⤷ Title: LdrShuffle: Stealthy Code Execution via DLL EntryPoint Overwriting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:27:50 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Code Execution #Defensive Telemetry #DLL hijacking #Lateral Movement #LdrShuffle #Memory Injection #Red Team #Windows Loader
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 23 Nov 2025 03:27:50 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Code Execution #Defensive Telemetry #DLL hijacking #Lateral Movement #LdrShuffle #Memory Injection #Red Team #Windows Loader
Penetration Testing Tools
LdrShuffle: Stealthy Code Execution via DLL EntryPoint Overwriting
"LdrShuffle" is a stealthy code execution technique that abuses the Windows Loader by overwriting a DLL's EntryPoint, enabling injection without creating new threads.
⤷ Title: DCOMRunAs: Covert Technique for Remote Code Execution in a Logged-on Session
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 03:31:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #DCOM #DCOMRunAs #DLL hijacking #Lateral Movement #post_exploitation #remote code execution #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 03:31:40 +0000
════════════════════════
⌗ Tags: #Open Source Tool #DCOM #DCOMRunAs #DLL hijacking #Lateral Movement #post_exploitation #remote code execution #Windows Security
Penetration Testing Tools
DCOMRunAs: Covert Technique for Remote Code Execution in a Logged-on Session
DCOMRunAs is a covert technique that exploits DCOM and DLL hijacking to execute payloads in the context of a remote, logged-on user's session without new process creation.
⤷ Title: FusterCluck PoC: Script Exploits RPC to Achieve Lateral Movement in Failover Clusters
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 08:23:48 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Cluster API #Failover Cluster #FusterCluck #Lateral Movement #PoC #Red Team #RPC #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 03 Dec 2025 08:23:48 +0000
════════════════════════
⌗ Tags: #Open Source Tool #Cluster API #Failover Cluster #FusterCluck #Lateral Movement #PoC #Red Team #RPC #Windows Security
Penetration Testing Tools
FusterCluck PoC: Script Exploits RPC to Achieve Lateral Movement in Failover Clusters
FusterCluck PoC exploits the Windows Cluster API over RPC to migrate cluster groups and achieve lateral movement across all nodes of a failover cluster.
⤷ Title: HTB CTF Write-Up: Dancing
════════════════════════
𐀪 Author: Paulo Melo
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:00:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #smbclient #hackthebox_writeup #enumeration #lateral_movement
════════════════════════
𐀪 Author: Paulo Melo
════════════════════════
ⴵ Time: Sun, 14 Dec 2025 22:00:52 GMT
════════════════════════
⌗ Tags: #cybersecurity #smbclient #hackthebox_writeup #enumeration #lateral_movement
Medium
HTB CTF Write-Up: Dancing
Hello, fellow nerds!
⤷ Title: Silent Pivot: Exploiting SpeechRuntimeMove for Stealthy Lateral Movement via DCOM
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 04:57:03 +0000
════════════════════════
⌗ Tags: #Open Source Tool #COM Hijacking #DCOM #DLL Sideloading #Lateral Movement #post_exploitation #red teaming #Remote Registry #SpeechRuntime #Windows Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 17 Dec 2025 04:57:03 +0000
════════════════════════
⌗ Tags: #Open Source Tool #COM Hijacking #DCOM #DLL Sideloading #Lateral Movement #post_exploitation #red teaming #Remote Registry #SpeechRuntime #Windows Security
Penetration Testing Tools
Silent Pivot: Exploiting SpeechRuntimeMove for Stealthy Lateral Movement via DCOM
SpeechRuntimeMove abuses DCOM and COM hijacking to execute code in an active user's session, bypassing the need for a full system takeover.
⤷ Title: From Edge to Cloud: Pivoting to AWS via Compromised IoT Greengrass Devices
════════════════════════
𐀪 Author: Arun Nair
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 17:54:10 GMT
════════════════════════
⌗ Tags: #greengrass #penetration_testing #lateral_movement #aws #red_team
════════════════════════
𐀪 Author: Arun Nair
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 17:54:10 GMT
════════════════════════
⌗ Tags: #greengrass #penetration_testing #lateral_movement #aws #red_team
Medium
From Edge to Cloud: Pivoting to AWS via Compromised IoT Greengrass Devices
TL;DR
⤷ Title: Exploited in the Wild: Critical BeyondTrust Flaw (CVSS 9.9) Opens Door to Network Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 15 Feb 2026 03:58:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arctic Wolf #BeyondTrust #CISA KEV #CVE_2026_1731 #lateral movement #Patch Alert #Privileged Remote Access #Remote Support #RMM #SimpleHelp
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 15 Feb 2026 03:58:23 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arctic Wolf #BeyondTrust #CISA KEV #CVE_2026_1731 #lateral movement #Patch Alert #Privileged Remote Access #Remote Support #RMM #SimpleHelp
Daily CyberSecurity
Exploited in the Wild: Critical BeyondTrust Flaw (CVSS 9.9) Opens Door to Network Takeover
Arctic Wolf warns of CVE-2026-1731, a critical BeyondTrust flaw exploited in the wild. Attackers use it to deploy backdoors. Patch self-hosted instances now.
