflesher that might come in super handy for windows machines. It's strictly for enumeration and assessment, so no auto-exploitation—purely helps you map things out. Check it out if you want! Like PingCastle went out for drinks with Bloodhound, and they actually decided to get some work done. 🍷 WinFlesher is an advanced attack surface security assessment framework designed to analyze, evaluate, and report on security postures, attack paths, and remediation strategies in complex environments. Developed for security professionals and cybersecurity auditors, WinFlesher automates vulnerability discovery and critical path correlation within Active Directory and local infrastructures. https://github.com/mindsflee/WinFlesher <!-- SC_ON --> submitted by /u/mindsflee (https://www.reddit.com/user/mindsflee)
[link] (https://www.reddit.com/r/Pentesting/comments/1vzdz4c/winflesher_attack_surface_security_framework/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vzdz4c/winflesher_attack_surface_security_framework/)
<!-- SC_OFF -->A recent preprint formalizes a problem pentesters keep running into with LLM safeguards: the same dual-use request can come from an authorized tester or an attacker, and copyable context cannot reliably prove which one you are. Paper: https://arxiv.org/abs/2607.27951 <!-- SC_ON --> submitted by /u/ClaudiusPapirus (https://www.reddit.com/user/ClaudiusPapirus)
[link] (https://www.youtube.com/watch?v=-2iITRLT7fg) [comments] (https://www.reddit.com/r/Pentesting/comments/1vzcpoe/why_an_llm_cant_reliably_tell_an_authorized/)
Hx0-HawkEye v1.0.6

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling capture, interception, modification, replay, rule-based detection, and AI-assisted analysis—all from the browser sidebar.)
Read more...
androidReverse v20
https://kitploit.com/en/posts/github-ultrasina-androidreverse-v20

Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.
magic-extractor v1.3.1

Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.
Read more...
The Best-Paying Bug in Bounty Isn’t the One Everyone Hunts

4,590 disclosed reports. Eleven bug types. The crowd is hunting where the money isn’t.Continue reading on Medium »
Read more...
cottage v0.7.0

A modern git based age-encrypted secrets manager for teams.
Read more...
cdncheck v1.2.50

A utility to detect various technology for a given IP address.
Read more...
Hackers Don’t Need Zero-Days Anymore: How Misconfigurations, IAM & Broken Logic Become Critical

Every time a breach makes headlines, someone asks “was it a zero-day?” Almost every time, the honest answer is no.Continue reading on Medium »
Read more...
4,590 disclosed reports. Eleven bug types. The crowd is hunting where the money isn’t.Continue reading on Medium » (https://medium.com/@rajnamdev/the-best-paying-bug-in-bounty-isnt-the-one-everyone-hunts-878568269b67?source=rss------bug_bounty-5)
Every time a breach makes headlines, someone asks “was it a zero-day?” Almost every time, the honest answer is no.Continue reading on Medium » (https://medium.com/@bugitrix/hackers-dont-need-zero-days-anymore-how-misconfigurations-iam-broken-logic-become-critical-293df09deaf4?source=rss------bug_bounty-5)
Crack the Gate 1 — picoCTF Write-up | Authentication Bypass via Hidden HTTP Header

IntroductionContinue reading on Medium »
Read more...
cli v1.1307.0

Snyk CLI scans and monitors your projects for security vulnerabilities.
Read more...
Nest v2026.08.24

Your gateway to OWASP. Discover, engage, and help shape the future!
Read more...
apex v2.4.0-canary.d5c18874

AI-powered offensive security testing using autonomous agents, directly in your terminal.
Read more...