8.3K Followers
1.8K Following
1.4K Posts

Founder & CEO of runZero (@runZeroInc - https://runzero.com), previously the founder and lead developer of Metasploit, a CSO, a consultant, and the head of various security research teams.

My work is focused on #infosec, #security, #networking, #discovery, #osint, #postgresql, #aws, #engineering, #opensource, #devops, and #startup stuff. For fun I write #golang, build #IoT projects, and #run in circles.

Homehttps://hdm.io
Githubhttps://github.com/hdm
Workhttps://www.runzero.com/
Twitterhttps://twitter.com/hdmoore
Blueskyhttps://bsky.app/profile/hdm.bsky.social
Signalhdm.01
My favorite bugs are where the vendor doesn't consider it a vulnerability: How a USB-connected speaker can infect a PC without ever being touched: https://arstechnica.com/security/2026/06/highly-reviewed-speaker-can-be-hacked-over-the-air-to-infect-connected-devices/

ATX Go is TONIGHT (a week early this month):

Hey gophers! Join us Wednesday (May 6th, today), 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: πŸ• pizza, 🍻 beer, and a few short talks on Go. Bring a talk, a friend, or an idea!

https://www.meetup.com/atxgolang/events/312781570/

ATX Golang Meetup - May 2026 (RESCHEDULED), Wed, May 6, 2026, 6:30 PM | Meetup

Join us for an evening of information, networking, friendship, beer, and pizza! You are invited to come discuss our favorite programming language and meet other Go develope

Meetup

ATX Go is a week early this month, tomorrow night!

Hey gophers! Join us Wednesday, 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: πŸ• pizza, 🍻 beer, a few short talks on Go, and general discussion. Whether you write Go all day or just dabble on the weekends, come hang out and meet other folks in the Austin Go community.

https://www.meetup.com/atxgolang/events/312781570/

ATX Golang Meetup - May 2026 (RESCHEDULED), Wed, May 6, 2026, 6:30 PM | Meetup

Join us for an evening of information, networking, friendship, beer, and pizza! You are invited to come discuss our favorite programming language and meet other Go develope

Meetup
@joshbressers it feels like we're back to the 90s - anyone can break into anything and there's very little public information on actively exploited capabilities (and since you find new ones as you go...) - i don't see CVE even with CNAs, keeping up

RE: https://infosec.exchange/@runZeroInc/116493908814143481

Excited to share what we've been cooking for the last few months:

Interactive attack graphs, with hop-by-hop planning, support for over 220 protocols, and no-auth backplane enumeration to identify non-IP systems unauth over the network!

Our free trial includes a fun Demo Organization you can explore and converts into our free Community Edition at the end (with all of the same capabilities, just a lower asset limit)!

🚨 New runZero 4.9: Shatter the segmentation illusion and reveal hidden attack paths across IT and #OT environments!

Experience the power of our latest release:

πŸ“ˆ Interactive attack path mapping
πŸ‘οΈ Multi-homed & bridge detection
πŸ—ΊοΈ 2D/3D searchable topology
🧠 Deep OT intelligence, including field-level discovery
πŸ”₯ Real-world risk prioritization
βœ… Identify protocol exposures
πŸ’» UI/UX enhancements

πŸ‘‰ Learn more at: https://www.runzero.com/blog/runzero-4-9

#OTsecurity

There is a bunch of buzz along the lines of "Apple FINALLY backports DarkSword related fixes to 18.x and will release this on April 1".

Based on publicly available information this is incorrect.

What Apple has actually done broadened the device models that are eligible to upgrade to iOS/iPadOS 18.

Per Google [1] every vuln in the DarkSword kit except for CVE-2026-20700 had already been patched in iOS 18 as of 18.7.3 which was released on Dec 12, 2025.

Per Apple [2], CVE-2026-20700 is not included in 18.7.7 which was released today.

Apple has placed an easy to miss note at the top of the release notes:

"We enabled the availability of iOS 18.7.7 for more devices on April 1, 2026, so users with Automatic Updates turned on can automatically receive important security protections from web attacks called Darksword. The fixes associated with the Darksword exploit first shipped in 2025."

Unfortunately I don't see an indication of which devices are newly eligible to upgrade to iOS/iPadOS 18.

References:

  • Google DarkSword writeup - https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain

  • Apple iOS/iPadOS 18.7.7 release notes:
    https://support.apple.com/en-us/126793

  • #Security #Apple #DarkSword

    The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors | Google Cloud Blog

    DarkSword is a new iOS exploit chain that leverages multiple zero-day vulnerabilities to fully compromise iOS devices.

    Google Cloud Blog
    @joshbressers will be interesting - maybe folks will stop reporting vulns entirely and everyone will assume that if one LLM can find it, it's already public
    Tom Ptacek posted a great writeup titled "Vulnerability Research Is Cooked", covering the state of vulndev and its rapidly accelerating future:
    https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/
    Vulnerability Research Is Cooked β€” Quarrelsome