⤷ Title: Active Directory Security Series — Part 3
════════════════════════
𐀪 Author: servet demirci
════════════════════════
ⴵ Time: Sun, 01 Mar 2026 10:33:37 GMT
════════════════════════
⌗ Tags: #azure_active_directory #ethical_hacking #privilege_escalation #lateral_movement
════════════════════════
𐀪 Author: servet demirci
════════════════════════
ⴵ Time: Sun, 01 Mar 2026 10:33:37 GMT
════════════════════════
⌗ Tags: #azure_active_directory #ethical_hacking #privilege_escalation #lateral_movement
Medium
Active Directory Security Series — Part 3
Privilege Escalation: How a Single Misconfigured Permission Can Bring Down an Entire Domain
⤷ Title: Edge of Extinction: How FortiGate Flaws Open the Gates to Active Directory Subjugation
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:19:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Active Directory #CVE_2025_59718 #CVE_2025_59719 #CVE_2026_24858 #FortiGate #Fortinet #InfoSec 2026 #Initial Access Broker #Lateral Movement #NTDS.dit #SentinelOne #SIEM #SSO Bypass
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 12 Mar 2026 07:19:35 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Active Directory #CVE_2025_59718 #CVE_2025_59719 #CVE_2026_24858 #FortiGate #Fortinet #InfoSec 2026 #Initial Access Broker #Lateral Movement #NTDS.dit #SentinelOne #SIEM #SSO Bypass
Penetration Testing Tools
Edge of Extinction: How FortiGate Flaws Open the Gates to Active Directory Subjugation
The compromise of a perimeter network appliance can swiftly shepherd a malefactor toward domain controllers and the enterprise’s
⤷ Title: SentinelOne Unmasks Exploitation of FortiGate Appliances as Gateways to Network Takeover
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 15 Mar 2026 14:00:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #CVE_2025_59718 #CVE_2026_24858 #cybersecurity #FortiGate #infosec #lateral movement #network_security #SentinelOne DFIR #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sun, 15 Mar 2026 14:00:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #CVE_2025_59718 #CVE_2026_24858 #cybersecurity #FortiGate #infosec #lateral movement #network_security #SentinelOne DFIR #threat intelligence
Daily CyberSecurity
SentinelOne Unmasks Exploitation of FortiGate Appliances as Gateways to Network Takeover
SentinelOne DFIR reveals how attackers exploit FortiGate NGFW flaws to extract credentials, abuse Active Directory, and establish persistent network access.
⤷ Title: Wormable Bugs: Microsoft April 2026 Patch Tuesday Fixes Two “Zero-Interaction” RCE Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 03:15:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_33824 #CVE_2026_33827 #cybersecurity #IKE Service #infosec #IPv6 #lateral movement #Microsoft #Patch Tuesday #rce #windows #Wormable
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 17 Apr 2026 03:15:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_33824 #CVE_2026_33827 #cybersecurity #IKE Service #infosec #IPv6 #lateral movement #Microsoft #Patch Tuesday #rce #windows #Wormable
Daily CyberSecurity
Wormable Bugs: Microsoft April 2026 Patch Tuesday Fixes Two "Zero-Interaction" RCE Flaws
Microsoft’s April 2026 Patch Tuesday fixes two "wormable" CVEs (9.8 & 8.1 CVSS). Secure your network against zero-click RCE and lateral movement now.
