Last Week in Security (LWiS) - 2025-09-08
文章总结了过去一周的网络安全动态,包括变形编译、Windows安全调用、macOS竞态条件漏洞、NTLM中继攻击、iOS零点击RE等技术与工具。还涉及Cloudflare证书问题、npm供应链攻击、Firefox 32位Linux支持终止等新闻事件,并介绍了BloodHound OpenGraph挑战等活动与工具更新。 2025-9-9 03:59:0 Author: blog.badsectorlabs.com(查看原文) 阅读量:3 收藏

Metamorphic compilation (@tijme), Windows Secure Calls (@33y0re), macOS race condition exploit (@patch1t), NTLM relaying (@elad_shamir), iOS zero-click RE (@quarkslab), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2025-09-02 to 2025-09-08.

News

  • Specter Bash 2025 – October 6–9, 2025 | Denver, CO is SpecterOps' annual training event with a Halloween twist. Over four days, participants take part in SpecterOps courses on Red Team Operations, Tradecraft Analysis, Identity-driven Offensive Tradecraft, and Detection, led by the team behind BloodHound. When classes wrap up, evening sessions and community gatherings keep the energy going and give plenty of opportunities to connect with one another. Can’t attend in person? They have virtual options too! Last Week in Security readers get an exclusive 25% discount with code LWIS. Get the full details and register here. Sponsored

Techniques and Write-ups

Tools and Exploits

  • BloodHound OpenGraph Challenge - OpenGraph is live in BloodHound 8.0, and SpecterOps wants to see what you can do with it. Share your research, writeups, or talks for a chance at challenge coins, swag, and even SpecterOps training or a trip to SO-CON 2026. Submit your work here. Sponsored

  • dittobytes - Metamorphic cross-compilation of C++ & C-code to PIC, BOF & EXE.
  • sneaky_remap - A C and Go /proc/pid/maps cloak of invisibility for shared object files.
  • once-campfire - Campfire is web-based chat application. [Formally a $299 product by basecamp]
  • tls-preloader - LD_PRELOAD library to bypass TLS certificate verification for debugging and testing. See more at, TLS NoVerify: Bypass All The Things.
  • killerPID-BOF - Kill a process by specifying its PID. Short post here .
  • MeetC2 - (MeetC2 a.k.a Meeting C2) - A framework abusing Google Calendar APIs.
  • raw-disk-parser - A tool to interact with Windows drivers to perform a raw disk read and parse out target files without calling standard Windows file APIs.
  • orsted - Orsted C2 Framework.

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.


文章来源: https://blog.badsectorlabs.com/last-week-in-security-lwis-2025-09-08.html
如有侵权请联系:admin#unsafe.sh