SkillSpector v2.11.1
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
Read more...
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
Read more...
When Pre-Account Takeover Actually Means Pre-Account Takeover
بِسْمِ اللَّهِ رَبِّ الْعَالَمِينَ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِنَا الْأَمِينِ.Continue reading on Medium »
Read more...
بِسْمِ اللَّهِ رَبِّ الْعَالَمِينَ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِنَا الْأَمِينِ.Continue reading on Medium »
Read more...
Medium
When Pre-Account Takeover Actually Means Pre-Account Takeover
بِسْمِ اللَّهِ رَبِّ الْعَالَمِينَ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِنَا الْأَمِينِ.
I Found a Tiny Filename Bypass That Broke a “Safe” Loader — and Earned $$$
Continue reading on Medium »
Read more...
Continue reading on Medium »
Read more...
Medium
I Found a Tiny Filename Bypass That Broke a “Safe” Loader — and Earned $ $$$
I Found a Tiny Filename Bypass That Broke a “Safe” Loader — and Earned $ $$$ السلام عليكم ورحمة الله وبركاتة Sometimes the best security findings start with a …
choosing college degree
https://www.reddit.com/r/Pentesting/comments/1w9ll85/choosing_college_degree/
<!-- SC_OFF -->I’m 18 years old and have been doing bug bounties since I was 15. I earned my CPTS and eJPT certifications I’m finishing my last in year in high school and getting ready for college. I’m trying to decide if I want to get a bachelor’s degree in Computer Science or Cybersecurity. I feel like cybersecurity bachelor’s programs focus on fundamentals, not advanced techniques. I’m also interested in AI because I want to get deep in AI red teaming. <!-- SC_ON --> submitted by /u/Capital-Rub269 (https://www.reddit.com/user/Capital-Rub269)
[link] (https://www.reddit.com/r/Pentesting/comments/1w9ll85/choosing_college_degree/) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9ll85/choosing_college_degree/)
https://www.reddit.com/r/Pentesting/comments/1w9ll85/choosing_college_degree/
<!-- SC_OFF -->I’m 18 years old and have been doing bug bounties since I was 15. I earned my CPTS and eJPT certifications I’m finishing my last in year in high school and getting ready for college. I’m trying to decide if I want to get a bachelor’s degree in Computer Science or Cybersecurity. I feel like cybersecurity bachelor’s programs focus on fundamentals, not advanced techniques. I’m also interested in AI because I want to get deep in AI red teaming. <!-- SC_ON --> submitted by /u/Capital-Rub269 (https://www.reddit.com/user/Capital-Rub269)
[link] (https://www.reddit.com/r/Pentesting/comments/1w9ll85/choosing_college_degree/) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9ll85/choosing_college_degree/)
Scoping our firm's first pentest engagement: Looking for methodology and ROE advice for a small team.
https://www.reddit.com/r/Pentesting/comments/1w9ogwn/scoping_our_firms_first_pentest_engagement/
<!-- SC_OFF -->Hey everyone, Our small MSP/IT firm is expanding our offerings and preparing to execute our very first client penetration testing engagement. I am looking for some technical and operational advice to make sure we scope and execute this correctly. Our Setup: We have a two-person team handling this new service: Technical Lead (Me): I have a background in IT networking and hold my Sec+. I have foundational pentesting knowledge (labs, CTFs) but this will be my first time leading a live commercial engagement. GRC Lead: My colleague (also Sec+) is handling the administrative side. He has already drafted up a solid SOW (Statement of Work) and ROE (Rules of Engagement), so we have the legal/compliance side reasonably locked down. The Proposed Plan: We are planning to start the engagement with a phishing campaign, followed by a White Box pentest. Currently, we are letting the client select their exact testing scope from the following menu: [ ] External Network Penetration Test [ ] Internal Network Penetration Test [ ] Active Directory Assessment [ ] Web Application Penetration Test Questions for the Community: Scope Reality Check: Is this menu of services too broad for a newly established two-man team? Should we restrict our first few engagements to just Internal/External Network testing? Methodology: For a White Box approach, what frameworks (e.g., PTES, OWASP) do you recommend we strictly adhere to for a first-time engagement? Risk Management: What are the most common beginner pitfalls when transitioning from lab environments to live production networks? What technical guardrails should we put in place to ensure we don't accidentally knock over their services? Reporting: Any recommendations on reporting templates or tools that help deliver real business value, rather than just handing them a glorified vulnerability scan output? Any advice on tools, scoping, or managing client expectations would be massively appreciated. Thanks! <!-- SC_ON --> submitted by /u/PsychologicalMud59 (https://www.reddit.com/user/PsychologicalMud59)
