niph

1.2K posts

niph banner
niph

niph

@niph_

red / purple teaming at @codewhitesec - my tweets, my opinions - https://t.co/YcrfmTTwqg

🏔️ เข้าร่วม Nisan 2013
591 กำลังติดตาม471 ผู้ติดตาม
niph รีทวีตแล้ว
CODE WHITE GmbH
CODE WHITE GmbH@codewhitesec·
You like technical deep dives into binary exploitation and crazy heap wizardry? Then you'll like our blog post by @0xor_solo about unauth'ed RCE in NetSupport Manager aka CVE-2025-34164 & CVE-2025-34165 code-white.com/blog/2026-01-n…
English
0
52
140
17.9K
niph รีทวีตแล้ว
solst/ICE of Astarte
solst/ICE of Astarte@IceSolst·
I wrote Task Unmanager: keeps killing processes Russian Roulette style, until your machine crashes
English
531
4.5K
61.7K
1.8M
niph รีทวีตแล้ว
IT Unprofessional
IT Unprofessional@it_unprofession·
Last week I hosted family for Thanksgiving. My 12-year-old nephew asked for the WiFi password. He wanted to play Roblox on his iPad. I looked at the device. Unmanaged. No antivirus. No encryption. I’m an IT Professional. I don't run an open network. So I didn’t give him the password. Instead, I spent 45 minutes provisioning a Guest VLAN. I set up a captive portal. I throttled the bandwidth down to 56kbps. Then I blocked all traffic on ports 80 and 443. He came back crying. He said it wouldn't load. My sister screamed at me to "just let him play." I told her that Zero Trust architecture doesn't care about bloodlines. We didn't have a "fun" Thanksgiving. But we had a secure perimeter. You’re welcome for the compliance.
English
1.9K
6.1K
116.3K
8.9M
niph รีทวีตแล้ว
Andrea P
Andrea P@decoder_it·
We know that Microsoft improved the overall printing security in 2025, now using DCE/RPC for callback, you can force NTLM local auth and reflect back machine auth even without CredMarshalTargetInfo() trick 😇
Andrea P tweet mediaAndrea P tweet media
English
6
73
295
17.9K
niph รีทวีตแล้ว
Smukx.E
Smukx.E@5mukx·
Smukx.E tweet media
ZXX
5
39
463
15K
niph รีทวีตแล้ว
Tuta
Tuta@TutaPrivacy·
🚨Our governments are about to decide whether 450M Europeans deserve privacy - or not. Help ensure your country says NO to Chat Control: Call you local representatives! Privacy is not negotiable. Speak up now. ✊ #privacy 👉 More on how to stop Chat Control: tuta.com/blog/chat-cont…
Tuta tweet media
English
39
547
1.4K
70.2K
niph รีทวีตแล้ว
Check Point Research
Check Point Research@_CPResearch_·
Malicious executions of compiled JavaScript, leading to the of JSCEAL — a stealthy, multi-stage crypto stealer : ⚠️ Malicious ads for fake crypto apps installers 🧩 Modular PowerShell loaders 🕵️ Unique evasion techniques that kept the campaign undetected research.checkpoint.com/2025/jsceal-ta…
English
2
30
83
7.5K
niph รีทวีตแล้ว
Dirk-jan
Dirk-jan@_dirkjan·
For those like me who prefer to stay in the terminal and want to call REST APIs like the Microsoft Graph without complicated commands or copy/pasting tokens: roadtx now has a graphrequest command to perform simple requests against these APIs and parse the JSON.
Dirk-jan tweet media
English
3
39
151
9.9K
niph รีทวีตแล้ว
CODE WHITE GmbH
CODE WHITE GmbH@codewhitesec·
We have reproduced "ToolShell", the unauthenticated exploit chain for CVE-2025-49706 + CVE-2025-49704 used by @_l0gg to pop SharePoint at #Pwn2Own Berlin 2025, it's really just one request! Kudos to @mwulftange
CODE WHITE GmbH tweet media
English
8
163
643
109.7K
niph รีทวีตแล้ว
%TEMP%
%TEMP%@TEMP43487580·
It was great to attend #TROOPERS25! Beautiful city, nice weather, talented researchers. My talk was just based on how Entra works but I hope it contributed to the community. Thanks for everyone I had a chance to talk to! No jet lug now. Time to go home😂 github.com/temp43487580/E…
English
2
23
86
16.7K
niph รีทวีตแล้ว
IT Guy
IT Guy@T3chFalcon·
New attack vector: FileFix. A phishing trick that executes PowerShell straight from your browser no Run dialog, no pop-ups. Just a fake file path + clipboard + File Explorer. Red teamers, this one’s wild. 📽️ PoC + write-up: @t3chfalcon/filefix-a-simple-social-engineering-trick-that-launches-powershell-from-the-browser-31ff3120ccd1" target="_blank" rel="nofollow noopener">medium.com/@t3chfalcon/fi…
IT Guy@T3chFalcon

Great work 👏@mrd0x I'll try to replicate this "FileFix Attack Simulation" 💪

English
27
250
1.1K
107.3K
niph
niph@niph_·
Lets go, looking forward to the next few days ;)
niph tweet media
English
0
0
6
68
niph รีทวีตแล้ว
Yehuda Smirnov
Yehuda Smirnov@yudasm_·
What if you skipped VirtualAlloc, skipped WriteProcessMemory and still got code execution? We explored process injection using nothing but thread context. Full write-up + PoCs: blog.fndsec.net/2025/05/16/the…
English
6
76
221
13.8K
niph รีทวีตแล้ว
Dirk-jan
Dirk-jan@_dirkjan·
I'll be returning to #BHUSA @BlackHatEvents this summer for a brand talk about moving laterally from AD to Entra ID. I don't think I've ever been this excited about a talk, with lots of cool stuff to share 🎢 😄.
Dirk-jan tweet media
English
10
33
195
13.6K
niph รีทวีตแล้ว
Bobby Cooke
Bobby Cooke@0xBoku·
⚡️ Loki C2 just leveled up! 🍄🧙‍♂️ 🔗 Agents can now link to each other, and across platforms! 🔗 No internet? No problem. Chain them, pivot deep, and keep moving! @XForce @IBM @IBMSecurity Check out the new release here: github.com/boku7/Loki
Bobby Cooke tweet media
English
7
66
253
14.1K
niph รีทวีตแล้ว
Rich Mirch
Rich Mirch@0xm1rch·
I blogged about my discovery of CVE-2025-26684 - Microsoft Defender for Endpoint (MDE) on Linux Elevation of Privilege stratascale.com/vulnerability-…
English
3
30
111
10.5K