Search:

Last Week in Security (LWiS) - 2025-06-30

Linux sleep obfs (@k0zmer), sudo vuln (@0xm1rch), self-xss trick (@slonser_), primitive injection (@trickster012), Sitecore RCE (@chudyPB ), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2025-06-09 to 2025-06-30.

News

Techniques and Write-ups

Tools and Exploits

  • SCCMDecryptor-BOF - A Beacon Object File (BOF) implementation of Adam Chester's(@_xpn_) c# tool for decrypting SCCM encrypted password blobs retrieved from the site DB.
  • BitlockMove - Lateral Movement via Bitlocker DCOM interfaces & COM Hijacking.
  • EntraPassTheCert - tool for requesting Entra ID's P2P certificate and authenticating remote Entra joinned devices with it.
  • COMmander - .NET tool used to enrich RPC telemetry.
  • wsuks - Automating the MITM attack on WSUS.
  • ctail - Tail Certificate Transparency logs and extract hostnames.
  • silentpulse - single-threaded event driven sleep obfuscation poc for linux.
  • schtask - Rust implementation, creating a scheduled task programmatically with user logon trigger.
  • Panoptes - Panoptes Endpoint Detection and Response Solution.
  • SMAStorageDump - Symantec Management Agent (a.k.a. "Altiris Agent") dumper and decryptor.
  • wirego - A Wireshark plugin framework based on ZMQ, supporting Golang, Python and hopefully more languages soon. More info at Getting started with Wirego.
  • PrimitiveInjection - PrimitiveInjection by using Read, Write and Allocation Primitives. For more info see: Primitive Injection - Breaking the Status Quo.
  • DragonHash - Demo code JavaScript POC that tricks user into sending Windows hash to responder. For more info see: Dragging Secrets Out of Chrome: NTLM Hash Leaks via File URLs.
  • GoClipC2 - Clipboard for Command and Control between VDI, RDP and Others on Windows.
  • Nemesis - 2.0 release of Nemesis! - An offensive data enrichment pipeline.

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.

page 1 | older articles »