This article walks through how binary planting behavior in Code AI Editor extends beyond the previously reported git.exe case. Under specific conditions, other attacker-controlled files can also be automatically executed when a developer opens a folder, with no additional user interaction beyond opening the folder repositories.
This research share the details of attack chain where modern AI code editor URI handlers within the built-in remote development functionality of popular AI IDEs such as Cursor, Antigravity and Devin can be abused as delivery mechanisms for remote code execution and under some conditions credential stealing.
This post cover how PowerShell becomes a main tool in offensive operations starting with the weaponization, delivery, attak-chain and post-exploitation.
Creating shellcode manually, starting with simple functions like displaying a message box, until creating a custom reverse shell.
A Practical Walkthrough of Bypassing Windows Data Execution Prevention with Return‑Oriented Programming Leveraging VirtualAlloc
Autonomous lateral movement allows Red Teams to navigate networks, simulate attacks, and uncover hidden vulnerabilities efficiently, helping defenders strengthen detection and response strategies.
This post explores the offensive and defensive aspects of stageless Havoc implants, covering how they are deployed, detected, and mitigated in modern cybersecurity environments.
PEN-300 is OffSec’s advanced penetration testing course, focused on evading defenses, developing custom techniques, and preparing for the OSEP exam
There are still many gaps in the security industry when it comes to defining Vulnerability Assessment (VA), Penetration Testing, and Red Teaming. Interestingly, some people think a Pentest is the **same** as Red Teaming.