Adam Hassan
@adamkadaban.com
📤 145
📥 490
📝 153
Doing Windows Security @ Microsoft
https://hackback.zip
reposted by
Adam Hassan
Paul Frazee
13 days ago
C has a borrow checker it’s called mythos
12
349
36
I managed to get the
copy.fail
exploit down to 395 bytes See if you can beat me!
copy.golf
loading . . .
Copy Fail — 732 Bytes to Root
CVE-2026-31431. 100% Reliable Linux LPE — no race, no per-distro offsets, page-cache write that bypasses on-disk file-integrity tools and crosses containers. Found by Xint Code.
https://copy.fail
21 days ago
2
1
0
reposted by
Adam Hassan
24 days ago
Three ways to implement dependency cooldown for your Python packages: * pip --uploaded-prior-to
ichard26.github.io/blog/2026/04...
* uv exclude-newer
docs.astral.sh/uv/reference...
* Dependabot cooldown
github.blog/changelog/20...
loading . . .
What's new in pip 26.1 - lockfiles and dependency cooldowns!
pip 26.1 adds support for dependency cooldowns, experimental support for reading/installing from standard lockfiles (pylock.toml), fixes several long-standing limitations of the 2020 resolver, and dro...
https://ichard26.github.io/blog/2026/04/whats-new-in-pip-26.1/
0
6
2
Finding out this exists genuinely made my month
github.com/psmux/psmux
loading . . .
GitHub - psmux/psmux: Tmux on Windows Powershell - tmux for PowerShell, Windows Terminal, cmd.exe. Includes psmux, pmux, and tmux commands. This is native Powershell Tmux designed for Windows in Rust ...
Tmux on Windows Powershell - tmux for PowerShell, Windows Terminal, cmd.exe. Includes psmux, pmux, and tmux commands. This is native Powershell Tmux designed for Windows in Rust 🦀 - psmux/psmux
https://github.com/psmux/psmux
about 2 months ago
0
3
0
For some reason, coding agents seem to love running `pip install --break-system-packages` unless I explicitly tell them not to. TIL you can do this to globally prevent installing packages without a venv.
2 months ago
1
0
0
lol
2 months ago
0
1
0
It's incredible how many redaction mistakes made it through
neosmart.net/blog/recreat...
loading . . .
Recreating uncensored Epstein PDFs from raw encoded attachments
There have been a lot of complaints about both the competency and the logic behind the latest Epstein archive release by the DoJ: from censoring the names of co-conspirators to censoring pictures o…
https://neosmart.net/blog/recreating-epstein-pdfs-from-raw-encoded-attachments/
4 months ago
0
0
0
Is this the longest-lived GitHub action?
github.com/tdakhran/raz...
4 months ago
1
2
0
Been looking through the latest sliver release today. Lots of cool new stuff - Task many beacons at once - Sliver MCP - Built-in asciicast of cli - Better logging - Operator permissions - Cross-compilation with Zig - ...
github.com/BishopFox/sl...
loading . . .
Release v1.6.0 · BishopFox/sliver
What's Changed Verbose error when msfvenom fails in generate starger by @rkervella in #1239 Bump gorm.io/gorm from 1.25.0 to 1.25.1 by @dependabot[bot] in #1234 Check for nil session when using se...
https://github.com/BishopFox/sliver/releases/tag/v1.6.0
5 months ago
0
2
0
I finally took the time to move away from Spotify. s/o to these two projects for making it fast and easy
github.com/Pushan2005/S...
github.com/OuterTune/Ou...
loading . . .
GitHub - Pushan2005/SpotTransfer: Spotify to YT-Music Migration Tool
Spotify to YT-Music Migration Tool. Contribute to Pushan2005/SpotTransfer development by creating an account on GitHub.
https://github.com/Pushan2005/SpotTransfer
5 months ago
1
1
0
chatgpt knows me too well
6 months ago
1
0
0
Troopers Conference consistently has some of my favorite security talks every year. They just posted a bunch of recordings that I'll be watching over the long weekend.
www.youtube.com/@TROOPERScon
loading . . .
TROOPERS IT Security Conference
Welcome TROOPER, on our channel you will find talks and impressions around the ITsecurity conference TROOPERS in Heidelberg, hosted by ERNW. Enjoy the talks of the last years and exchange with the co...
https://www.youtube.com/@TROOPERScon
6 months ago
0
0
0
security.googleblog.com/2025/11/rust...
> We adopted Rust for its security and are seeing a 1000x reduction in memory safety vulnerability density compared to Android’s C and C++ code Wow
loading . . .
