Bad Sector Labs

@badsectorlabs.com

Cybersecurity news, techniques, exploits, and tools every week at http://blog.badsectorlabs.com 🐘@badsectorlabs@infosec.exchange

Ludus Feature Friday! The new 2.2.0 release brings "sources" which allow you to easily add blueprints, templates, and roles to your Ludus host. We even converted GOAD to a fully Ludus-native blueprint! Check out the full change log and video here: ludus.cloud/changelog/2....

Ludus 2.2.0: Sources — Ludus

Add blueprints, templates, and roles/collections from trusted sources to your Ludus host — shipping with native GOAD, a no-Defender Windows 11 template, and every Bad Sector Labs template and role pre...

ludus.cloud

Relax and unwind in the Tradecraft Garden aff-wg.org/2026/06/01/r... Celebrating one year of Tradecraft Garden. 40 blog posts. ~30 POCs/projects. A lot of thank you's inside. The release itself: stack unwinding data generation, reference relaxation in the linker, and COFF mixing (+disco baby!)

Relax and unwind in the Tradecraft Garden

We’re at the 12th release of Crystal Palace and marking one year in the Tradecraft Garden. This release adds reference relaxation to make global references PIC-friendly. I’ve also added stack unwin…

aff-wg.org

🏟️ Ludus launched 2 years ago and the community embraced and extended it with write-ups, roles, configs, and environments. We're excited to see what you build with Ludus 2! (1/4)

We try hard to do this with Ludus. We've gotten huge value from the Ludus Discord and watching what people struggle with or have to fight to get to work and that makes us try to solve that issue in Ludus itself. It's a balance of not adding every little feature though, so there is art to it.

Raphael Mudge@raphaelmudge.bsky.social · 5mo ago

The above doesn't just apply to C2s or offensive security. Platform owners of any ilk, who see a problem that their community and partners are collectively trying to solve, would do well to look for that expended energy, see the barriers, and ask what they can do to make that energy more effective

We published 44 editions of Last Week in Security in 2025, the best free technical cybersecurity newsletter. We sifted through the noise (without AI!) to deliver: 📰 179 News Stories 🧠 407 Techniques & Write-ups 🛠️ 438 Tools & Exploits 👀 51 New X Accounts & 37 New Blogs followed

DEF CON releases, PDQ SmartDeploy creds (@unsigned_sh0rt), FortiSIEM root command injection (@SinSinology), a cat themed loader (@vxunderground), fine-tune LLMs for offsec (@kyleavery_), juicing NTDS.DIT (@MGrafnetter), and more! blog.badsectorlabs.com/last-week-in...

Last Week in Security (LWiS) - 2025-08-18

DEF CON releases, PDQ SmartDeploy creds (@unsigned_sh0rt), FortiSIEM root command injection (@SinSinology), a cat themed loader (@vxunderground), fine-tune LLMs for offsec (@kyleavery_), juicing NTDS....

blog.badsectorlabs.com

Come see a preview of the new Web UI for 🏟️Ludus at the Embedded Systems Village. Our mini-workshop walks you through deploying a range and then hacking an emulated IP camera.

Bild