Last Week in Security (LWiS) - 2025-05-27
上周网络安全新闻包括量子计算对RSA加密的潜在威胁、微软Windows Recall功能引发隐私担忧、自托管趋势兴起、Tailscale安全问题及UAE招募AI人才等。技术方面涉及BadSuccessor特权提升攻击、o3发现Linux内核SMB零日漏洞及Argusee自动化漏洞发现框架等工具与研究进展。 2025-5-28 08:14:56 Author: blog.badsectorlabs.com(查看原文) 阅读量:27 收藏

BadSuccessor (@YuG0rd), o3 finds SMB 0day (@seanhn), crashing defender (@InfoGuard_Labs), MDT looting (@Oddvarmoe), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2025-05-19 to 2025-05-27.

News

Techniques and Write-ups

Tools and Exploits

  • SharpSuccessor - SharpSuccessor is a .NET Proof of Concept (POC) for fully weaponizing Yuval Gordon’s (@YuG0rd) BadSuccessor attack from Akamai.
  • BadSuccessor.ps1 - BadSuccessor checks for prerequisites and attack abuse.
  • OnionC2 - C2 written in Rust & Go powered by Tor network.
  • AI-Red-Teaming-Playground-Labs - AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure.
  • brc4_profile_maker - An interactive TUI tool to create Brute Ratel C4 profiles based on BURP browsing data.

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

  • kunai - Threat-hunting tool for Linux.

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.


文章来源: https://blog.badsectorlabs.com/last-week-in-security-lwis-2025-05-27.html
如有侵权请联系:admin#unsafe.sh