Duck Duck

1.1K posts

Duck Duck banner
Duck Duck

Duck Duck

@dsmcf

IT Security / Risk Management Professional; Hacker (@hacknotcrime); @dcskytalks Organizer; @TribeOfHackers Blue Team; @defcon Policy Goon; views here are mine

New Hampshire شامل ہوئے Ağustos 2014
927 فالونگ544 فالوورز
Duck Duck
Duck Duck@dsmcf·
@UK_Daniel_Card Nice pussy. So what did they do? Is it up to the providers how they implement controls or was there central guidance?
Duck Duck tweet media
English
0
0
0
177
mRr3b00t
mRr3b00t@UK_Daniel_Card·
I bypassed this on one of my phones on 20 seconds. No vpn required.
mRr3b00t tweet media
English
10
0
28
11K
Duck Duck
Duck Duck@dsmcf·
@SecurityWeek Microsoft is aware of active attacks targeting on-premises SharePoint Server hosts. SharePoint Online in Microsoft 365 is not impacted. A patch is currently not available for this vulnerability, please read more at msrc.microsoft.com/blog/2025/07/c… CVE 2025-49704 2025-49706 2025-53770
English
0
0
0
186
SecurityWeek
SecurityWeek@SecurityWeek·
Enterprises running SharePoint servers should not wait for a fix for CVE-2025-53770 and should commence threat hunting to search for compromise immediately. securityweek.com/sharepoint-und…
English
1
8
18
3K
The Hacker News
The Hacker News@TheHackersNews·
⚠️ A critical UNPATCHED zero-day in Microsoft SharePoint (CVE-2025-53770) is being massively exploited right now. At least 75 orgs breached—including major companies and governments. Here’s what you need to know ↓ thehackernews.com/2025/07/critic…
English
29
202
551
131.4K
International Cyber Digest
International Cyber Digest@IntCyberDigest·
🚨 ALERT 🚨 SharePoint servers are under attack: Eye Security identified active, large-scale exploitation of a new SharePoint remote code execution vulnerability chain, dubbed ToolShell. Exploitation began July 18, 2025. If you run SharePoint, act urgently. Thread 👇
International Cyber Digest tweet media
English
5
68
287
29K
&!^
&!^@ANDnXOR·
Badge started levitating in the drop zone. Hard hat antenna locked onto a magnetic anomaly shaped suspiciously like Matt Damon. @5n4ck3y just said “it’s working” and rolled into the fog. #mainedoesnotexist
English
1
1
9
623
watchTowr
watchTowr@watchtowrcyber·
🚨A SharePoint zero-day (CVE-2025-53770) is under active exploitation, with attackers stealing MachineKey secrets to forge __VIEWSTATE and maintain RCE. No patch exists. If you expose SharePoint to the Internet, assume breach. Reach out to via our website if you need support.
watchTowr tweet media
English
2
55
153
23.5K
International Cyber Digest
International Cyber Digest@IntCyberDigest·
The exploit combines two CVEs (CVE-2025-49706 & CVE-2025-49704) demo’d at Pwn2Own Berlin in May 2025 by Code White GmbH. It went public on X days ago, and boom—attackers weaponized it for unauthenticated remote code execution (RCE). No auth needed!
English
2
2
9
2.7K
Unit 42
Unit 42@Unit42_Intel·
We are observing active global exploitation of critical Microsoft SharePoint vulns CVE-2025-49704 and CVE-2025-49706. Orgs worldwide are being targeted. Patch immediately. The exploits are real, in-the-wild and pose a serious threat. IoCs we've seen: bit.ly/4kQZS2e
Unit 42 tweet media
English
5
118
299
69.2K
Duck Duck
Duck Duck@dsmcf·
Microsoft is aware of active attacks targeting on-premises SharePoint Server customers. SharePoint Online is not impacted. A patch is currently not available… read the blog post for more information: linkedin.com/posts/dmcfarla… #CVE 2025-49704 2025-49706 2025-53770 ToolPane.aspx
English
0
0
0
55
mRr3b00t
mRr3b00t@UK_Daniel_Card·
I can now right click an IP address and enrich with IPINFO and/or Shodan (bring your own keys!)
mRr3b00t tweet media
English
11
3
130
12.2K
Duck Duck
Duck Duck@dsmcf·
@DefconRaffle I heard a rumor that Mauvehed can insert and remove cards from sealed packs with his eyes closed #bbrtcg
GIF
English
0
0
1
16
Duck Duck ری ٹویٹ کیا
Natalie Winters
Natalie Winters@nataliegwinters·
🚨🚨🚨 The founder of the group behind the lawsuit removing President Trump from the Colorado Ballot reveals their largest donor is George Soros.
English
384
3.9K
7.8K
582.5K
Duck Duck ری ٹویٹ کیا
James O'Keefe
James O'Keefe@JamesOKeefeIII·
BREAKING LEAKED VIDEO: CEO of IBM @ArvindKrishna admits to using coercion to fire people and take away their bonuses unless they discriminate in the hiring process. “You got to move both forward by a percentage that leads to a plus on your bonus," Krishna said about hiring Hispanics, "and by the way if you lose, you lose part of your bonus.” After pulling ads from X for 'racism,' IBM chief Arvind Krishna says he will fire, demote or strip bonuses from execs who don't hire enough blacks, Hispanics — or hire too many Asians "Asians are not an underrepresented minority in tech in America...I’m not going to finess this, for blacks we should try to get towards 13 percent," says Krishna. Paul Cormier, the chairman of Red Hat, a subsidiary of IBM, says in the leaked recording that Red Hat has terminated people because they weren't willing to engage in racial discrimination through hiring and promotion. Title VII of the Civil Rights Act makes it illegal for employers to discriminate on the basis of race in the workplace. #IBMLeaks
English
2.9K
20.8K
48.2K
10.6M
WhiskeyHacker
WhiskeyHacker@whiskeyhacker·
Relic Rumble: The head-scratching persistence of NTLMv1 authentication in 2023 like clinging to a rotary phone in the age of smartphones It's like trying to win a modern smartphone battle armed with a rotary phone You're not just calling the past you're ringing up a disaster.
WhiskeyHacker tweet media
English
4
2
8
917
Duck Duck
Duck Duck@dsmcf·
@whiskeyhacker 1980s was better. Before IDs, bag scanners, non-transferable tickets and shitty seats.
English
0
0
1
19
WhiskeyHacker
WhiskeyHacker@whiskeyhacker·
At airport thinking how archaic this whole process is to fly somewhere Who remembers flying in the 1990s
English
1
0
9
331