⤷ Title: Microsoft Teams Exploited for Silent Enterprise Takeovers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 00:40:29 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Administrative Protocols #data exfiltration #infosec #lateral movement #Level RMM #Microsoft Defender #Microsoft Teams #Quick Assist #Rclone #social engineering #WinRM
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 00:40:29 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Administrative Protocols #data exfiltration #infosec #lateral movement #Level RMM #Microsoft Defender #Microsoft Teams #Quick Assist #Rclone #social engineering #WinRM
Daily CyberSecurity
Microsoft Teams Exploited for Silent Enterprise Takeovers
Microsoft warns of a Teams campaign using fake IT support to hijack workstations via Quick Assist, move laterally with WinRM, and steal data using Rclone.
⤷ Title: Splunk Unmasks New Malware Campaign Pairing Ghost RAT with CloverPlus Adware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 06:44:16 +0000
════════════════════════
⌗ Tags: #Malware #adware #CloverPlus #cybersecurity #defense evasion #Ghost RAT #infosec #Keylogger #lateral movement #malware #RDP Theft #Splunk STRT #wiseman.exe
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 22 Apr 2026 06:44:16 +0000
════════════════════════
⌗ Tags: #Malware #adware #CloverPlus #cybersecurity #defense evasion #Ghost RAT #infosec #Keylogger #lateral movement #malware #RDP Theft #Splunk STRT #wiseman.exe
Daily CyberSecurity
Splunk Unmasks New Malware Campaign Pairing Ghost RAT with CloverPlus Adware
Splunk STRT identifies a new campaign bundling Ghost RAT with CloverPlus adware to steal RDP credentials and monetize infections. Patch your systems now!
⤷ Title: Day 21 : Password Attacks HTB
════════════════════════
𐀪 Author: Cybersecurity with Jojo
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 16:39:47 GMT
════════════════════════
⌗ Tags: #hackthebox #lateral_movement #hackthebox_writeup #hackthebox_walkthrough #cybersecurity
════════════════════════
𐀪 Author: Cybersecurity with Jojo
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 16:39:47 GMT
════════════════════════
⌗ Tags: #hackthebox #lateral_movement #hackthebox_writeup #hackthebox_walkthrough #cybersecurity
Medium
Day 21 : Password Attacks HTB
In offensive security engagements, gaining an initial foothold is rarely the end goal. What truly defines the impact of a penetration test…
⤷ Title: Critical Wazuh Vulnerability Enables Lateral Movement and Root Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 12:05:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cluster Security #CVE_2026_30893 #cybersecurity #infosec #lateral movement #open_source #Patch Alert #Path Traversal #rce #Threat Detection #wazuh
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 30 Apr 2026 12:05:42 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cluster Security #CVE_2026_30893 #cybersecurity #infosec #lateral movement #open_source #Patch Alert #Path Traversal #rce #Threat Detection #wazuh
Daily CyberSecurity
Critical Wazuh Vulnerability Enables Lateral Movement and Root Access
Wazuh patches a critical 9.0 CVSS flaw (CVE-2026-30893) in cluster sync. Malicious peers can achieve RCE and lateral movement. Upgrade your clusters now.
⤷ Title: Bir Casino, Balık Tankı Yüzünden Soyuldu
════════════════════════
𐀪 Author: canndalcii
════════════════════════
ⴵ Time: Thu, 14 May 2026 20:21:15 GMT
════════════════════════
⌗ Tags: #siber_güvenlik #hacking #lateral_movement #iot #security
════════════════════════
𐀪 Author: canndalcii
════════════════════════
ⴵ Time: Thu, 14 May 2026 20:21:15 GMT
════════════════════════
⌗ Tags: #siber_güvenlik #hacking #lateral_movement #iot #security
Medium
Bir Casino, Balık Tankı Yüzünden Soyuldu
Güvenlik açığının bir nükleer reaktörde ya da bankada olmasına gerek yoktu. Bir termometre yeterliydi.
⤷ Title: Spirals Ransomware Encrypts a South Asian IT Network in Under 24 Hours
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 14:30:13 +0000
════════════════════════
⌗ Tags: #Malware #Double Extortion #IIS Web Shell #lateral movement #PsExec #ransomware #Rust malware #Spirals Ransomware #Symantec
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 14:30:13 +0000
════════════════════════
⌗ Tags: #Malware #Double Extortion #IIS Web Shell #lateral movement #PsExec #ransomware #Rust malware #Spirals Ransomware #Symantec
Daily CyberSecurity
Spirals Ransomware Encrypts a South Asian IT Network in Under 24 Hours
At a glance Malware family Spirals (new Rust-based ransomware, named by its operators) Threat actor Unknown. No named group; attribution not established. Target / victims One IT services company i…