@domchell.bsky.social

If a host is compromised, what risk does that data represent? Nemesis 2.2 helps answer that. ✅ Large container processing ✅ Host-based reporting ✅ AI-assisted triage ✅ Full Chromium DPAPI handling Read @harmj0y.bsky.social + @tifkin.bsky.social's latest blog post: https://ghst.ly/4l2DDbl

Nemesis 2.2 - SpecterOps

Nemesis 2.2 introduces large disk image processing, LLM agents for automated finding triage and credential analysis, full Chromium DPAPI decryption support, host reporting, and significant performance...

ghst.ly

Binary injection vulnerabilities can be found in many MacOS apps. Those may be abused to bypass EDR, hide backdoor, access memory, or bypass TCC! DarwinOps provides - An advanced injection vulnerability scanner - A redteam scenario to exploit them #redteam blog.balliskit.com/macos-dylib-...

macOS DYLIB Injection at Scale: Designing a Self-Sufficient Loader

Let’s explore Dylib injection and Dylib proxying on macOS (the equivalent of Windows DLL injection)

blog.balliskit.com

Our red team is growing and we have a rare open position for a Principal RT Operator - if this sounds like you, get in touch 🙏

Bild

[Blog] This ended up being a great applied research project with my co-worker Dylan Tran on weaponizing a technique for fileless DCOM lateral movement based on the original work of James Forshaw. Defensive recommendations provided. - Blog: ibm.com/think/news/f... - PoC: github.com/xforcered/Fo...

Fileless lateral movement with trapped COM objects | IBM

New research from IBM X-Force Red has led to the development of a proof-of-concept fileless lateral movement technique by abusing trapped Component Object Model (COM) objects. Get the details.

ibm.com

The Blind Eagle APT group has compromised over 1,600 victims inside Colombian institutions and government agencies. The campaign took place in November & December of last year and used an exploit similar to a zero-day exploited by Russian hackers in Ukraine. research.checkpoint.com/2025/blind-e...

Blind Eagle: …And Justice for All - Check Point Research

Key Points Introduction APT-C-36, also known as Blind Eagle, is a threat group that engages in both espionage and cybercrime. It primarily targets organizations in Colombia and other Latin American co...

research.checkpoint.com

It appears Microsoft quietly mitigated most of the risk of the "Intune company portal" device compliance CA bypass by restricting the scope of Azure AD graph tokens issued to this app, making them almost useless for most abuse scenarios. Thx @domchell.bsky.social for the heads up.

Bild