Search:

Last Week in Security (LWiS) - 2025-11-10

Apple's sourcemaps takedown (@moeruri), Call stack sig bypass (@saerxcit), AD Site pwnage (@croco_byte), sneaky remap (@MagisterQuis), Deceptiq launch (@deceptiq_), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2025-11-03 to 2025-11-10.

News

Techniques and Write-ups

Tools and Exploits

  • DonPwner - Advanced Domain Controller attack and credential analysis tool leveraging DonPAPI database.
  • magnet - Purple-team telemetry & simulation toolkit.
  • srsocwamof - Sneaky Remap - Shared Object Cloaking with a Minimum of Fuss ~ BSides Berlin 2025.
  • ExitPatcher - Prevent in-process process termination by patching exit APIs.
  • MaleficentVM - This is practice VM for malware development.
  • DiaSymbolView - PDB file inspection tool.
  • PhantomTask - A tool to play with scheduled tasks on Windows, in Rust.

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.