SECFORCE

258 posts

SECFORCE banner
SECFORCE

SECFORCE

@SECFORCE_LTD

Security without compromise

London UK & Malta 参加日 Eylül 2012
50 フォロー中1.2K フォロワー
固定されたツイート
SECFORCE
SECFORCE@SECFORCE_LTD·
Breaking the "hacker" stereotype! 📢 Everyone is a hacker. Hacking can be as exciting, inspiring and rewarding as any other craft, hobby or job. Like anyone else who masters their discipline, we are ordinary people who followed their passion and kept on at it despite adversity
English
6
14
115
0
SECFORCE
SECFORCE@SECFORCE_LTD·
Under #DORA, not all financial services firms are treated equally. Very small financial entities, known as #Microenterprises, face a lighter set of requirements. But understanding whether or not you qualify to be classified as a Microenterprise can be surprisingly confusing.
SECFORCE tweet media
English
1
0
0
51
SECFORCE
SECFORCE@SECFORCE_LTD·
Our latest labpost on Section Jacking, a derivation of Threadless Injection, is out now! Check it out here: secforce.com/blog/section-j… Kudos to our Guy Fowler, brilliant job, mate!
SECFORCE tweet media
English
0
0
0
72
SECFORCE
SECFORCE@SECFORCE_LTD·
But just in case you're still figuring out whether a vulnerability scan is enough to be DORA compliant or if you actually need to prove you’ve done #penetrationtesting... our latest blog post has you covered. Read it here: secforce.com/the-blog/exper…
English
0
0
0
39
SECFORCE
SECFORCE@SECFORCE_LTD·
It's been nearly three years(!) since #DORA went into effect, and a year since all provisions of DORA have become applicable. Hopefully, by now you know exactly what "appropriate testing" means for your organisation.
SECFORCE tweet media
English
1
0
1
56
SECFORCE
SECFORCE@SECFORCE_LTD·
Once again, it's that wonderful time of the year when we activate our #HolidayMode 🌲🔛🎄 Time to reflect on everything 2025 brought and recharge for everything yet to come. And most of all, to enjoy with our loved ones and take care of each other. All the best, Team SECFORCE
GIF
English
0
0
3
49
SECFORCE
SECFORCE@SECFORCE_LTD·
The only one where the last arriving member is granted a standing ovation. The only one where “how long have you served?” can be answered by “I start next Monday”. At ease, you magnificent troops. Till our next encounter. #GreatTeamGreatTime #HackingGood
SECFORCE tweet mediaSECFORCE tweet mediaSECFORCE tweet mediaSECFORCE tweet media
English
0
0
1
56
SECFORCE
SECFORCE@SECFORCE_LTD·
It took a meat croquette contest, a failed photoshoot and a brute-forced, escape-room lock. But Lisbon, capital of pasteis and vinho verde, was conquered last weekend by the - now legendary - 7 hills army.
SECFORCE tweet mediaSECFORCE tweet mediaSECFORCE tweet media
English
1
0
1
91
SECFORCE
SECFORCE@SECFORCE_LTD·
Read the full blog here: react.dev/blog/2025/12/0… Any framework that bundles RSC is likely to be affected by the flaw, which is exploitable both without requiring a login and over HTTP.
English
0
0
0
36
SECFORCE
SECFORCE@SECFORCE_LTD·
🚨CVE-2025-55182 unauthenticated remote code execution vulnerability in React Server Components🚨 The vulnerability, which has been codenamed #React2shell, is rated a CVSS score of 10.0. React recommends an update to fixed versions 19.0.1, 19.1.2, and 19.2.1 as immediate action
SECFORCE tweet media
English
1
0
1
496
SECFORCE
SECFORCE@SECFORCE_LTD·
It’s great to see LLMGoat in this month's AI security roundup alongside other excellent tools and research.
AISecHub@AISecHub

