VillaRoot

601 posts

VillaRoot banner
VillaRoot

VillaRoot

@VillaRoot

¡Viva Cristo Rey! Adversary Emulation Engineer

localhost Bergabung Nisan 2022
414 Mengikuti421 Pengikut
VillaRoot me-retweet
𝑵𝒐𝒃𝒍𝒆
𝑵𝒐𝒃𝒍𝒆@Nobleheart·
He is Risen.
GIF
English
70
2.3K
18K
220.1K
VillaRoot me-retweet
Pope Leo XIV
Pope Leo XIV@Pontifex·
Christ is risen from the dead, and with him, we too rise to new life! This Easter proclamation embraces the mystery of our lives and the destiny of history, reaching us even in the depths of death. #Easter
English
1.1K
17K
116K
1.8M
VillaRoot
VillaRoot@VillaRoot·
Bad Omens Tour SanAntonioTx
English
0
0
2
52
VillaRoot
VillaRoot@VillaRoot·
Another day, another major supply chain attack
VillaRoot tweet media
English
0
0
2
38
VillaRoot me-retweet
Feross
Feross@feross·
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
547
4.1K
16.3K
12.2M
VillaRoot
VillaRoot@VillaRoot·
@LindseyOD123 Don't worry they just need a couple of hours for IT to build up their Cyber defenses
English
0
0
3
109
Medusa
Medusa@medusa_0xf·
I'm happy to share that I’ve just completed the Hugging Face LLM Fundamentals course! ✨ Learned about: - LLM architectures (encoder-decoder vs. decoder-only) - Self-attention and masked attention mechanisms - Tokenization and how LLMs process text, is trained & limits!
Medusa tweet media
English
7
0
100
3.3K
VillaRoot
VillaRoot@VillaRoot·
When will it end?! 🚨Breaking:AIRedTeamHackPentest
VillaRoot tweet media
English
2
0
2
103
VillaRoot
VillaRoot@VillaRoot·
@infosec_fox You trying to AI my AI with your AI using AI?!
English
0
0
1
10
INFOSEC F0X 🔥
INFOSEC F0X 🔥@infosec_fox·
All the new AI tool released now uses AI to create new AI to AI your AI into AI with AI
English
6
1
8
452
VillaRoot
VillaRoot@VillaRoot·
@medusa_0xf Not fully replace it. Part of the toolkit but not a replacement. If anything it might become it's own streamline, how a Vulnerability Assessment is. There's also the risk of it hallucinating and going outside the the ROE scope. And if it causes an outage, clients will be pissed.
English
1
0
9
1.7K
Medusa
Medusa@medusa_0xf·
Will pentesting be replaced by AI? 🤔
English
63
17
172
44.2K
VillaRoot
VillaRoot@VillaRoot·
@bngrsec We'd be disappointed if you didn't
GIF
English
0
0
2
61
bngr
bngr@bngrsec·
gained initial access to a user and had to pivot to someone else because their cat was cute as fuck
English
1
0
2
172
VillaRoot
VillaRoot@VillaRoot·
Make sure to be checking if Tor connections is blocked on workstations. Useful purple team exercise right here: Try making connections to Tor on an workstation -> Work with detections team -> retest.
Tanner@wbmmfq

A fun new-ish #Clickfix payload has been using Node.js to deploy a local SOCKS proxy, then connecting to Tor over that to download a secondary payload. Maybe I'll do a bit more of a writeup of it later. We'll see how the day goes.

English
0
0
2
103
VillaRoot
VillaRoot@VillaRoot·
@wbmmfq That's pretty interesting!
English
0
0
1
55
Tanner
Tanner@wbmmfq·
A fun new-ish #Clickfix payload has been using Node.js to deploy a local SOCKS proxy, then connecting to Tor over that to download a secondary payload. Maybe I'll do a bit more of a writeup of it later. We'll see how the day goes.
English
4
4
46
3.2K
Jason Lang
Jason Lang@curi0usJack·
It's over.
Jason Lang tweet media
English
7
2
27
3K
Medusa
Medusa@medusa_0xf·
The only best real life anime adaptation I’ve seen is “one piece”. Like just take a look at what they did to Death Note, Nahh bro 😭🙏
English
5
1
15
1.1K
VillaRoot
VillaRoot@VillaRoot·
@RussianPanda9xx But will the treat actors still file my taxes for me after I download the malware? I'm already getting robbed with these taxes anyways
English
0
0
2
89
RussianPanda 🐼 🇺🇦
RussianPanda 🐼 🇺🇦@RussianPanda9xx·
Tax season is open 🎯 New blog just dropped on a malvertising campaign targeting W-2/W-9 searches since January 2026 Google Ad -> dual-layer cloaking -> rogue ScreenConnect -> FatMalloc crypter (2GB alloc to choke AV emulators) -> previously undocumented Huawei audio driver killing EDR 60+ rogue SC instances across our customer base 💀 huntress.com/blog/w2-malver…
English
3
13
77
8.1K
Bryson 🦄
Bryson 🦄@brysonbort·
Explain AI to me in 0 words.
English
115
5
72
10.4K