WINDOWS PRIVILEGE ESCALATION USING NCSI ACTIVE PROBES
https://www.reddit.com/r/redteamsec/comments/1wsgscq/windows_privilege_escalation_using_ncsi_active/
<!-- SC_OFF -->Peter Gabaldon from LABS @ ITRES discusess a vulnerability in the Windows Network Connectivity Status Indicator (NCSI) that can be exploited to escalate privileges from a low-privileged user to local admin. The attack leverages proxy configuration flaws to relay authentication to an Active Directory Certificate Services endpoint, enabling attackers to forge access tickets. <!-- SC_ON --> submitted by /u/That_Address_2122 (https://www.reddit.com/user/That_Address_2122)
[link] (https://labs.itresit.es/2026/09/28/windows-privilege-escalation-using-ncsi-active-probes/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wsgscq/windows_privilege_escalation_using_ncsi_active/)
https://www.reddit.com/r/redteamsec/comments/1wsgscq/windows_privilege_escalation_using_ncsi_active/
<!-- SC_OFF -->Peter Gabaldon from LABS @ ITRES discusess a vulnerability in the Windows Network Connectivity Status Indicator (NCSI) that can be exploited to escalate privileges from a low-privileged user to local admin. The attack leverages proxy configuration flaws to relay authentication to an Active Directory Certificate Services endpoint, enabling attackers to forge access tickets. <!-- SC_ON --> submitted by /u/That_Address_2122 (https://www.reddit.com/user/That_Address_2122)
[link] (https://labs.itresit.es/2026/09/28/windows-privilege-escalation-using-ncsi-active-probes/) [comments] (https://www.reddit.com/r/redteamsec/comments/1wsgscq/windows_privilege_escalation_using_ncsi_active/)
Benchmark and defense code for persistent memory attacks on OpenClaw-style computer-use agents, with memory-zoning mitigation, attack scenarios, and evaluation scripts.
The Bug Bounty Report That Got Closed as “Informative” (And How I Fixed It)
https://medium.com/@neonmaxima/the-bug-bounty-report-that-got-closed-as-informative-and-how-i-fixed-it-769654ef6d0c?source=rss------bug_bounty-5
https://medium.com/@neonmaxima/the-bug-bounty-report-that-got-closed-as-informative-and-how-i-fixed-it-769654ef6d0c?source=rss------bug_bounty-5
I still have the screenshot.Continue reading on Medium » (https://medium.com/@neonmaxima/the-bug-bounty-report-that-got-closed-as-informative-and-how-i-fixed-it-769654ef6d0c?source=rss------bug_bounty-5)
Smali By bithowl: Chapter 13 Object Operations
https://medium.com/@bithowl/smali-by-bithowl-chapter-13-object-operations-ba65301a7d5f?source=rss------bug_bounty-5
https://medium.com/@bithowl/smali-by-bithowl-chapter-13-object-operations-ba65301a7d5f?source=rss------bug_bounty-5
“The Register Has an Object. But What Exactly Is It?”Continue reading on Medium » (https://medium.com/@bithowl/smali-by-bithowl-chapter-13-object-operations-ba65301a7d5f?source=rss------bug_bounty-5)
The Bug Bounty Report That Got Closed as “Informative” (And How I Fixed It)
I still have the screenshot.Continue reading on Medium »
Read more...
I still have the screenshot.Continue reading on Medium »
Read more...
Medium
The Bug Bounty Report That Got Closed as “Informative” (And How I Fixed It)
I still have the screenshot.
Smali By bithowl: Chapter 13 Object Operations
“The Register Has an Object. But What Exactly Is It?”Continue reading on Medium »
Read more...
“The Register Has an Object. But What Exactly Is It?”Continue reading on Medium »
Read more...
Medium
Smali By bithowl: Chapter 13 Object Operations
“The Register Has an Object. But What Exactly Is It?”
🕵️♂️ All-in-one OSINT tool for analysing any website