A beautiful crescent moon 😃 Good enough for my 130/900 Skywatcher + a phone video
Felipe Molina
@felmoltor.me
Mastodon felmoltor@defcon.social. Now with more #OSCP than the previous version. Working @SensePost.com - Orange Cyberdefense https://blog.felipemolina.com/
Venus emerging from behind the Moon after being occulted for an hour by the Moon on June 17, 2026. Clouds made it difficult to photograph but in the end, they added to the scene. #astrophotography #astronomy #venusmoon
My first attempt at capturing the Milky Way went not as bad as I thought (I still need to upskill with the foreground shot, but I'm getting there)
IPv6 addresses are too hard to memorize. That ends today, with the launch of my new, free service: sentence2IPv6 ❌ 0788:7b06:edcb:24f1:a2ff:08f0:6525:be66 ✅ The lazy chickens explode awkwardly beneath the mad toilet while ugly dogs eat the imaginary bacon. https://is.gd/gyxSQG
I can go sleep now with a more colourful photo of M42 obtained tonight 🌌
I'm still in the learning phase, but I feel pretty proud of my first M42 Nebula shot 🌌. Even taking it with a full moon and in the middle of the city, I got a decent photo. Next time will be much better 💪🏼
an easy way to remember the difference between ssh -L and ssh -R is to try both until it works
I updated that Burp Global Match & Replace plugin to use the Montoya API, be able to target specific Burp tools (or apply globally), extend the rule matching syntax, and give you a view per request and response of the changes. github.com/singe/burp_g...
Today I made my first portrait of the sun 🌞 You can even see the sunspots! The focal length of my telescope makes it impossible to take the picture of the whole sun, but I'll get to it soon.
Quick lunch time side quest building a simple lab to play with the inetutils-telnetd authentication bypass as disclosed on oss-sec ₁. github.com/leonjza/inet... ₁ seclists.org/oss-sec/2026...
Yesterday I was able to catch, with my phone, Jupiter transitioning through the lens. A lot of margin for improvement (e.g. motor for the RA axis), but happy with the progress I'm making 🔭
I'm getting more and more disappointed with the Internet nowadays, so I made one for myself yesterday.
A source shares some screenshots of the Lapsus ransomware gang celebrating the government shutdown as a disruption to the FBI investigations tracking them. They also refer to Trump as "my king."
Maybe it's my fault, but I'm really missing non-US related content in Bluesky. Can we talk about other countries, please? I don't want to go back to X 😢 🙏🏼
If you're at RomHack at the end of the month, come tell me your @github.com username and I'll give you early access to the @sensepost.com tool repo for PipeTap at the con! 🙃 Below is a demo of the proxy in action. www.youtube.com/watch?v=or8Y...
PipeTap WIP Demo
YouTube video by Leon Jacobs
youtube.com
I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :)
One of the pools in the Alhambra Palace complex in Granada.... had to be this one for #PalacesandGardens #Water #photography #dailyphoto #travel #Spain
Reverse engineering Microsoft’s SQLCMD.exe to implement Channel Binding support for MSSQL into Impacket’s mssqlclient.py. Storytime from Aurelien (@Defte_ on the bird site), including instructions for reproducing the test environment yourself. sensepost.com/blog/2025/a-...
From June 2025 through July 2025, the Cloudflare Email Security team has been tracking a cluster of cybercriminal threat activity leveraging Proofpoint and Intermedia link wrapping to mask phishing payloads. Read more: cfl.re/4lUXBEE
Attackers abusing Proofpoint & Intermedia link wrapping to deliver phishing payloads
Attackers are exploiting Proofpoint and Intermedia link wrapping to mask phishing payloads.
cfl.re
There's an ongoing npm supply chain attack taking place: socket.dev/blog/npm-phi... x.com/AikidoSecuri...
Active Supply Chain Attack: npm Phishing Campaign Leads to P...
Popular npm packages like eslint-config-prettier were compromised after a phishing attack stole a maintainer’s token, spreading malicious updates.
socket.dev
I've created a pull request to detect CitrixBleed 2 into Burp's Bcheck repository: github.com/PortSwigger/...
CVE-2025-5777 - CitrixBleed 2 by felmoltor · Pull Request #253 · PortSwigger/BChecks
BCheck Contributions BCheck compiles and executes as expected BCheck contains appropriate metadata (name, version, author, description and appropriate tags) Only .bcheck files have been added o...
github.com