Weaponize signed .NET ClickOnce applications for initial access by hijacking a dependency DLL via AppDomainManager injection and loading a C# port of ProxyBlob Agent.

https://github.com/dazzyddos/ClickOnceBlobber

#infosec #cybersecurity #redteam #pentest

A .NET 8 toolkit for creating and analysing Windows Shell Link (.lnk) files. Includes a command-line builder (LnkMeMaybe) and a graphical editor (LnkUi).

https://github.com/trustedsec/LnkMeMaybe

#infosec #cybersecurity #redteam #pentest #phishing

Orchestrate detonating your MalDev in VMs with different EDRs to see their detection surface.

https://github.com/dobin/detonator

#infosec #cybersecurity #redteam #pentest

GitHub - dobin/detonator: Orchestrate detonating your MalDev in VMs with different EDRs to see their detection surface.

Orchestrate detonating your MalDev in VMs with different EDRs to see their detection surface. - dobin/detonator

GitHub
GitHub - vanhoefm/airsnitch: Generalized Wi-Fi Client Isolation Bypasses

Generalized Wi-Fi Client Isolation Bypasses. Contribute to vanhoefm/airsnitch development by creating an account on GitHub.

GitHub

Tried my new VPN gateway on a Raspberry Pi and booted BlackArch live to explore some tools. Sadly, the distro feels abandoned: outdated packages, broken apps, no copy/paste in terminals, and a prehistoric Firefox. A shame, because it still boots under 500MB RAM ๐Ÿ˜•

#linux #infosec #pentest #raspberrypi #vpn #blackarch

This ASPX web shell enables execution of Beacon Object Files (BOFs) on a target server using a semi-interactive Python client.

https://github.com/epotseluevskaya/ASPX_WebShell_COFFLoader

#infosec #cybersecurity #redteam #pentest #web

GitHub - epotseluevskaya/ASPX_WebShell_COFFLoader: ASPX Web Shell with COFF Loader

ASPX Web Shell with COFF Loader. Contribute to epotseluevskaya/ASPX_WebShell_COFFLoader development by creating an account on GitHub.

GitHub

๐Ÿ“ฃ New @7ASecurity public #Pentest report
๐Ÿ” @dComms improves resilience with verified fixes, thanks to @OpenTechFund
4 issues identified (2 high) and remediated
Feedback is welcome enjoy ๐Ÿ™‚
๐Ÿ”— https://7asecurity.com/blog/2026/03/dcomms-audit-by-7asecurity/

#7ASecurity #CyberSecurity #OpenSource #dComms #infosec

dComms audit by 7ASecurity - 7ASecurity Blog

dComms security audit by 7ASecurity covering whitebox testing, vulnerabilities, and remediations for secure decentralized communication

7ASecurity Blog

Another session announcement for BSides Luxembourg!

๐Ÿ’ป ๐—ง๐—›๐—ข๐—ฆ๐—˜ ๐—ช๐—›๐—ข ๐——๐—ข๐—กโ€™๐—ง ๐—Ÿ๐—˜๐—”๐—ฅ๐—ก ๐—™๐—ฅ๐—ข๐—  ๐—–๐—ฉ๐—˜๐—ฆ ๐—”๐—ฅ๐—˜ ๐——๐—ข๐—ข๐— ๐—˜๐—— ๐—ง๐—ข ๐—ฅ๐—˜๐——๐—œ๐—ฆ๐—–๐—ข๐—ฉ๐—˜๐—ฅ ๐—ง๐—›๐—˜๐—  - Louis Nyffenegger (@snyff ) ๐Ÿ’ฅ

Real vulnerabilities donโ€™t appear in isolation, theyโ€™re rooted in code, context, and human error. This session walks through actual CVEs, analyzing the code where they were introduced. You will see the patterns, assumptions, and language quirks that led to the flaw - not just the exploit, but the moment it couldโ€™ve been caught.

Louis Nyffenegger https://bsky.app/profile/snyff.pentesterlab.com is the founder of PentesterLab and AppSecSchool, application security expert, and hands-on trainer with experience at the National Bank of Australia, Australia Post, and Fitbit.

๐Ÿ“… Conference Dates: 6โ€“8 May 2026 | 09:00โ€“18:00
๐Ÿ“ 14, Porte de France, Esch-sur-Alzette, Luxembourg
๐ŸŽŸ๏ธ Tickets: https://2026.bsides.lu/tickets/
๐Ÿ“… Schedule Link: https://pretalx.com/bsidesluxembourg-2026/schedule/

#BSidesLuxembourg #CVE #CodeReview #SecureCoding #PenTest #SecurityEducation #DevSecOps

Opening a file in GNU Emacs can trigger arbitrary code execution through version control (git), most requiring zero user interaction beyond the file open itself.

https://github.com/califio/publications/blob/main/MADBugs/vim-vs-emacs-vs-claude/Emacs.md

#infosec #cybersecurity #redteam #pentest #ai #emacs #claude

publications/MADBugs/vim-vs-emacs-vs-claude/Emacs.md at main ยท califio/publications

Publications from Calif. Contribute to califio/publications development by creating an account on GitHub.

GitHub