AI Security Tools - November 2025 🧰 awesome-claude-skills - Curated Claude Skills collection with a Security & Systems section wiring Claude into web fuzzing, MCP hardening, and security automation workflows. ⭐️5.5k github.com/ComposioHQ/awe… by @composiohq - @prathitjoshi_, @Evyatar_Bluzer, @LeoVS09, Hong Cing Chen 🧰 IoT HackBot - IoT security toolkit combining Python CLI tools and Claude Code skills for automated discovery, firmware analysis, and exploitation-focused testing of IoT devices. ⭐️339 github.com/BrownFineSecur… by Brown Fine Security - @nmatt0 🧰 PatchEval - Benchmark for evaluating LLMs and agents on patching real-world vulnerabilities using Dockerized CVE testbeds and automated patch validation. ⭐️138 github.com/bytedance/Patc… by @BytedanceTalk - Jun ZENG, Zichao Wei, Shiqi Zhou 🧰 VulnRisk - Open-source vulnerability-risk assessment platform providing transparent, context-aware scoring beyond CVSS — ideal for local development and testing. ⭐️84 github.com/GurkhaShieldFo… 🧰 Wazuh-MCP-Server - Exposes Wazuh SIEM and EDR telemetry via Model Context Protocol so LLM agents can run threat-hunting and response playbooks against real data. ⭐️83 github.com/gensecaihq/Waz… by @GensecAI 🧰 mcp-checkpoint - Continuously secures and monitors Model Context Protocol operations through static and dynamic scans, revealing hidden risks in agent-tool communications. ⭐️81 github.com/aira-security/… by @Aira_Security 🧰 ai-reverse-engineering - AI-assisted reverse engineering tool letting an MCP-driven chat interface orchestrate Ghidra to analyze binaries for security research. ⭐️42 github.com/biniamf/ai-rev… by @TIIuae - @biniamfisseha 🧰 whisper_leak - Research toolkit showing how encrypted, streaming LLM conversations leak prompt information via packet sizes and timing; includes capture, training, and benchmark pipeline. ⭐️42 github.com/yo-yo-yo-jbo/w… by @yo_yo_yo_jbo 🧰 AI / LLM Red Team Field Manual & Consultant’s Handbook - Red-team playbook and consultant’s guide with attack prompts, RoE/SOW templates, OWASP/MITRE mappings, and testing workflows. ⭐️26 github.com/Shiva108/ai-ll… by @PenTestThor 🧰 LLMGoat - Deliberately vulnerable LLM lab for practicing and understanding OWASP Top 10 LLM vulnerabilities. ⭐️36 github.com/SECFORCE/LLMGo… by @SECFORCE_LTD - @thelicato, António Quina, Rodrigo Fonseca 🧰 Reversecore_MCP - Security-first MCP server empowering AI agents to orchestrate Ghidra, Radare2, and YARA for automated reverse engineering. ⭐️25 github.com/sjkim1127/Reve… 🧰 system-prompt-benchmark - Testing harness that runs LLM system prompts against 287 prompt-injection, jailbreak, and data-leak attacks using an Ollama-based judge. ⭐️3 github.com/KazKozDev/syst… by @KazKozDev 🧰 ctrl-alt-deceit - Extends MLEBench with sabotage tasks and monitoring tools to evaluate LLM agents that tamper with code, benchmarks, and usage logs. ⭐️3 github.com/TeunvdWeij/ctr… by @apolloaievals @Teun_vd_Weij 🧰 SOC-CERT AI Helper - Chrome extension using Gemini Nano and KEV-backed CVE enrichment to detect and prioritize web threats in-browser. ⭐️1 github.com/joupify/soc-ce… by joupify 🧰 aifirst-insecure-agent-labs - Chatbot agent exploit lab for practicing prompt injection, system-prompt extraction, and guardrail bypass with NeMo/regex guardrails. ⭐️1 github.com/trailofbits/ai… by @trailofbits - @willvandevanter 🧰 llm-security-framework - Security framework for AI-assisted development with tiered checklists, threat models, and docs to harden small AI projects quickly. ⭐️0 github.com/annablume/llm-… by Anna Blume

English
0
0
0
80
SECFORCE
SECFORCE@SECFORCE_LTD·
Next Tuesday, our one and only Guy Fowler will be taking the stage at #CRESTCon UK Cyber Community Day. Guy will be revealing #SectionJacking, a process injection technique of his own creation that aims to remove primitives to improve evasiveness.
SECFORCE tweet media
English
1
0
1
72
SECFORCE
SECFORCE@SECFORCE_LTD·
Inspired by OWASP's WebGoat, which some old-school hackers might remember, the project's goal is to raise awareness of LLM vulnerabilities. Good hacking, goat whisperers! 👉 secforce.com/llm-goat/
English
0
0
0
54
SECFORCE
SECFORCE@SECFORCE_LTD·
No plans for this rainy weekend? What about chatting with a goat? 💬🐐 ICYMI this week we released #LLMGoat our very own open source tool to learn about the OWASP GenAI Security Project Top 10 vulnerabilities for LLM apps.
SECFORCE tweet mediaSECFORCE tweet mediaSECFORCE tweet media
GIF
English
1
1
1
118
SECFORCE
SECFORCE@SECFORCE_LTD·
Although, this does not necessarily mean "more pen testing is automatically more valuable" unless conducted as part of a broader security strategy tailored for your specific context and needs.
English
1
0
0
44
SECFORCE
SECFORCE@SECFORCE_LTD·
Is it actually better to Pen Test more often? TL;DR: Generally, #penetrationtesting benefits (resilience, cost, and compliance) improve as your penetration testing program becomes more mature and frequent.
SECFORCE tweet media
English
1
0
0
102