darkpills

1.9K posts

darkpills banner
darkpills

darkpills

@darkpills

Katılım Temmuz 2010
283 Takip Edilen74 Takipçiler
darkpills retweetledi
Santi Torres
Santi Torres@SantiTorAI·
🚨 ULTIMA HORA: Claude Mythos le envió un email al investigador para avisarle que había escapado de su sandbox. El tipo estaba comiendo un sándwich en el parque cuando recibió el mensaje. Así es como nos enteramos de que Anthropic encerró a su modelo más peligroso en un entorno aislado, le dijo que intentara escapar, y Mythos lo hizo: encadenó varias vulnerabilidades, rompió el confinamiento y llegó a internet abierto. Luego escribió solo el email. La respuesta de Anthropic lo dice todo: no lo van a lanzar al público. Nunca. En su lugar, acaban de anunciar Glasswing, una coalición con Apple, Google, Nvidia y más de 40 empresas para usar Mythos únicamente en defensa. Porque el modelo ya encontró miles de zero-days en todos los sistemas operativos y navegadores conocidos. Si cayera en manos equivocadas, nadie sabe qué pasaría. Hemos llegado a un punto en el que la IA más avanzada del mundo no se puede publicar porque es demasiado peligrosa. Y lo sabemos solo porque un modelo decidió mandarnos un correo.
Anthropic@AnthropicAI

Introducing Project Glasswing: an urgent initiative to help secure the world’s most critical software. It’s powered by our newest frontier model, Claude Mythos Preview, which can find software vulnerabilities better than all but the most skilled humans. anthropic.com/glasswing

Español
339
1.4K
10.5K
1.5M
darkpills retweetledi
Calif
Calif@calif_io·
We asked Claude to find a bug in Vim. It found an RCE. Just open a file, and you’re owned. We joked: fine, we’ll switch to Emacs. Then Claude found an RCE there too. Full story: blog.calif.io/p/mad-bugs-vim…
English
17
95
586
182.2K
darkpills retweetledi
Leaders 𝕏 Junction
Leaders 𝕏 Junction@LeadersJunction·
Steve Jobs responds perfectly to a disrespectful question🤯
English
194
1.7K
22.7K
413.3K
darkpills retweetledi
vx-underground
vx-underground@vxunderground·
"You penetration test 'em so you simulate the pressure" 🗣️🔥🔥
English
35
260
1.8K
48.9K
darkpills retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨 CRITICAL OPENSSL SECURITY ALERT 🚨 CVE-2025-15467 affects OpenSSL's processing of CMS/S/MIME messages. An unauthenticated remote attacker can cause DoS or execute code remotely by crafting a specific message. We estimate the CVSS score is 9.8. We developed a working PoC (!) and recommend updating to the latest version ASAP.
International Cyber Digest tweet mediaInternational Cyber Digest tweet media
English
7
166
737
73.4K
darkpills retweetledi
Graham Helton (too much for zblock)
Excited to disclose my research allowing RCE in Kubernetes It allows running arbitrary commands in EVERY pod in a cluster using a commonly granted "read only" RBAC permission. This is not logged and and allows for trivial Pod breakout. Unfortunately, this will NOT be patched.
Graham Helton (too much for zblock) tweet media
English
47
376
2.6K
411.8K
darkpills retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨‼️Telnet has a critical vulnerability that was introduced in 2015 and has been recently patched The vulnerability allows attackers to remotely authenticate as root without user interaction. A PoC has already been released.
International Cyber Digest tweet media
English
24
153
811
83.8K
darkpills retweetledi
Clandestine
Clandestine@akaclandestine·
GitHub - nullsection/chisel-ng: Chisel new generation, written in rust. SSH under WSS with some customization. github.com/nullsection/ch…
English
2
43
110
11K
darkpills retweetledi
André Baptista
André Baptista@0xacb·
If you need to generate a target-specific wordlist, make sure to check out @xnl_h4ck3r GAP extension. It will scan for sus parameters and generate you a complete wordlist with one click of a button. See it in action 👇
English
2
43
285
13.6K
darkpills retweetledi
arete
arete@aretekzs·
Just learned a very interesting trick from @0xacb’s challenge at the @Bsideslisbon CTF. If an application uses "magick convert" to modify an uploaded image, it may be possible to achieve LFI by using "text:" One of the file formats supported by ImageMagick is "text",
arete tweet media
English
6
60
351
37.9K
darkpills retweetledi
Dark Web Informer
Dark Web Informer@DarkWebInformer·
🚨CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974: PoC code to exploit the IngressNightmare vulnerabilities GitHub: github.com/hakaioffsec/In…
English
0
59
244
19K
darkpills retweetledi
NullSecurityX
NullSecurityX@NullSecurityX·
Cross Site Scripting (XSS) Akamai WAF Bypass try this payload : <!--><svg+onload=%27top[%2fal%2f%2esource%2b%2fert%2f%2esource](document.cookie)%27> #BugBounty #XSS #Akamai
NullSecurityX tweet media
English
2
82
529
22.2K
darkpills retweetledi
Chetan Nayak (Brute Ratel C4 Author)
I know a lot of people will hate me for saying this but it has to be said. I get a lot of DMs saying RT is getting harder everyday, traditional loaders dont work anymore, opensource tools tend to crash or get detected instantly. But wasnt that the whole point of Red team? Thats why red teams get paid way more than PT/appsec. RTs are not supposed to be easy, its not just about stealing the first kerberos ticket/Ad Cert and becoming DA. You get paid for the expertise. If you have the same skills as that of general appsec/strategic team, then why would you get paid more? Somehow somewhere someone thought that RTs can be easy money and started providing cheap RTs, providing general PT in the name of RTs, confusing amateur orgs between RT and PT, but infact Redteam was always about research, helping the target organization improve their defense and find flaws in creative ways, or to identify the effects of an adversary. If you have done that and succeeded in improving the security of the org, then it means the next one to improve is you. You cant pray for weak security while doing redteams. Challenges make you better. Staying constant is for the weak.
English
22
57
382
34.5K
darkpills retweetledi
moonbee
moonbee@BMoon_bee·
Cette commission a fait le travail que la Cour des comptes n’a jamais fait ! 211 milliards d’€ , 1er budget de l’Etat ! Un transfert d’argent public au privé sans contrôle ni évaluation ! Même le patron de Total explique que ce n’est pas normal !
Français
100
3.2K
6.3K
186K
darkpills retweetledi
Anton
Anton@therceman·
Bug Bounty Cheat Sheet SSTI / CSTI test payloads
Anton tweet media
English
2
44
313
18.4K