<!-- SC_OFF -->Hi everyone! Hope you are all well. I’ve recently started a substack where I write about all things pentesting and life. For ages, my colleagues have told me to write about my journey into pentesting so I thought I would share it here. Feedback is welcome! https://substack.com/@silverafterhours/note/p-214580389?r=4bknbl&utm\_medium=ios&utm\_source=notes-share-action (https://substack.com/@silverafterhours/note/p-214580389?r=4bknbl&utm%5C_medium=ios&utm%5C_source=notes-share-action) <!-- SC_ON --> submitted by /u/supermusicxxx (https://www.reddit.com/user/supermusicxxx)
[link] (https://i.redd.it/h1cvbwk4t4oh1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9y8he/the_wrong_interview_the_right_career/)
[link] (https://i.redd.it/h1cvbwk4t4oh1.jpeg) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9y8he/the_wrong_interview_the_right_career/)
Learning Pentesting
https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/
<!-- SC_OFF -->Hello! I’m currently learning penetration testing, and I already have some basic knowledge and experience with pentesting. I was wondering if it would be a good idea to use ChatGPT, Claude, and Gemini together to guide me while I’m learning and practicing penetration testing. <!-- SC_ON --> submitted by /u/Skulln_Man30 (https://www.reddit.com/user/Skulln_Man30)
[link] (https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/)
https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/
<!-- SC_OFF -->Hello! I’m currently learning penetration testing, and I already have some basic knowledge and experience with pentesting. I was wondering if it would be a good idea to use ChatGPT, Claude, and Gemini together to guide me while I’m learning and practicing penetration testing. <!-- SC_ON --> submitted by /u/Skulln_Man30 (https://www.reddit.com/user/Skulln_Man30)
[link] (https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1w9z1sd/learning_pentesting/)
rustls v/0.23.44
https://kitploit.com/en/posts/github-rustls-rustls-v02344
Memory-safe TLS library in Rust implementing TLS 1.2 and 1.3 with pluggable crypto providers, client/server modes, and certificate-based authentication.
https://kitploit.com/en/posts/github-rustls-rustls-v02344
Memory-safe TLS library in Rust implementing TLS 1.2 and 1.3 with pluggable crypto providers, client/server modes, and certificate-based authentication.
I Used My Own Identity Provider to Take Over Another Tenant
How a missing tenant-to-SSO binding turned a valid authentication response into cross-organization account takeoverContinue reading on Medium »
Read more...
How a missing tenant-to-SSO binding turned a valid authentication response into cross-organization account takeoverContinue reading on Medium »
Read more...
Medium
I Used My Own Identity Provider to Take Over Another Tenant
How a missing tenant-to-SSO binding turned a valid authentication response into cross-organization account takeover
SkillSpector v2.11.1
https://kitploit.com/en/posts/github-nvidia-skillspector-v2111
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
https://kitploit.com/en/posts/github-nvidia-skillspector-v2111
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, security risks, prompt injection, data exfiltration, and supply-chain risks in Claude Code, Codex, and MCP skills before you install them.
0xM0nCrush
https://kitploit.com/en/tools/github/deathshotxd/0xm0ncrush
Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.
https://kitploit.com/en/tools/github/deathshotxd/0xm0ncrush
Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.
mxc
https://kitploit.com/en/tools/github/microsoft/mxc
Policy-driven, layered isolation and containment
https://kitploit.com/en/tools/github/microsoft/mxc
Policy-driven, layered isolation and containment
When Pre-Account Takeover Actually Means Pre-Account Takeover
https://medium.com/@mostvvfv/when-pre-account-takeover-actually-means-pre-account-takeover-84ee9dd2263c?source=rss------bug_bounty-5
https://medium.com/@mostvvfv/when-pre-account-takeover-actually-means-pre-account-takeover-84ee9dd2263c?source=rss------bug_bounty-5
بِسْمِ اللَّهِ رَبِّ الْعَالَمِينَ، وَالصَّلَاةُ وَالسَّلَامُ عَلَى رَسُولِنَا الْأَمِينِ.Continue reading on Medium » (https://medium.com/@mostvvfv/when-pre-account-takeover-actually-means-pre-account-takeover-84ee9dd2263c?source=rss------bug_bounty-5)
I Found a Tiny Filename Bypass That Broke a “Safe” Loader — and Earned $$$
https://medium.com/@xoemekk1/i-found-a-tiny-filename-bypass-that-broke-a-safe-loader-and-earned-7fc1afb70af3?source=rss------bug_bounty-5
https://medium.com/@xoemekk1/i-found-a-tiny-filename-bypass-that-broke-a-safe-loader-and-earned-7fc1afb70af3?source=rss------bug_bounty-5
I Used My Own Identity Provider to Take Over Another Tenant
https://yaseenzubair.medium.com/i-used-my-own-identity-provider-to-take-over-another-tenant-5f356ef77d3b?source=rss------bug_bounty-5
https://yaseenzubair.medium.com/i-used-my-own-identity-provider-to-take-over-another-tenant-5f356ef77d3b?source=rss------bug_bounty-5
How a missing tenant-to-SSO binding turned a valid authentication response into cross-organization account takeoverContinue reading on Medium » (https://yaseenzubair.medium.com/i-used-my-own-identity-provider-to-take-over-another-tenant-5f356ef77d3b?source=rss------bug_bounty-5)
Ethical Hacker: Hire The Best Certified Ethical Hackers > Smatchoicehackers.com
Certificate Ethical HackerContinue reading on Medium »
Read more...
Certificate Ethical HackerContinue reading on Medium »
Read more...
Medium
Ethical Hacker: Hire The Best Certified Ethical Hackers > Smatchoicehackers.com
Certificate Ethical Hacker
How a Default Password Let Me Log Into Almost Anyone’s Account
A story about how one shared default password, combined with a simple user-enumeration flaw, turned into a critical account takeover…Continue reading on Medium »
Read more...
A story about how one shared default password, combined with a simple user-enumeration flaw, turned into a critical account takeover…Continue reading on Medium »
Read more...
Medium
How a Default Password Let Me Log Into Almost Anyone’s Account
A story about how one shared default password, combined with a simple user-enumeration flaw, turned into a critical account takeover…
Video tutorial: How to run Password Spraying attacks directly from Sliver C2 framework?
https://www.reddit.com/r/redteamsec/comments/1w8qsx9/video_tutorial_how_to_run_password_spraying/
submitted by /u/lsecqt (https://www.reddit.com/user/lsecqt)
[link] (https://youtu.be/MgotYfujDio) [comments] (https://www.reddit.com/r/redteamsec/comments/1w8qsx9/video_tutorial_how_to_run_password_spraying/)
https://www.reddit.com/r/redteamsec/comments/1w8qsx9/video_tutorial_how_to_run_password_spraying/
submitted by /u/lsecqt (https://www.reddit.com/user/lsecqt)
[link] (https://youtu.be/MgotYfujDio) [comments] (https://www.reddit.com/r/redteamsec/comments/1w8qsx9/video_tutorial_how_to_run_password_spraying/)
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT
https://www.reddit.com/r/redteamsec/comments/1wal658/cve202525249_exploitation_delivers_pivotc2_a/
submitted by /u/socradario (https://www.reddit.com/user/socradario)
[link] (https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wal658/cve202525249_exploitation_delivers_pivotc2_a/)
https://www.reddit.com/r/redteamsec/comments/1wal658/cve202525249_exploitation_delivers_pivotc2_a/
submitted by /u/socradario (https://www.reddit.com/user/socradario)
[link] (https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wal658/cve202525249_exploitation_delivers_pivotc2_a/)