Errant Packet @ErrantPacket
Danny Tanner x Neo with splash of captain morgan | General tech geek and tinkerer with red team flavor | ***personal account, tweets my own etc blah blah blah errantpacket.com Washington, DC Joined February 2020-
Tweets522
-
Followers149
-
Following498
-
Likes3K
Update: the AUR compromise appears to be ongoing After the initial incident affecting 1,500+ packages, another wave of malicious AUR packages has been discovered. This time the attackers reportedly used code obfuscation to better conceal the malicious behavior. Affected packages included Node.js packages, Firefox-related packages, LibreWolf extensions, NeoVim plugins and others. If you’re using #Arch Linux and install software from AUR, I’d review recently updated packages and keep an eye on this story. phoronix.com/news/Arch-Linu…
People using Arch Linux should probably pay attention to this More than 1,500 AUR packages were reportedly modified in a supply-chain compromise The malicious changes are said to have included: - credential theft - SSH key collection - browser data theft - persistence via
"All I'm saying is It's a new era now, and things are about to get really weird. So you should keep your code close to your vest. And pick your friends wisely." - Harold Finch
I've had this side project on the backburner for a long time... The XGecu line of universal programmers are awesome, but they come with some of the sketchiest proprietary Windows software ever. (XGPro) MiniPro is an software program made to interact with the XGecu hardware. An open source XGPro alternative.
At @BsidesHbg yesterday I did a talk about how I built a modular asset discovery framework by using open source tooling to help automate my work when handling large engagements. That tool is called cygor: github.com/tjnull/cygor
Oblique Relay- Cloudflare Workers edge redirector for red team ops. Validates implant traffic against your C2 profile. KV-backed profile import, Durable Object session tracking. No more hand-translating C2 URIs into rewrite rules. errantpacket.com/blog/oblique-r…
It appears that Microsoft removed the discovery of all domains in a tenant through ACS, a technique that I shared at my BH/DC talks last summer (though probably not many people spotted the reference). I found it out during a live demo of course 🙃
New way to use skills to get RCE: Just include tests. npx skills add will include test files. Most js/ts test runners (Vitest/Jest) execute **/*.test.* anywhere in the repo by default, including inside .agents/skills. When the dev runs tests locally, your code executes.
I swear the best advice i got was to learn your own path. If you follow too closely to tutorials you'll be stuck hunting the same bugs as everyone else Learn the fundamentals then just start hunting until you are comfortable in your environment Once your comfortable only THEN do you start referencing other people's more specific methodologies
During your pentest mission, please don’t make the same mistake I did. Add printer IPs to your exclusion list when running Nuclei. Otherwise, the printer will interpret every packet sent to port 9100 as a print job.
Found this TINY flash chip on the DistrictCon conference badge and just had to remove it and dump the firmware 🤣 First time using my USON8 2x3 adapter
@DistrictCon was a blast, stay warm and safe travels home! Until next time friends, be kind and hack on.
Hello, The year is coming to a conclusion. Thank you everyone for another wonderful year. Once the next round of giveaways finish I'll probably be AFK-ish. I am extremely fatigued from work and life. I'm not sure if it's possible, but I would like to be able to nap somewhere between 240 to 480 hours. Thank you everyone for the fun times and sticking with me while I deal with a vx-underground and a newborn baby. I wholeheartedly appreciate all the kind words and support all of you have shown me. Many of you are great, caring, and compassionate people. I have some good news and some neutral news. The good news is that I have completed (within reason) collecting every easily discoverable malware analysis paper on the internet. Yes, of course one or two may be missing here or there, but I feel like 14,000 papers over the time span of 2 decades is pretty good. The neutral news is that moving forward vx-underground will primarily be keeping up to date on things. This isn't necessarily good or bad, but this means updates to vx-underground will be significantly smaller and fewer. Truthfully, I'm not sure what to do anymore. I started the website with the goal of collecting malware source code, samples, and papers. I've collected 34TB (if decompressed) over 6.5 years. I feel like it would be a betrayal to my audience to continually make silly posts all day, everyday. I sort of worked myself out of a job, I don't know.
Yesterday I shared my proof-of-concept on disabling Bitlocker using undocumented COM objects. @thebookisclosed decided to implement my code in C#.NET C: pastebin.com/raw/knQNbG4U C#: pastebin.com/raw/JhtcWPSM Behold the pain of C/C++ WINAPI vs. C#.NET.
