An interesting experience in solving a pentesting task
Kubernetes API can reveal many secrets without authentication
We found out which local LLMs are better at finding vulnerabilities
Comparative analysis of multiple LLMs in their ability to uncover vulnerabilities
Fake RPC server can impersonate the security context of the calling client, up to SYSTEM
We found a vulnerabilty in a popular LLM agent
Following a special link, the AI agent itself will execute shell commands
Previously, pentesting tools did not work with 802.11r hashes
Overly autonomous LLM executes commands not requested by the user
If Exchange ActiveSync requires security policy agreement, PEAS still works
K8s clusters can be an interesting target during a pentest
How we improved our work with Hexway Pentest Suite
If Mythic agents communicate over HTTP(S), they are easy to detect
We selected posts that got the most likes