Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of ProxyBlob Agent.
Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of ProxyBlob Agent.
A .NET 8 toolkit for creating and analysing Windows Shell Link (.lnk) files. Includes a command-line builder (LnkMeMaybe) and a graphical editor (LnkUi).
Orchestrate detonating your MalDev in VMs with different EDRs to see their detection surface.
Generalized Wi-Fi Client Isolation Bypasses
DCSync Beacon Object File (BOF)
Tried my new VPN gateway on a Raspberry Pi and booted BlackArch live to explore some tools. Sadly, the distro feels abandoned: outdated packages, broken apps, no copy/paste in terminals, and a prehistoric Firefox. A shame, because it still boots under 500MB RAM ๐
This ASPX web shell enables execution of Beacon Object Files (BOFs) on a target server using a semi-interactive Python client.
๐ฃ New @7ASecurity public #Pentest report
๐ @dComms improves resilience with verified fixes, thanks to @OpenTechFund
4 issues identified (2 high) and remediated
Feedback is welcome enjoy ๐
๐ https://7asecurity.com/blog/2026/03/dcomms-audit-by-7asecurity/
Another session announcement for BSides Luxembourg!
๐ป ๐ง๐๐ข๐ฆ๐ ๐ช๐๐ข ๐๐ข๐กโ๐ง ๐๐๐๐ฅ๐ก ๐๐ฅ๐ข๐ ๐๐ฉ๐๐ฆ ๐๐ฅ๐ ๐๐ข๐ข๐ ๐๐ ๐ง๐ข ๐ฅ๐๐๐๐ฆ๐๐ข๐ฉ๐๐ฅ ๐ง๐๐๐ - Louis Nyffenegger (@snyff ) ๐ฅ
Real vulnerabilities donโt appear in isolation, theyโre rooted in code, context, and human error. This session walks through actual CVEs, analyzing the code where they were introduced. You will see the patterns, assumptions, and language quirks that led to the flaw - not just the exploit, but the moment it couldโve been caught.
Louis Nyffenegger https://bsky.app/profile/snyff.pentesterlab.com is the founder of PentesterLab and AppSecSchool, application security expert, and hands-on trainer with experience at the National Bank of Australia, Australia Post, and Fitbit.
๐
Conference Dates: 6โ8 May 2026 | 09:00โ18:00
๐ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐๏ธ Tickets: https://2026.bsides.lu/tickets/
๐
Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/
#BSidesLuxembourg #CVE #CodeReview #SecureCoding #PenTest #SecurityEducation #DevSecOps
Opening a file in GNU Emacs can trigger arbitrary code execution through version control (git), most requiring zero user interaction beyond the file open itself.
https://github.com/califio/publications/blob/main/MADBugs/vim-vs-emacs-vs-claude/Emacs.md
#infosec #cybersecurity #redteam #pentest #ai #emacs #claude