XPN
banner
xpnsec.com
XPN
@xpnsec.com
Hacker for hire at @specterops.bsky.social
Blog: https://blog.xpnsec.com
Reposted by XPN
AI tooling and MCP servers are entering enterprises fast, often faster than security teams can assess the risks.

During a recent engagement, @xpnsec.com found a new Claude Code vuln (CVE-2025-64755) while exploring MCP abuse paths.

๐Ÿ‘€ Read the details: ghst.ly/49ybl4W
An Evening with Claude (Code) - SpecterOps
This blog post explores a bug, (CVE-2025-64755), I found while trying to find a command execution primitive within Claude Code to demonstrate the risks of web-hosted MCP to a client.
ghst.ly
November 21, 2025 at 4:34 PM
Still here.. still lurking
October 28, 2025 at 1:25 PM
My second post for the month is now live ๐ŸŽ‰
Get the scoop on the incoming Administrator Protection for Windows 11.

@xpnsec.com covers the architecture, access controls, and why some legacy UAC bypass techniques remain effective in his latest blog post. ghst.ly/44mw5JM
Administrator Protection Review - SpecterOps
Microsoft will be introducing Administrator Protection into Windows 11. This post explores security considerations for red teamers.
ghst.ly
June 18, 2025 at 6:54 PM
Talking Heads released a music video for Psycho Killer and it's fucking awesome :D www.youtube.com/watch?v=CJ54...
Talking Heads - Psycho Killer (Official Video)
YouTube video by Talking Heads
www.youtube.com
June 13, 2025 at 11:37 AM
Please say we're getting another PsychOdyssey to go with Keeper dev!!!
a man in a suit and tie is standing in front of a microphone and saying `` please be true '' .
ALT: a man in a suit and tie is standing in front of a microphone and saying `` please be true '' .
media.tenor.com
June 9, 2025 at 10:20 AM
Reposted by XPN
๐Ÿšจ New blog post alert!

@xpnsec.com drops knowledge on LLM security w/ his latest post showing how attackers can by pass LLM WAFs by confusing the tokenization process to smuggle tokens to back-end LLMs.

Read more: ghst.ly/4koUJiz
Tokenization Confusion - SpecterOps
Meta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs.
ghst.ly
June 3, 2025 at 5:44 PM
New blog post is up! Stepping out of my comfort zone (be kind), looking at Meta's Prompt Guard 2 model, how to misclassify prompts using the Unigram tokenizer and hopefully demonstrate why we should invest time looking beyond the API at how LLMs function. specterops.io/blog/2025/06...
Tokenization Confusion - SpecterOps
Meta's Prompt Guard 2 aims to prevent prompt injection. This post looks at how much knowledge of ML we need to be effective at testing these LLM WAFs.
specterops.io
June 3, 2025 at 4:57 PM
The level of snark in my upcoming blogpost is next level... And I'm not even sorry!
taylor swift is wearing a black off the shoulder top .
ALT: taylor swift is wearing a black off the shoulder top .
media.tenor.com
May 21, 2025 at 3:34 PM
Reposted by XPN
Didnโ€™t know this impressive fact. @xpnsec.com did you?
Each year, Eurovision has more live viewers than the Super Bowl, Oscars and Grammys combined. This shocks Europeans when I tell them.

So check it out. Live semi-final 1 airing now: www.youtube.com/live/0HNXVB2...
Eurovision Song Contest 2025 - First Semi-Final - Livestream | #Eurovision2025
YouTube video by Eurovision Song Contest
www.youtube.com
May 13, 2025 at 8:47 PM
I did not but it makes me feel better about watching it now :D
May 14, 2025 at 11:57 AM
Wrong XPN (unless you like hacker techno) ๐Ÿค—
May 9, 2025 at 2:19 PM
Reposted by XPN
You've been prepping for #OSCP exam day, and it finally arrives. ๐Ÿ™‡

In Part 4 of his blog series, @anam0x.bsky.social focuses on the test & how to maximize the educational, financial, & professional value of the exam experience.

