Thanks to @unix-ninja.bsky.social for joining us on the WedOff! We had a great discussion on using AI to accelerate reverse engineering, where it shines, where it falls short, and why understanding its limitations matters just as much as its capabilities. See you next week! redsiege.com/wedoff
Red Siege
@redsiege.com
Penetration Testing, Purple Team, Red Team & Adversary Emulation. Let our Offense, Prepare your Defense. https://redsiege.com #weareoffensive
You've heard him on the WedOff, and today we're excited to have Chris_ as our guest! We'll be chatting about AI in RE pipelines, and there's a decent chance the conversation drifts into some password cracking. Come hang out! See you at 130pm ET 🔗 redsiege.com/wedoff
Blue Teamers: Want to make attackers work harder? Join Red Siege CEO Tim Medin at Blue Team Con for Offense for Defense. Learn how attackers think, move, and operate so you can build stronger detections and better defenses. Reserve your seat 🔗👇
Think Content Security Policies are just another security header? Listen in as Red Siege Security Consultants Douglas and Stuart discuss Cross-Site Scripting (XSS), and hear Douglas explain why CSPs are far more powerful than most people realize. #hacking #infosec #cybersecurity
The lab series is back! Senior Security Consultant Justin Palk is expanding his original Windows AD lab series with new capabilities designed to make your lab more realistic and versatile. The first installment shows you how to deploy Elastic Defend EDR 🔗 redsiege.com/elastic-defend
A new edition of the SiegeStack is dropping soon. Your monthly collection of all things offensive, threat trends, insights, and Red Siege updates — delivered straight to your inbox. Subscribe now and stay ahead of the latest in cybersecurity 🔗 redsiege.com/signup ️
Thanks to Joe Brinkley for joining today's WedOff! We had a great discussion on AI-powered offensive security, vibe hacking, and building autonomous penetration testing tools. Thanks for sharing your experience and insights with the community! We'll see y'all next week. Same time. Same channel.
We're here in Bozeman for Interface Montana! Stop by our booth, grab some swag, and don't miss our CEO Tim Medin presenting his keynote "Modern Breaches: Lessons for Security Leaders" at 3pm MT #hacking #infosec #cybersecurity #interface
Wake up, it's Wednesday! You know that means it's time for the 2nd Best Show on the Internet: The Wednesday Offensive! Today we have Joe Brinkley, Director of Offsec Research - Cobalt, talkin about "How I embraced the vibe hack" See you at 130pm ET 🔗 redsiege.com/wedoff
🔔 Friendly Neighborhood Reminder 🔔 Tomorrow on The Wednesday Offensive we'll have Joe Brinkley, Director of Offsec Research - Cobalt, leading the discussion on "How I embraced the vibe hack" Join the conversation at 130pm ET 🔗 redsiege.com/wedoff #hacking #infosec #cybersecurity
What's the first thing you change after generating shellcode? Encrypt it? Encode it? Write your own loader? Learn the tradeoffs in Modern Shellcode Obfuscation with Principal Security Consultant Mike Saunders. Hide the Payload. Expand the Toolkit. 🔗 redsiege.com/modsho
SourTrade now builds malware inside victims' browsers, evading detection by downloading only clean components before assembling an infostealer. via Infosecurity Magazine www.infosecurity-magazine.com/news/malvert...
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
mpersonating well-known cryptocurrency and trading sites, SourTrade has developed a novel technique to drop infostealers to victims
infosecurity-magazine.com
Coca-Cola confirmed data was stolen in a ransomware attack on Fairlife. Production has largely resumed, but the stolen data has now been leaked. via @bleepingcomputer.com www.bleepingcomputer.com/news/securit...
Coca-Cola confirms data theft in Fairlife ransomware attack
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month.
bleepingcomputer.com
Looking to sharpen your offensive security skills? Our YouTube channel is packed with hours of practical cybersecurity content, technical deep dives, and expert insights. 🔗 redsiege.com/ytsubscribe #hacking #infosec #cybersecurity
Thanks to everyone who joined today's WedOff, and a special thanks to Don C. Weber for a great discussion on AI in ICS/OT cybersecurity, practical tool development, and why human expertise still matters. We'll see y'all next week! Same time. Same channel. redsiege.com/wedoff
It's time for The Wednesday Offensive! Today we have Don C. Weber discussing what he's accomplished using AI-assisted code development to take his projects to the next level, without integrating AI into the projects themselves. See you at 130pm ET 🔗 redsiege.com/wedoff
🚨 New Red Siege Training🚨 Raw payloads don't stay raw for long. Modern Shellcode Obfuscation with Principal Security Consultant Mike Saunders features 16 browser-based, hands-on labs covering practical shellcode obfuscation and detection tradeoffs. Zero setup, start today 🔗 redsiege.com/modsho
Hugging Face disclosed that attackers used an autonomous AI agent framework to exploit vulnerabilities in its production infrastructure, stealing internal credentials and datasets before moving laterally across its network. via @bleepingcomputer.com www.bleepingcomputer.com/news/securit...
Hugging Face warns an autonomous AI agent hacked its network
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI age...
bleepingcomputer.com
This week, the group collaborated on everything from Model Context Protocols (MCPs) to the future of AI in cybersecurity, and the conversation was just getting started. Join us next week as Don C. Weber continues the discussion! Same time. Same channel 🔗 redsiege.com/wedoff
Wake up, it's Wednesday! You know that means it's time for the 2nd Best Show on the Internet: The Wednesday Offensive See you at 130pm ET 🔗 redsiege.com/wedoff #hacking #infosec #cybersecurity
A new macOS infostealer dubbed CrashStealer masquerades as Apple's Crash Reporter to steal browser credentials, password manager data, cryptocurrency wallets, and keychain contents before encrypting and exfiltrating the data. via CyberSecurity News cybersecuritynews.com/macos-steale...
New macOS Stealer Mimics Apple's Crash Report Framework to Steal Browser Credentials
CrashStealer, a native C++ macOS infostealer that disguises itself as Apple's built-in crash-reporting utility to harvest browser credentials, cryptocurrency wallets, password manager data, and keycha...
cybersecuritynews.com
A new phishing-as-a-service platform called Forg365 is targeting Microsoft 365 users with device code phishing, adversary-in-the-middle (AitM) attacks, AI-generated phishing lures, and session token theft via The Hacker News thehackernews.com/2026/07/forg...
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
Forg365 targets Microsoft 365 with device code and AitM phishing, then uses stolen tokens for persistent browser sessions and mailbox access.
thehackernews.com
Thank you BB King for coming on the WedOff today, and everyone who participated in the discussion! Great input all around about why guardrails, prompt engineering, and verifying AI-generated output are critical for security professionals. We'll see y'all next time 🔗 redsiege.com/wedoff
It's Wednesday! You know that means it's time for The Wednesday Offensive! Today we have Brian King, Security Consultant - Black Hills Information Security, work shopping a new talk "Use the AI, Keep Your Humanity" See you at 130pm ET 🔗 redsiege.com/wedoff #hacking #infosec #cybersecurity
The lab series is back! Senior Security Consultant Justin Palk is expanding his original Windows AD lab series with new capabilities designed to make your lab more realistic and versatile. The first installment shows you how to deploy Elastic Defend EDR 🔗 redsiege.com/elastic-defend