Red Siege

@redsiege.com

Penetration Testing, Purple Team, Red Team & Adversary Emulation. Let our Offense, Prepare your Defense. https://redsiege.com #weareoffensive

You've heard him on the WedOff, and today we're excited to have Chris_ as our guest! We'll be chatting about AI in RE pipelines, and there's a decent chance the conversation drifts into some password cracking. Come hang out! See you at 130pm ET 🔗 redsiege.com/wedoff

Blue Teamers: Want to make attackers work harder? Join Red Siege CEO Tim Medin at Blue Team Con for Offense for Defense. Learn how attackers think, move, and operate so you can build stronger detections and better defenses. Reserve your seat 🔗👇

The lab series is back! Senior Security Consultant Justin Palk is expanding his original Windows AD lab series with new capabilities designed to make your lab more realistic and versatile. The first installment shows you how to deploy Elastic Defend EDR 🔗 redsiege.com/elastic-defend

Bild

A new edition of the SiegeStack is dropping soon. Your monthly collection of all things offensive, threat trends, insights, and Red Siege updates — delivered straight to your inbox. Subscribe now and stay ahead of the latest in cybersecurity 🔗 redsiege.com/signup

Thanks to Joe Brinkley for joining today's WedOff! We had a great discussion on AI-powered offensive security, vibe hacking, and building autonomous penetration testing tools. Thanks for sharing your experience and insights with the community! We'll see y'all next week. Same time. Same channel.

Bild

Wake up, it's Wednesday! You know that means it's time for the 2nd Best Show on the Internet: The Wednesday Offensive! Today we have Joe Brinkley, Director of Offsec Research - Cobalt, talkin about "How I embraced the vibe hack" See you at 130pm ET 🔗 redsiege.com/wedoff

What's the first thing you change after generating shellcode? Encrypt it? Encode it? Write your own loader? Learn the tradeoffs in Modern Shellcode Obfuscation with Principal Security Consultant Mike Saunders. Hide the Payload. Expand the Toolkit. 🔗 redsiege.com/modsho

Thanks to everyone who joined today's WedOff, and a special thanks to Don C. Weber for a great discussion on AI in ICS/OT cybersecurity, practical tool development, and why human expertise still matters. We'll see y'all next week! Same time. Same channel. redsiege.com/wedoff

Bild

It's time for The Wednesday Offensive! Today we have Don C. Weber discussing what he's accomplished using AI-assisted code development to take his projects to the next level, without integrating AI into the projects themselves. See you at 130pm ET 🔗 redsiege.com/wedoff

🚨 New Red Siege Training🚨 Raw payloads don't stay raw for long. Modern Shellcode Obfuscation with Principal Security Consultant Mike Saunders features 16 browser-based, hands-on labs covering practical shellcode obfuscation and detection tradeoffs. Zero setup, start today 🔗 redsiege.com/modsho

This week, the group collaborated on everything from Model Context Protocols (MCPs) to the future of AI in cybersecurity, and the conversation was just getting started. Join us next week as Don C. Weber continues the discussion! Same time. Same channel 🔗 redsiege.com/wedoff

Bild

A new macOS infostealer dubbed CrashStealer masquerades as Apple's Crash Reporter to steal browser credentials, password manager data, cryptocurrency wallets, and keychain contents before encrypting and exfiltrating the data. via CyberSecurity News cybersecuritynews.com/macos-steale...

New macOS Stealer Mimics Apple's Crash Report Framework to Steal Browser Credentials

CrashStealer, a native C++ macOS infostealer that disguises itself as Apple's built-in crash-reporting utility to harvest browser credentials, cryptocurrency wallets, password manager data, and keycha...

cybersecuritynews.com

A new phishing-as-a-service platform called Forg365 is targeting Microsoft 365 users with device code phishing, adversary-in-the-middle (AitM) attacks, AI-generated phishing lures, and session token theft via The Hacker News thehackernews.com/2026/07/forg...

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

Forg365 targets Microsoft 365 with device code and AitM phishing, then uses stolen tokens for persistent browser sessions and mailbox access.

thehackernews.com

Thank you BB King for coming on the WedOff today, and everyone who participated in the discussion! Great input all around about why guardrails, prompt engineering, and verifying AI-generated output are critical for security professionals. We'll see y'all next time 🔗 redsiege.com/wedoff

Bild

The lab series is back! Senior Security Consultant Justin Palk is expanding his original Windows AD lab series with new capabilities designed to make your lab more realistic and versatile. The first installment shows you how to deploy Elastic Defend EDR 🔗 redsiege.com/elastic-defend

Bild