Rust in Android: move fast and fix things
Posted by Jeff Vander Stoep, Android Last year, we wrote about why a memory safety strategy that focuses on vulnerability prevention in ...
https://security.googleblog.com/2025/11/rust-in-android-move-fast-fix-things.html?m=1
6 months ago
0
2
1
reposted by
Adam Hassan
Taggart
8 months ago
Here's the reality: the authoritative sources of truth in the coming decade will not be state-run. They will be decentralized, redundant, peer-reviewed, and often contrary to the state's narrative. And it's crucial we keep that fire alive.
loading . . .
DOJ Deletes Study Showing Domestic Terrorists Are Most Often Right Wing
Following Charlie Kirk’s assassination and the Trump administration’s promise to go after the “radical left” a study showing most domestic terrosim is far-right was disappeared.
https://www.404media.co/doj-deletes-study-showing-domestic-terrorists-are-most-often-right-wing/
0
3
1
reposted by
Adam Hassan
SpecterOps
10 months ago
BloodHound v8.0 is here! 🎉 This update introduces BloodHound OpenGraph, revolutionizing Identity Attack Path Management by exposing attack paths throughout your entire tech stack, not just AD/Entra ID. Read more from Justin Kohler:
ghst.ly/bloodhoundv8
đź§µ: 1/7
loading . . .
1
13
10
so used to the bus that when I got off the train, I looked back and shouted "thank you!'
11 months ago
0
0
0
found the malware author
about 1 year ago
0
1
0
Working on an MCP for sliver. Can't wait to see how LLMs red team
about 1 year ago
0
1
0
made a ceramic strawberry matcha set right before the studio closed. time to get back to cyber
about 1 year ago
0
2
0
spent 8 hours at the pottery studio today
about 1 year ago
0
3
0
as far as I know, these are numbered sequentially. I love the idea of a senator waiting for the right number to submit a bill
add a skeleton here at some point
about 1 year ago
0
0
0
reposted by
Adam Hassan
Rich Cassara
about 1 year ago
The American public:
2
419
100
Claude stops itself from using potentially dangerous binary "for security reasons" and then immediately comes up with a workaround lol
about 1 year ago
1
0
0
In the process of trying to figure out how claude code implemented their user input features / repl, I found this little easter egg in the code
about 1 year ago
1
0
0
This competition had tons of vulnerabilities, backdoors, rootkits etc. for the blue team to detect and defend against. I put all the ansible and terraform for deploying on my GitHub
github.com/Adamkadaban/...
add a skeleton here at some point
about 1 year ago
0
0
0
red teaming against the blue team novices today
about 1 year ago
0
0
1
I asked claude code to help me fix some unit tests, and it ended up just deleting all the tests and replacing them with this đź’€
about 1 year ago
0
2
0
Found out recently that my apartment complex has this gorgeous 200 dollar scrabble board from Anthropologie. Game from today
over 1 year ago
1
2
0
"so I made a chrome plugin to patch Google maps and still show 'The Gulf of Mexico' as the world's smallest form of protest"
youtu.be/F5m2JxplnXk?...
loading . . .
Modding the Gulf of Mexico Back
YouTube video by Bryce Bostwick
https://youtu.be/F5m2JxplnXk?si=JuRdyVJ8qNwegX46
over 1 year ago
0
0
0
Woah since when did HTB have assumed breach machines 🤯
over 1 year ago
0
1
0
Go supply chain attack taking advantage of Google's Go mirror proxy.
socket.dev/blog/malicio...
loading . . .
Go Supply Chain Attack: Malicious Package Exploits Go Module...
Socket researchers uncovered a backdoored typosquat of BoltDB in the Go ecosystem, exploiting Go Module Proxy caching to persist undetected for years.
https://socket.dev/blog/malicious-package-exploits-go-module-proxy-caching-for-persistence
over 1 year ago
0
0
0
My recent annoyance with overleaf's docker-compose has led me to discover my new favorite persistence technique. Privileged container with a RestartPolicy of "always"
over 1 year ago
0
0
0
reposted by
Adam Hassan
Machine Learning
over 1 year ago
It traps AI crawlers and sends them down an "infinite maze" of static files with no exit links, where they "get stuck" and "thrash around" for months, he tells users. Once trapped, the crawlers can be fed gibberish data, aka Markov babble, which is designed to poison AI models.
#AI
#ML
#malware
loading . . .
AI haters build tarpits to trap and trick AI scrapers that ignore robots.txt
Attackers explain how an anti-spam defense became an AI weapon.
https://arstechnica.com/tech-policy/2025/01/ai-haters-build-tarpits-to-trap-and-trick-ai-scrapers-that-ignore-robots-txt/
1
9
11
reposted by
Adam Hassan
Synacktiv
over 1 year ago
In our latest article, @croco_byte proposes an implementation of a trick discovered by James Forshaw in his research regarding Kerberos relaying. Discover how to perform pre-authenticated Kerberos relay over HTTP with our Responder and krbrelayx pull requests!
www.synacktiv.com/publications...
loading . . .
Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx
https://www.synacktiv.com/publications/abusing-multicast-poisoning-for-pre-authenticated-kerberos-relay-over-http-with
0
16
13
reposted by
Adam Hassan
onion person
over 1 year ago
it says a lot about an industry if a free and open source alternative to every product on the market can destroy 1 trillion dollars of “value” in one day lol
120
14526
2200
reposted by
Adam Hassan
spencer
over 1 year ago
Phishing with a little salt…
loading . . .
Seasoning email threats with hidden text salting
Hidden text salting is a simple yet effective technique for bypassing email parsers, confusing spam filters, and evading detection engines that rely on keywords. Cisco Talos has observed an increase…
https://blog.talosintelligence.com/seasoning-email-threats-with-hidden-text-salting/
1
6
5
reposted by
Adam Hassan
over 1 year ago
In case if you wonder what broke
#ProcessHollowing
on Windows 11 24H2, I have something for you:
hshrzd.wordpress.com/2025/01/27/p...
loading . . .
Process Hollowing on Windows 11 24H2
Process Hollowing (a.k.a. RunPE) is probably the oldest, and the most popular process impersonation technique (it allows to run a malicious executable under the cover of a benign process). It is us…
https://hshrzd.wordpress.com/2025/01/27/process-hollowing-on-windows-11-24h2/
0
58
39
This is pretty cool. Nice way to automatically get IoCs from malware samples
github.com/RussianPanda...
loading . . .
GitHub - RussianPanda95/Configuration_extractors: Configuration Extractors for Malware
Configuration Extractors for Malware. Contribute to RussianPanda95/Configuration_extractors development by creating an account on GitHub.
https://github.com/RussianPanda95/Configuration_extractors/
over 1 year ago
0
0
0
reposted by
Adam Hassan
DASS
over 1 year ago
The Cybersecurity and Infrastructure Security Agency (CISA) safeguards our nation against cyber attacks, including those targeting our elections. Project 2025 contains a push to gut CISA - threatening the our elections and national cybersecurity. ⤵️
loading . . .
A Little-Known Federal Agency Helps Secure Elections. Trump Wants to Gut It.
Read more here.
https://buff.ly/3Cj85Mq
0
1
3
reposted by
Adam Hassan
Iain Thomson
over 1 year ago
Great feature from
@jessicalyons.bsky.social
on Trump's infosec policy, or lack of it. Dumping many talented security folks from unpaid advisory committees is bonkers.
loading . . .
Infosec was Trump's lowest priority, but he'll change bigly
Everyone agrees defense matters. How to do it is up for debate
https://www.theregister.com/2025/01/22/trump_cyber_policy/?td=rt-3a
1
24
7
ADCS honeypot. One more thing I'll have to add to my lab
github.com/srlabs/Certi...
loading . . .
GitHub - srlabs/Certiception: An ADCS honeypot to catch attackers in your internal network.
An ADCS honeypot to catch attackers in your internal network. - srlabs/Certiception
https://github.com/srlabs/Certiception
over 1 year ago
0
1
0
archive.org
for the white house constitution page. why do I feel like they just deleted everything that was changed in the last 4 years?
over 1 year ago
0
1
0
reposted by
Adam Hassan
Mrs. Betty Bowers
over 1 year ago
Carrie Underwood has gone from singing disapprovingly about an unfaithful man to singing approvingly *to* an unfaithful man.
795
30905
4756
in related news, swampctf 2024 has now been statically archived at
2024.swampctf.com
!
add a skeleton here at some point
over 1 year ago
1
0
0
left a subdomain with a dangling DNS record for one day and someone took it over đź’€
over 1 year ago
1
0
1
reposted by
Adam Hassan
Nicolas Krassas
over 1 year ago
AWS introduced same RCE vulnerability three times in four years
www.reddit.com/r/netsec/com...
loading . . .
AWS introduced same RCE vulnerability three times in four years
https://www.reddit.com/r/netsec/comments/1htcd4h/aws_introduced_same_rce_vulnerability_three_times/
0
8
6
Someone on LinkedIn posted something claiming that Crowdstrike only has 14% threat detection and SentinelOne has less than 1%. I was skeptical and replied. It seems comments have been disabled and my comment has since been deleted đź’€
over 1 year ago
1
0
0
Better opsec too 🙌 Time to start working on new detection rules
add a skeleton here at some point
over 1 year ago
0
0
0
Load more
feeds!
log in