[link] (https://www.reddit.com/r/Pentesting/comments/1w9ogwn/scoping_our_firms_first_pentest_engagement/) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9ogwn/scoping_our_firms_first_pentest_engagement/)
https://www.reddit.com/r/Pentesting/comments/1w9ogwn/scoping_our_firms_first_pentest_engagement/
<!-- SC_OFF -->Hey everyone, Our small MSP/IT firm is expanding our offerings and preparing to execute our very first client penetration testing engagement. I am looking for some technical and operational advice to make sure we scope and execute this correctly. Our Setup: We have a two-person team handling this new service: Technical Lead (Me): I have a background in IT networking and hold my Sec+. I have foundational pentesting knowledge (labs, CTFs) but this will be my first time leading a live commercial engagement. GRC Lead: My colleague (also Sec+) is handling the administrative side. He has already drafted up a solid SOW (Statement of Work) and ROE (Rules of Engagement), so we have the legal/compliance side reasonably locked down. The Proposed Plan: We are planning to start the engagement with a phishing campaign, followed by a White Box pentest. Currently, we are letting the client select their exact testing scope from the following menu: [ ] External Network Penetration Test [ ] Internal Network Penetration Test [ ] Active Directory Assessment [ ] Web Application Penetration Test Questions for the Community: Scope Reality Check: Is this menu of services too broad for a newly established two-man team? Should we restrict our first few engagements to just Internal/External Network testing? Methodology: For a White Box approach, what frameworks (e.g., PTES, OWASP) do you recommend we strictly adhere to for a first-time engagement? Risk Management: What are the most common beginner pitfalls when transitioning from lab environments to live production networks? What technical guardrails should we put in place to ensure we don't accidentally knock over their services? Reporting: Any recommendations on reporting templates or tools that help deliver real business value, rather than just handing them a glorified vulnerability scan output? Any advice on tools, scoping, or managing client expectations would be massively appreciated. Thanks! <!-- SC_ON --> submitted by /u/PsychologicalMud59 (https://www.reddit.com/user/PsychologicalMud59)
[link] (https://www.reddit.com/r/Pentesting/comments/1w9ogwn/scoping_our_firms_first_pentest_engagement/) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9ogwn/scoping_our_firms_first_pentest_engagement/)
Best beginner certs for web?
https://www.reddit.com/r/Pentesting/comments/1w9sxxj/best_beginner_certs_for_web/
<!-- SC_OFF -->I'm a high school student and I'm trying to get some certs to build up my Portfolio for college apps as well as internships, etc.. I've already got eJPT and done pentesting on THM for about 6-8 months. I am comfortable with most easy and most medium rooms. I've also done a bunch of labs on portswigger. I've been debating between PWPP and eWPT for my next cert, are these okay for a beginner/intermediate level (I know the basics of the OWASP top 10 and web pentesting). Are there any other certs suggested? <!-- SC_ON --> submitted by /u/Vivid_Reward_8008 (https://www.reddit.com/user/Vivid_Reward_8008)
[link] (https://www.reddit.com/r/Pentesting/comments/1w9sxxj/best_beginner_certs_for_web/) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9sxxj/best_beginner_certs_for_web/)
https://www.reddit.com/r/Pentesting/comments/1w9sxxj/best_beginner_certs_for_web/
<!-- SC_OFF -->I'm a high school student and I'm trying to get some certs to build up my Portfolio for college apps as well as internships, etc.. I've already got eJPT and done pentesting on THM for about 6-8 months. I am comfortable with most easy and most medium rooms. I've also done a bunch of labs on portswigger. I've been debating between PWPP and eWPT for my next cert, are these okay for a beginner/intermediate level (I know the basics of the OWASP top 10 and web pentesting). Are there any other certs suggested? <!-- SC_ON --> submitted by /u/Vivid_Reward_8008 (https://www.reddit.com/user/Vivid_Reward_8008)
[link] (https://www.reddit.com/r/Pentesting/comments/1w9sxxj/best_beginner_certs_for_web/) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9sxxj/best_beginner_certs_for_web/)
The wrong interview, the right career