Read more: ghst.ly/4lHDw4M

๐Ÿงต: 1/4
April 22, 2025 at 4:14 PM
Worked on a simple POC last night for connecting Mythic up to LiteLLM (pointing to Claude) for riding shotgun on a C2 session. Only using shell cmd, but provides oversight and hints to potential paths to explore. Quite happy for a weekend project :D youtu.be/C9J5okm6cA4
Superintendent POC
YouTube video by Adam Chester
youtu.be
April 20, 2025 at 10:53 AM
New AI Slop Avatar, who dis?
April 18, 2025 at 12:02 PM
Reposted by XPN
WinRMS relay (@Defte_), plaintext Zip attacks (@pfiatde), SQL Server Crypto deep dive (@_xpn_), FindUnusualSessions (@podalirius_), and more!

blog.badsectorlabs.com/last-week-in...
Last Week in Security (LWiS) - 2025-04-14
WinRMS relay (@Defte_), plaintext Zip attacks (@pfiatde), SQL Server Crypto deep dive (@_xpn_), FindUnusualSessions (@podalirius_), and more!
blog.badsectorlabs.com
April 15, 2025 at 7:46 PM
Slides from my SOCON 2025 presentation are now up on GitHub github.com/xpn/Presenta...
Presentations/SOCON2025 at main ยท xpn/Presentations
A collections of presentations. Contribute to xpn/Presentations development by creating an account on GitHub.
github.com
April 15, 2025 at 9:36 AM
Awesome post from @atomicchonk.bsky.social on NLP Tokenizing. We need more content like this to show the "how" behind the LLM :) www.corgi-corp.com/post/tokeniz...
Tokenizing the Sandwich Debate: How NLP Models Weigh In on Hot Dogs
Get the gist for Natural Language Processing (NLP) and how tokenization plays a factor
www.corgi-corp.com
April 11, 2025 at 1:51 PM
Reposted by XPN
Think NTLM relay is a solved problem? Think again.

Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31
April 8, 2025 at 11:00 PM
New blog post ๐Ÿค—
In our latest blog post, @xpnsec.com breaks down how SQL Server Transparent Data Encryption works, shares new methods for brute-forcing database encryption keys, & reveals a default key used by ManageEngine's ADSelfService product backups.

Read more ๐Ÿ‘‰ ghst.ly/4iXFTyF
April 8, 2025 at 6:45 PM
No idea why my first thought to a problem is a heavy RE session, something for therapy I think ๐Ÿคฃ
April 8, 2025 at 5:35 PM
Celebrating 1 year at SpecterOps, this was the first project I worked on after starting. Looking at SQL Server Transparent Data Encryption, how to bruteforce weak keys, and how ManageEngine's ADSelfService product uses TDE with a suspect key. Enjoy :) specterops.io/blog/2025/04...
The SQL Server Crypto Detour - SpecterOps
As part of my role as Service Architect here at SpecterOps, one of the things Iโ€™m tasked with is exploring all kinds of technologies to help those on assessments with advancing their engagement. Not l...
specterops.io
April 8, 2025 at 4:03 PM
Love this article. Itโ€™s something that Iโ€™ve tried to follow throughout my career, having a line of sight to business profit centres. Even more important in the days of tech layoffs www.seangoedecke.com/where-the-mo...
Knowing where your engineer salary comes from
How tech companies make money and why it's important
www.seangoedecke.com
April 8, 2025 at 2:37 PM
1 year anniversary at SpecterOps, so many personal and professional achievements in a short space of time. My advice for anyone getting into this field, try and make sure that you work companies and colleagues that push you beyond your comfort level. \o/
April 6, 2025 at 5:17 PM
Iโ€™ll throw the blog post up soon to share it :)
April 2, 2025 at 2:04 AM
I did a talk!! #socon2025
April 1, 2025 at 9:47 PM