Most tools added AI and called it a feature. We kept asking whether it actually makes results more reliable.

Session two of Office Hours is recorded. Jan covers the ML classifier, the authentication layer, and the MCP integration that won't act without your explicit go-ahead.

45 minutes. Q&A included.

Recording: https://www.youtube.com/watch?v=abGruzf2pPk

#penetrationtesting #offensivesecurity #vulnerabilitymanagement

Office Hours 2: AI, Accuracy and what's next

YouTube
Frida 17.9.5 Released

Observe and reprogram running programs on Windows, macOS, GNU/Linux, iOS, watchOS, tvOS, Android, FreeBSD, and QNX

Frida • A world-class dynamic instrumentation toolkit
Teachable to YouTube - Here's Why I Made the Switch

YouTube

HackRF PortaPack Splash Screen Without Removing the SD Card

https://www.youtube.com/watch?v=KZ6xrDWykf4

#cybersecurity #iotsecurity #penetrationtesting

HackRF PortaPack Splash Screen Without Removing the SD Card

YouTube

CVE-2026-40321: stored XSS in DNN (DotNetNuke) prior to v10.2.2 chains to full RCE.

Any authenticated user can upload a crafted SVG with embedded JavaScript. If a power user opens it, the payload calls DNN's own config endpoint to drop an ASPX backdoor in the server root.

One file. One click. Full RCE. CVSS 8.1, patched, fully documented.

Write-up + PoC payloads: https://pentest-tools.com/blog/dotnetnuke-xss-to-rce

More research from our team: https://pentest-tools.com/research

#offensivesecurity #penetrationtesting #infosec

DotNetNuke: XSS to RCE (CVE-2026-40321)

Pentest-Tools.com

AI Hacking Tools Are Coming Soon… NEW Neoconda AI Integration Details!

https://www.youtube.com/watch?v=89DTERT6IvI

#cybersecurity #aisecurity #penetrationtesting

AI Hacking Tools Are Coming Soon… NEW Neoconda AI Integration Details!

YouTube

Compliance evidence trails don't build themselves in the two weeks before an audit.
Jan Pedersen walked through how continuous scanning handles that automatically: scheduled scans, before-and-after remediation proof, reports for both auditors and engineers.

Recording: https://www.youtube.com/watch?v=HpuXoV_ngRQ
Tomorrow: session two on AI, accuracy and what's next.
1️⃣ 3:00 PM Bucharest / 1:00 PM London / 8:00 AM New York
👉 https://zoom.us/webinar/register/WN_uMAjbUwRSqCj1knLCcOCTg
2️⃣ 7:00 PM Bucharest / 5:00 PM London / 12:00 PM New York / 9:00 AM Los Angeles
👉 https://zoom.us/webinar/register/WN_xp1ewHcMQVKVoZe4bAEIxw
#infosec #compliance #penetrationtesting

Office hours #1: From panic to process — building a compliance evidence trail

YouTube
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side

Claude Mythos’ April 7 launch accelerates vulnerability discovery, but limited access and rising false positives strain remediation workflows.

The Hacker News

Sicherheitslücke in Geutebrück-Kameras: Befehlsinjektion ermöglichte Root-Zugriff über Weboberfläche

Über mindestens 13 CGI-Endpunkte der Weboberfläche ließen sich nach erfolgreicher Authentifizierung beliebige Systembefehle mit Root-Rechten einschleusen. Ausgangspunkt war eine einzige Fehlermeldung des Unix-Werkzeugs sed.

https://www.all-about-security.de/sicherheitsluecke-in-geutebrueck-kameras-befehlsinjektion-ermoeglichte-root-zugriff-ueber-weboberflaeche/

#penetrationtesting #unix #root #rootrechte #Authentifizierung

Sicherheitslücke in Geutebrück-Kameras: Befehlsinjektion ermöglichte Root-Zugriff über Weboberfläche

Sicherheitsforscher entdeckten eine Befehlsinjektion in Geutebrück-Kameras. Angreifer konnten als Root beliebige Befehle ausführen. Patch liegt vor.

All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing, IT-Sicherheit, Netzwerksicherheit, KI, Threats, DDoS, Identity & Access, Plattformsicherheit