https://www.reddit.com/r/Pentesting/comments/1w9y8he/the_wrong_interview_the_right_career/
https://www.reddit.com/r/Pentesting/comments/1w9y8he/the_wrong_interview_the_right_career/
<!-- SC_OFF -->Hi everyone! Hope you are all well. I’ve recently started a substack where I write about all things pentesting and life. For ages, my colleagues have told me to write about my journey into pentesting so I thought I would share it here. Feedback is welcome! https://substack.com/@silverafterhours/note/p-214580389?r=4bknbl&utm\_medium=ios&utm\_source=notes-share-action (https://substack.com/@silverafterhours/note/p-214580389?r=4bknbl&utm%5C_medium=ios&utm%5C_source=notes-share-action) <!-- SC_ON --> submitted by /u/supermusicxxx (https://www.reddit.com/user/supermusicxxx)
[link] (https://i.redd.it/h1cvbwk4t4oh1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9y8he/the_wrong_interview_the_right_career/)
[link] (https://i.redd.it/h1cvbwk4t4oh1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9y8he/the_wrong_interview_the_right_career/)
Learning Pentesting
https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/
<!-- SC_OFF -->Hello! I’m currently learning penetration testing, and I already have some basic knowledge and experience with pentesting. I was wondering if it would be a good idea to use ChatGPT, Claude, and Gemini together to guide me while I’m learning and practicing penetration testing. <!-- SC_ON --> submitted by /u/Skulln_Man30 (https://www.reddit.com/user/Skulln_Man30)
[link] (https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/)
https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/
<!-- SC_OFF -->Hello! I’m currently learning penetration testing, and I already have some basic knowledge and experience with pentesting. I was wondering if it would be a good idea to use ChatGPT, Claude, and Gemini together to guide me while I’m learning and practicing penetration testing. <!-- SC_ON --> submitted by /u/Skulln_Man30 (https://www.reddit.com/user/Skulln_Man30)
[link] (https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/)
rustls v/0.23.44
https://kitploit.com/en/posts/github-rustls-rustls-v02344
Memory-safe TLS library in Rust implementing TLS 1.2 and 1.3 with pluggable crypto providers, client/server modes, and certificate-based authentication.
https://kitploit.com/en/posts/github-rustls-rustls-v02344
Memory-safe TLS library in Rust implementing TLS 1.2 and 1.3 with pluggable crypto providers, client/server modes, and certificate-based authentication.
I Used My Own Identity Provider to Take Over Another Tenant
How a missing tenant-to-SSO binding turned a valid authentication response into cross-organization account takeoverContinue reading on Medium »
Read more...
How a missing tenant-to-SSO binding turned a valid authentication response into cross-organization account takeoverContinue reading on Medium »
Read more...
Medium
I Used My Own Identity Provider to Take Over Another Tenant
How a missing tenant-to-SSO binding turned a valid authentication response into cross-organization account takeover
SkillSpector v2.11.1
https://kitploit.com/en/posts/github-nvidia-skillspector-v2111
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
https://kitploit.com/en/posts/github-nvidia-skillspector-v2111
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
0xM0nCrush
https://kitploit.com/en/tools/github/deathshotxd/0xm0ncrush
Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.
https://kitploit.com/en/tools/github/deathshotxd/0xm0ncrush
Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.
mxc
https://kitploit.com/en/tools/github/microsoft/mxc
Policy-driven, layered isolation and containment
https://kitploit.com/en/tools/github/microsoft/mxc
Policy-driven, layered isolation and containment
When Pre-Account Takeover Actually Means Pre-Account Takeover
https://medium.com/@mostvvfv/when-pre-account-takeover-actually-means-pre-account-takeover-84ee9dd2263c?source=rss------bug_bounty-5
https://medium.com/@mostvvfv/when-pre-account-takeover-actually-means-pre-account-takeover-84ee9dd2263c?source=rss------bug_bounty-5
بِسْمِ اللَّهِ رَبِّ الْعَالَمِينَ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِنَا الْأَمِينِ.Continue reading on Medium » (https://medium.com/@mostvvfv/when-pre-account-takeover-actually-means-pre-account-takeover-84ee9dd2263c?source=rss------bug_bounty-5)
I Found a Tiny Filename Bypass That Broke a “Safe” Loader — and Earned $$$
https://medium.com/@xoemekk1/i-found-a-tiny-filename-bypass-that-broke-a-safe-loader-and-earned-7fc1afb70af3?source=rss------bug_bounty-5
https://medium.com/@xoemekk1/i-found-a-tiny-filename-bypass-that-broke-a-safe-loader-and-earned-7fc1afb70af3?source=rss------bug_bounty-5