Bad Sector Labs
@badsectorlabs.com
490 followers
53 following
58 posts
Cybersecurity news, techniques, exploits, and tools every week at http://blog.badsectorlabs.com 🐘@[email protected]
Posts
Media
Videos
Starter Packs
Bad Sector Labs
@badsectorlabs.com
· Aug 26
Last Week in Security (LWiS) - 2025-08-25
WebClient deep dive (@0xthirteen), 2x RCE chains in Commvault (@chudyPB), how to rob a hotel (@dmcxblue), MSI patch/protocol handler RCE (@johnnyspandex), self-relaying (@_logangoins), and more!
blog.badsectorlabs.com
Bad Sector Labs
@badsectorlabs.com
· Aug 19
Last Week in Security (LWiS) - 2025-08-18
DEF CON releases, PDQ SmartDeploy creds (@unsigned_sh0rt), FortiSIEM root command injection (@SinSinology), a cat themed loader (@vxunderground), fine-tune LLMs for offsec (@kyleavery_), juicing NTDS....
blog.badsectorlabs.com
Bad Sector Labs
@badsectorlabs.com
· Jul 15
Last Week in Security (LWiS) - 2025-07-14
LudusHound (@bagelByt3s), SpeechRuntimeMove (@ShitSecure), Havoc Pro (@C5pider), FortiWeb RCE (@SinSinology), SailPoint IQService RCE (@NetSPI), Altiris RCE (@lefterispan), WAF bypass (@nyxgeek ), and...
blog.badsectorlabs.com
Bad Sector Labs
@badsectorlabs.com
· Jul 14
LudusHound: Raising BloodHound Attack Paths to Life - SpecterOps
LudusHound is a tool for red and blue teams that transforms BloodHound data into a fully functional, Active Directory replica environment via the Ludus framework for controlled testing.
specterops.io
Bad Sector Labs
@badsectorlabs.com
· Jun 10
Last Week in Security (LWiS) - 2025-06-09
Windows self-delete on 24H2 (@TKYNSEC), DNS rebinding (@yarlob), VSCode backdoor (@d1rkmtr), leak Google users' 📞# (@brutecat), Entra sync dumping (@hotnops), Delegations (@podalirius_), Chrome abuse ...
blog.badsectorlabs.com
Bad Sector Labs
@badsectorlabs.com
· Jun 9