Vincent Yiu (@vysecurity) 's Twitter Profile
Vincent Yiu

@vysecurity

Director, Red Team, Offensive Security. Help organizations safeguard their businesses from the bad guys.

ID: 2915572024

calendar_today11-12-2014 14:09:53

34,34K Tweet

28,28K Followers

282 Following

SpecterOps (@specterops) 's Twitter Profile Photo

MSSQL support just landed in BloodHound! You can now map out how attackers might use SQL servers to move laterally. This is incredibly useful in hybrid and legacy heavy environments. Let us know what you find. Learn more ➡️ ghst.ly/MSSQLHound

MSSQL support just landed in BloodHound! You can now map out how attackers might use SQL servers to move laterally. This is incredibly useful in hybrid and legacy heavy environments. Let us know what you find.

Learn more ➡️ ghst.ly/MSSQLHound
Jason Lang (@curi0usjack) 's Twitter Profile Photo

Created two new ansible roles for Bad Sector Labs's Ludus that enable ASR rules and create/link the recommended audit GPOs for an MDI rollout. It's all simple powershell, so would work for AutomatedLabs as well (see tasks/main.yml) github.com/curi0usJack/Lu…

SpecterOps (@specterops) 's Twitter Profile Photo

👋 Say hello to Nemesis 2.0, a streamlined, Docker Compose-based platform that is laser-focused on file triage. After introducing v1 two years ago, the team has reworked the platform to better serve what people need from it. Read more from Will Schroeder. ⤵️ ghst.ly/4mxQzFU

Malfors (@malforshq) 's Twitter Profile Photo

We just noticed that Stark Industries Ltd. transferred their AS44477 and IP ranges to PQ Hosting Plus S.R.L. just *4 days* before sanctions were announced. Meaning, they knew in advance that sanctions were coming and likely managed to save all their infrastructure and assets.

We just noticed that Stark Industries Ltd. transferred their AS44477 and IP ranges to PQ Hosting Plus S.R.L. just *4 days* before sanctions were announced.

Meaning, they knew in advance that sanctions were coming and likely managed to save all their infrastructure and assets.
Unsloth AI (@unslothai) 's Twitter Profile Photo

You can now run gpt-oss-120b & 20b locally with our GGUFs! 🦥 Run OpenAI's 120b model on 66GB RAM & 20b model on 14GB RAM. Both in original precision. Uploads includes our chat template fixes. Guide: docs.unsloth.ai/basics/gpt-oss GGUF: huggingface.co/unsloth/gpt-os…

You can now run gpt-oss-120b & 20b locally with our GGUFs! 🦥

Run OpenAI's 120b model on 66GB RAM & 20b model on 14GB RAM. Both in original precision.

Uploads includes our chat template fixes.

Guide: docs.unsloth.ai/basics/gpt-oss
GGUF: huggingface.co/unsloth/gpt-os…
Kimberley Mitnick (@kminx) 's Twitter Profile Photo

Always nice to see kevs books making an appearance at Blackhat Met some new faces today at the innovators and investment summit. Left disappointed with the speaking content (perhaps I've been to one too many events). Who are a few new faces in cyber that are great at

Always nice to see kevs books making an appearance at Blackhat 
Met some new faces today at the innovators and investment summit. 

Left disappointed with the speaking content (perhaps I've been to one too many events). 

Who are a few new faces in cyber that are great at
nixCraft 🐧 (@nixcraft) 's Twitter Profile Photo

AWS Deleted all data despite redundancy, backup, dead man’s switch. This is why you need to keep all your data offline. Never trust hosting company for your backups. seuros.com/blog/aws-delet…

Florian Hansemann (@cyberwarship) 's Twitter Profile Photo

''GitHub - DosX-dev/obfus.h: Macro-header for compile-time C obfuscation (tcc, win x86/x64)'' #infosec #pentest #redteam #blueteam github.com/DosX-dev/obfus…

ZoomEye (@zoomeye_team) 's Twitter Profile Photo

🚨🚨Adobe AEM Forms Vulns Alert CVE-2025-54253 (CVSS: 10): Critical RCE via misconfig, no auth or interaction needed. CVE-2025-54254 (CVSS: 8.6): XXE flaw allows arbitrary file reads, exposing sensitive data. No auth required. Search by vul.cve Filter👉vul.cve="CVE-2025-54253"

🚨🚨Adobe AEM Forms Vulns Alert
CVE-2025-54253 (CVSS: 10): Critical RCE via misconfig, no auth or interaction needed.
CVE-2025-54254 (CVSS: 8.6): XXE flaw allows arbitrary file reads, exposing sensitive data. No auth required.

Search by vul.cve Filter👉vul.cve="CVE-2025-54253"
BleepingComputer (@bleepincomputer) 's Twitter Profile Photo

ReVault flaws let hackers bypass Windows login on Dell laptops - Sergiu Gatlan bleepingcomputer.com/news/security/… bleepingcomputer.com/news/security/…

Caido (@caidoio) 's Twitter Profile Photo

🎉 You’ve been asking for it. The Caido Scanner plugin is finally here. Run checks in the background or scan specific requests on demand to find issues like reflected XSS, SQL injection, and CORS misconfigs. All checks are open source. Add your own and help the list grow 💪

Claude (@claudeai) 's Twitter Profile Photo

We just shipped automated security reviews in Claude Code. Catch vulnerabilities before they ship with two new features: - /security-review slash command for ad-hoc security reviews - GitHub Actions integration for automatic reviews on every PR

Garrett (@unsigned_sh0rt) 's Twitter Profile Photo

I pushed updates to SCCMHunter as part of my Arsenal demo at #BHUSA today! New features include a relay module for TAKEOVER-5 and a community contribution to coerce client push from a *nix host for ELEVATE-2. github.com/garrettfoster1….