Calling all students! We’re giving away free tickets to our upcoming conference. To apply, email [email protected] us with: Why you’re interested in infosec & Something that shows your effort (project, blog, etc.) We’ll pick winners based on passion & initiative. Don’t miss out!
Remove the v word, and keep the second part of that sentence, what changes? I don’t get the hysteria, it’s the exact same principles and methodology that you apply. You think code blindly pasted from stackoverflow or random forums was adequate?
if you vibe-code, how do you know if your app is secure?
I tried using Claude Code to write platform-specific SIMD implementations for several functions I never got around to optimizing. I gave it full control to modify the code, run tests, benchmark, and make any tweaks it deem necessary. And here's the most amazing part: it actually DID IT P.S. even though nothing works, all the tests are failing, and, hilariously enough, there's not a single SIMD intrinsic used lol.🫡 Claude
CVE-2025-49596: Critical RCE in Anthropic MCP Inspector I stumbled across a nasty 0day in Anthropic’s official MCP Inspector. Turns out: any public website could have exploited it to run arbitrary bash commands.
bernini @bernini_tar_gz
1 Followers 46 Following
turb0 @7urb01
1K Followers 201 Following CTBB Full-Time Hunters' Guild Member | Recovering AppSec Engineer | /((de)?bu(g+)?(ing)?)?/i Bits, bytes, and bad ideas https://t.co/0iE5bU44up
Peter Logan @authpeterlogan
478 Followers 5K Following 🐬 Flipper Zero tips & education 📖 Hack Like A Pro With Flipper Zero ✍️ Author Peter Logan 🔗 Book link below
Oskar @OskarRommel88
12 Followers 262 Following
Adrian North @A_SignalCheck
8 Followers 174 Following Signal Check is a podcast by Adrian North that focuses on technology, security , and running or other outdoor stuff. Just news and hobbies that Adrian enjoys!
Matt Brown @nmatt0
10K Followers 1K Following Principal Consultant @ Brown Fine Security | IoT Security Researcher | Soli Deo Gloria
G1zm0 @G1zm0_infosec
17 Followers 52 Following
John Capobianco @John_Capobianco
22K Followers 8K Following Head of AI and DevRel | Itential | Distinguished Speaker | Award Winning Author | Educator | Google Developer Expert | NetClaw | https://t.co/CZb5OMC61J
Marianne @YI08UjkSax0r4
36 Followers 967 Following I’m not just a girl, I’m a force to be reckoned with.
Haptekz @Hapt3kz
78 Followers 299 FollowingJ'onn J'onzz @leinn32
397 Followers 1K Following Security engineer, Historian, Researcher at huskysec, I like mobile applications
meKhatai @vurtan
1 Followers 4 Following
her0x0ftime @her0x0ftime
92 Followers 287 Following Adversary Simulator. Defense Stimulator. Vulnerable by Design.
ȆĸNjªwȌ°Ⱡ)ţ @v1rVXBquIq
2 Followers 82 Following
uh @schizoldak
0 Followers 5 Following
J0hn_W1ck @findeldia
49 Followers 145 Following
McBartok @McBartok
23 Followers 529 Following
patrick armstrong @patarmstrong
128 Followers 434 Following Photographer /\ Digital Imaging Technician / \ Cyber Security
Pawnhaw @Pawnhaw0908
2 Followers 168 Following
EZ @IAMERICAbooted
3K Followers 2K Following Retired from Contoso & Fabrikam. Gone phishing with a team that wears purple. Posts don't represent my employer(s).
Paul @pling3r
624 Followers 3K Following Sr Cybersecurity Architect -- Cloud & AI / Bug Bounty Hunter / Hacker / Gamer / Husband / Father
Anurag Mishra🇮🇳 @mishr_a_nurag
502 Followers 1K Following Offensive Security | Product Security |Speaker | Cloud Security | I identify myself as a joke, my pronouns are ~ he/he
Syntax =@.@= syntax97... @syntax976
832 Followers 1K Following motorbike racer, hacker, mechanic,DJ, and I rock a mean suit! DCZIA!
@MrJeffMan (he/him) #... @MrJeffMan
7K Followers 1K Following Sr. InfoSec Curmudgeon. Grandpa, pastor, teacher, skeptic, builder, kryptos, NSA, speaker, PCI, @TribeofHackers*4 @darknetdiaries ep83 @hak4kidz @secweekly
Noashatosm @NoashatosmEqk5
110 Followers 5K Following
Chris Rose @digital_psyko
244 Followers 1K Following father, hacker, advocate for the advancement of education for all beings. Views expressed are my own.
