XPN

@xpnsec.com

Hacker for hire at @specterops.bsky.social Blog: https://blog.xpnsec.com

Our first-ever keynote: Chris Wysopal @weld.bsky.social. Original L0pht vulnerability researcher, Veracode co-founder, and one of the first people to warn the world about insecure software. Boston hacker history, back on a Boston stage at MinuteCon. April 30 – May 1, 2027 minutecon.org

Bild

What happens when a new Mythic agent can be generated, tested, and deployed in ~2 hours? @xpnsec.com explores "disposable tooling" and the implications for offensive operations and defenders alike. Check out the latest from GhostWorks ⬇️ https://ghst.ly/4oMyrdC

Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment

Using Claude Opus to autonomously generate Mythic C2 agents from prompt to deployment—and what that means for defenders.

ghst.ly

Most prompt engineering still boils down to vibes. @xpnsec.com explores GEPA, a framework for optimizing prompts using eval results, execution traces, & iterative refinement. Read this practical look at bringing measurable engineering practices to AI agents. https://ghst.ly/4vGffAp

Prompt Engineering for Security Agents with GEPAPrompt Engineering for Security Agents: A Measurable Approach with GEPA

Stop hoping your prompt edits helped. GEPA uses Genetic-Pareto selection and scored evaluations to prove it. Real code, real results.

ghst.ly

New blog post is up looking at what GEPA is, and how it can be used for refining prompts for security agents. This post was published as part of the @specterops.io GhostWorks initiative. Can't wait to show what we've been working on! specterops.io/blog/2026/06...

Prompt Engineering for Security Agents with GEPAPrompt Engineering for Security Agents: A Measurable Approach with GEPA

Stop hoping your prompt edits helped. GEPA uses Genetic-Pareto selection and scored evaluations to prove it. Real code, real results.

specterops.io

In his latest research, @xpnsec.com tears apart VS Code Dev Tunnels and finds a C2 framework underneath — REST → WebSocket → SSH → MsgPack RPC, remote exec, file ops. Find the Ouroboros tool and protocol breakdown here: https://ghst.ly/4mZ4arb

The Accidental C2: Exploring Dev Tunnels for Remote Access

Peel back the layers of Microsoft Dev Tunnels and you'll find embedded protocols, RPC message exchanges, and a full command-and-control architecture hiding in plain sight.

specterops.io

If you came to SOCON, you may have seen the fireside chat on Ouroboros (if you weren't too busy counting my "urm"s 😝). The blog post is now live, detailing how we can use Dev-Tunnels for lateral movement, and allow pivoting from GitHub/Entra ID access. specterops.io/blog/2026/05...

The Accidental C2: Exploring Dev Tunnels for Remote Access

Peel back the layers of Microsoft Dev Tunnels and you'll find embedded protocols, RPC message exchanges, and a full command-and-control architecture hiding in plain sight.

specterops.io

Next week at WWHF Mile High I'll present a major update to roadrecon, with some awesome features I wanted to add for a while! Friday 9am in track 1 for those attending 😀

Bild

What do you MEAN the president audibly SHIT himself live on camera and they immediately cancelled the press conference and rushed everyone out of the room like it's a fire drill, and it happened two days ago, and I'm just hearing about it NOW?

AI tooling and MCP servers are entering enterprises fast, often faster than security teams can assess the risks. During a recent engagement, @xpnsec.com found a new Claude Code vuln (CVE-2025-64755) while exploring MCP abuse paths. 👀 Read the details: ghst.ly/49ybl4W

An Evening with Claude (Code) - SpecterOps

This blog post explores a bug, (CVE-2025-64755), I found while trying to find a command execution primitive within Claude Code to demonstrate the risks of web-hosted MCP to a client.

ghst.ly

New blog post is up! Stepping out of my comfort zone (be kind), looking at Meta's Prompt Guard 2 model, how to misclassify prompts using the Unigram tokenizer and hopefully demonstrate why we should invest time looking beyond the API at how LLMs function. specterops.io/blog/2025/06...

Tokenization Confusion - SpecterOps

Meta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs.

specterops.io