Tyler Robinson @tyler_robinson
3K Followers 2K Following @nvidia - Offensive Threat Intel and Red. Podcast Co-Host on @SecurityWeekly, Owner/Founder Dark Element, Boutique Offensive Services #RedTeam
4NU81X👁⃤ @4NU81X
20 Followers 46 Following 3V3rY7H1N6 C4N 83 51MP11F13D 3NC0D3D 4ND UND3r5700D 45 1NF0rM4710N
MikeHacksThings @MikeHacksThings
1K Followers 1K Following Founder of Maltek Solutions | President of @RedTeamVillage_ | NCAE CyberGames CTF Lead | General Hacker of Things
nyxgeek @nyxgeek
8K Followers 4K Following rebel scum, nerfherder, dogged and relentless. Spoke at DEF CON, ShmooCon. Midnight Computer Lab H/P/V/A/C Directory - https://t.co/kjwuy6Pqx5
drew @hoodoer @hoodoer
2K Followers 1K Following Principal Consultant at Blackthorne Consulting. Beach bum. Super awesome dad. Coder of weird things.
RedSeerSecurity @RedSeerSecurity
423 Followers 485 Following Red Seer Security is a boutique cyber security and intelligence firm that specializes in Network Security
Cipher-Pierre @C1ph3r_Pierre
17 Followers 588 Following Cyber Security Researcher | Factorio Enthusiast
//CaptKurt @xL0xKEY
129 Followers 231 Following Penetration Tester | Breaking all the things for fun & fix things for a living | eCPPTv2 https://t.co/qZQShH7OuP
K @socalku
0 Followers 119 Following
ᅠᅠᅠᅠ ᅠᅠ �... @d0ublebind
1K Followers 1K Following Personal Account, Hacking systems and egos since Y2K. f@h: https://t.co/XwpOLPiPSn
Adrien @adrlsx
33 Followers 729 Following
Marcus Johansson @marcus_johansso
20 Followers 146 Following A hacker with an interest in fantasy and SecDevOps, however confusing that may be
pwn.ai @pwn_ai
12K Followers 0 Following Built to breach. The best defense is insane offense. Agentic hacking ecosystem in the works. Our pentest product is now live.
Mistral AI @MistralAI
209K Followers 2 Following Frontier AI in your hands. Get work done with @MistralVibe at https://t.co/JsGnCVMUFq.
Ushi @ush1c
16K Followers 7K Following I’d rather be in the woods or water |Mumblings of a perpetual n00b #Hacker @binaryhansolo == ❤️| mama of THE amazing #actuallyautistic Bubbs|@hackerhaussec
Hunt.io @Huntio
7K Followers 964 Following https://t.co/9I6nRUiFjm is a service that provides threat intelligence data about observed network scanning and cyber attacks.
freemyipod @freemyipod
813 Followers 12 Following Our goal is to gain execution and write drivers for the iPod nano and iPod classic products.
Dmitriy A. @jimaek
2K Followers 430 Following Founder of @jsDelivr. Building fast internet infrastructure. Focusing on network monitoring https://t.co/RQZHi7WY9H
@uartnet @uartnet
130 Followers 437 Following Building https://t.co/5cn6ugw03A - State of the art networking for developers and AI agents. Sharing insights on coding, hacking, and building things.
Matthew Hartensveld, ... @MattHartensveld
5K Followers 97 Following Posts related to homebrew semiconductor device fabrication and semiconductor news.
MangoNoFlake @mangonoflake
12K Followers 573 Following MangoNoFlake | 芒果不鸽 Mini embedded projects + Edge AI experiments Creator of MangoPi No flake. Regular content.
Bad Sector Labs @badsectorlabs
9K Followers 529 Following Cybersecurity news, techniques, exploits, and tools every week at https://t.co/UgKmeEEjIV 🐘 @[email protected]
MrBill // wardrive ev... @SecureThisNow
6K Followers 5K Following Dislike cyber__ terms | @HardHatBrigade | Perpetual Newb | Meyers-Briggs: IDGAF | !Serious Account | ex-Payphone Purveyor | on infosec exchange | views my own
jay @JayChopra_
1K Followers 545 Following 21 | Experimenting @stanleybystan | Prev Founder @Polarityco | Alum @uwaterloo
Jeff Lindsay @progrium
9K Followers 1K Following Influential indie dev. Early @twilio, prototyped @docker, created @dokku, started @shdh + @hackerdojo, original admin @tigsource, "invented webhooks", etc
trace37 @trace37_labs
1K Followers 402 Following Hacker - Security Researcher - Bug Bounty Hunter - Security Tooling Developer Bug Bounty has been solved.
Nick Spisak @NickSpisak_
16K Followers 723 Following - I help owner/operators use AI as leverage in their business - Former Principle Software Engineer & Architect
Aaronia AG @Aaronia_AG
18K Followers 16K Following Manufacturer of RF monitoring, direction finding, real-time spectrum analyzer, SDR, CUAS, IQ vector signal generator, network-analyzer, antennas, software & OEM
Matt Brown @nmatt0
10K Followers 1K Following Principal Consultant @ Brown Fine Security | IoT Security Researcher | Soli Deo Gloria
Dmitrii Kovanikov @ChShersh
74K Followers 245 Following Dysfunctional Programming account #1. Senior SWE. I still write C++ for money. ex-Haskell, ex-OCaml. All opinions are my own.
Project Owl @projectowlosint
38K Followers 419 Following Project Owl: The OSINT community hub. Foreign policy, geopolitical events, military, and government focused. RT/Like/Follow ≠ Endorsement.
Black Cat Systems @BlackCatSystems
1K Followers 34 Following
Steev 💙💛 @steevdave
1K Followers 382 Following BRANDJACKING CURATOR, WIDGET WONK, GAMING FIEND. MADE ENTIRELY OF BACON. I did Kali ARM things.
yung algo @yungalgorithm
7K Followers 4K Following rotating multimedia objects onchain (all tweets AI generated)
Peter Girnus 🦅 @gothburz
193K Followers 648 Following Reader. Writer. Satirist. Hacker. Confessions from the people running the systems you live with. Essays on everything else. Tolle, lege. Legendo fit legenda.
John Capobianco @John_Capobianco
22K Followers 8K Following Head of AI and DevRel | Itential | Distinguished Speaker | Award Winning Author | Educator | Google Developer Expert | NetClaw | https://t.co/CZb5OMC61J
DistrictCon @DistrictCon
2K Followers 33 Following A new DC hacker conference: Bringing together builders, breakers, and fixers to do cool shit. 🪩 Year 2: February 6-7, 2027 🪩 https://t.co/qYKu4hlyJR
Chapin Bryce @chapindb
546 Followers 822 Following DFIR, skiing, & aviation nerd. Co-author of Learning Python for Forensics & Python Forensics Cookbook.
Natan Voitenkov @NVoitenkov
3K Followers 413 Following Founder | a16z/Speedrun | exGoogler | Ironman | UWC Alumni
CAPE Sandbox @CapeSandbox
5K Followers 116 Following Payloads or it didn't happen. https://t.co/rAVsWT6dcl
Matt Huang @matthuang
247K Followers 835 Following founder @paradigm, founder @tempo, board member @stripe, building & investing at the frontier
Cape @CapeCellular
2K Followers 59 Following America's privacy-first mobile carrier. Premium, nationwide cell service for $99/month with no hidden costs.
张惠倩 @momika233
19K Followers 236 Following Anda boleh melakukan segala-galanya dari syurga ke bumi, wanita kecil!! If you have any questions, please contact me https://t.co/MkzsavUU9V
BSides Harrisburg @BsidesHbg
358 Followers 273 Following Official account for BSides Harrisburg ™. Community driven security conference serving Central Pennsylvania | Friday, May 29, 2026 | https://t.co/wEiRXVq0kP
rekdt @rekdt
17K Followers 841 Following // malware degenerate // sr cybersecurity leader, megacorp usa // @sec_defcon daemon // misery @despairware // take sincerely at your own riskJ'onn J'onzz @leinn32
397 Followers 1K Following Security engineer, Historian, Researcher at huskysec, I like mobile applications
Miizix 🔱 @Miizix
8 Followers 12 Following
meKhatai @vurtan
1 Followers 4 Following
Psyho @FakePsyho
31K Followers 423 Following Humanity's Last Programmer; Game Designer; Problem Solver; past: OpenAI (Dota), Pro Competitive Programmer, Poker
patrick armstrong @patarmstrong
128 Followers 434 Following Photographer /\ Digital Imaging Technician / \ Cyber Security
her0x0ftime @her0x0ftime
92 Followers 287 Following Adversary Simulator. Defense Stimulator. Vulnerable by Design.































