home.social

#hashpwn — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #hashpwn, aggregated by home.social.

  1. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  2. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  3. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  4. FortiBleed: The ongoing Fortinet / FortiGate compromise campaign

    Fortinet edge devices are being targeted in a large-scale compromise campaign involving exposed management interfaces, FortiCloud SSO abuse, credential theft, brute forcing, config exports, and suspicious admin account creation.

    This should be treated as a compromise-assessment event, not just a normal patch cycle.

    Admins should patch FortiOS, review all local admin accounts, rotate credentials and shared secrets, check for config exports, enforce MFA, and restrict management access to trusted IPs or VPN-only access.

    Full details:
    forum.hashpwn.net/post/14105

    #fortinet #fortigate #fortibleed #fortios #forticloud #cybersecurity #vpn #hashpwn

  5. NOCIX is currently experiencing an ongoing service-impacting outage affecting customer-hosted servers, with some users also reporting issues accessing the customer portal.

    No official root cause has been confirmed by NOCIX, but Reddit users are stating this is a power outage. This should be treated as unverified until NOCIX publishes an incident notice.

    More info:
    forum.hashpwn.net/post/13533

    #NOCIX #Hosting #DataCenter #Outage #SysAdmin #InfoSec #hashpwn

  6. NOCIX is currently experiencing an ongoing service-impacting outage affecting customer-hosted servers, with some users also reporting issues accessing the customer portal.

    No official root cause has been confirmed by NOCIX, but Reddit users are stating this is a power outage. This should be treated as unverified until NOCIX publishes an incident notice.

    More info:
    forum.hashpwn.net/post/13533

    #NOCIX #Hosting #DataCenter #Outage #SysAdmin #InfoSec #hashpwn

  7. NOCIX is currently experiencing an ongoing service-impacting outage affecting customer-hosted servers, with some users also reporting issues accessing the customer portal.

    No official root cause has been confirmed by NOCIX, but Reddit users are stating this is a power outage. This should be treated as unverified until NOCIX publishes an incident notice.

    More info:
    forum.hashpwn.net/post/13533

    #NOCIX #Hosting #DataCenter #Outage #SysAdmin #InfoSec #hashpwn

  8. NOCIX is currently experiencing an ongoing service-impacting outage affecting customer-hosted servers, with some users also reporting issues accessing the customer portal.

    No official root cause has been confirmed by NOCIX, but Reddit users are stating this is a power outage. This should be treated as unverified until NOCIX publishes an incident notice.

    More info:
    forum.hashpwn.net/post/13533

    #NOCIX #Hosting #DataCenter #Outage #SysAdmin #InfoSec #hashpwn

  9. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  10. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  11. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  12. YellowKey: BitLocker Bypass or Backdoor

    YellowKey, tracked as CVE-2026-45585, is a public BitLocker bypass that abuses WinRE/recovery-path behavior to expose a protected volume without the Windows password, recovery key, or AES cracking.

    At the time of this post, the author’s GitHub and original YellowKey repo appear to be down.

    Read more: forum.hashpwn.net/post/13339

    #BitLocker #YellowKey #CVE202645585 #CyberSecurity #InfoSec #WindowsSecurity #TPM #FullDiskEncryption #hack #exploit #news #hashpwn

  13. Spider v1.0.0 released.

    Spider is not just another web crawler -- it is a purpose-built wordlist and ngram processor for hash cracking workflows.

    URL Mode:
    Point it at a URL and Spider crawls the target, extracts words, and generates frequency-sorted wordlists and/or ngrams.

    But, Spider does not stop at web crawling...

    File Mode:
    Feed it local files and it brings the same word-processing engine to your own datasets, scraped content, notes, dumps, configs, or any other plaintext source you want to turn into a targeted wordlist or ngram set.

    More info:
    forum.hashpwn.net/post/52

    #spider #webcrawler #wordlist #generator #sort #ngram #cyclone #hashpwn #hashcracking

  14. Spider v1.0.0 released.

    Spider is not just another web crawler -- it is a purpose-built wordlist and ngram processor for hash cracking workflows.

    URL Mode:
    Point it at a URL and Spider crawls the target, extracts words, and generates frequency-sorted wordlists and/or ngrams.

    But, Spider does not stop at web crawling...

    File Mode:
    Feed it local files and it brings the same word-processing engine to your own datasets, scraped content, notes, dumps, configs, or any other plaintext source you want to turn into a targeted wordlist or ngram set.

    More info:
    forum.hashpwn.net/post/52

    #spider #webcrawler #wordlist #generator #sort #ngram #cyclone #hashpwn #hashcracking

  15. Spider v1.0.0 released.

    Spider is not just another web crawler -- it is a purpose-built wordlist and ngram processor for hash cracking workflows.

    URL Mode:
    Point it at a URL and Spider crawls the target, extracts words, and generates frequency-sorted wordlists and/or ngrams.

    But, Spider does not stop at web crawling...

    File Mode:
    Feed it local files and it brings the same word-processing engine to your own datasets, scraped content, notes, dumps, configs, or any other plaintext source you want to turn into a targeted wordlist or ngram set.

    More info:
    forum.hashpwn.net/post/52

    #spider #webcrawler #wordlist #generator #sort #ngram #cyclone #hashpwn #hashcracking

  16. Spider v1.0.0 released.

    Spider is not just another web crawler -- it is a purpose-built wordlist and ngram processor for hash cracking workflows.

    URL Mode:
    Point it at a URL and Spider crawls the target, extracts words, and generates frequency-sorted wordlists and/or ngrams.

    But, Spider does not stop at web crawling...

    File Mode:
    Feed it local files and it brings the same word-processing engine to your own datasets, scraped content, notes, dumps, configs, or any other plaintext source you want to turn into a targeted wordlist or ngram set.

    More info:
    forum.hashpwn.net/post/52

    #spider #webcrawler #wordlist #generator #sort #ngram #cyclone #hashpwn #hashcracking

  17. Spider v1.0.0 released.

    Spider is not just another web crawler -- it is a purpose-built wordlist and ngram processor for hash cracking workflows.

    URL Mode:
    Point it at a URL and Spider crawls the target, extracts words, and generates frequency-sorted wordlists and/or ngrams.

    But, Spider does not stop at web crawling...

    File Mode:
    Feed it local files and it brings the same word-processing engine to your own datasets, scraped content, notes, dumps, configs, or any other plaintext source you want to turn into a targeted wordlist or ngram set.

    More info:
    forum.hashpwn.net/post/52

    #spider #webcrawler #wordlist #generator #sort #ngram #cyclone #hashpwn #hashcracking

  18. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  19. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  20. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  21. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  22. Copy Fail (CVE-2026-31431) is a Linux kernel LPE that gives root access on every major linux distro.

    All that is needed is local shell access and a few lines of python.

    forum.hashpwn.net/post/12727

    #cybersecurity #copyfail #linux #exploit #cve202631431 #hashpwn

  23. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  24. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  25. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  26. Released: hashgen v1.3.0

    New in this version:

    * HMAC modes
    * PBKDF2 modes
    * scrypt support
    * additional BLAKE2 modes
    * hashcat UTF-16LE modes
    * optimized salt RNG on salted hashes
    * 95+ supported hash modes

    forum.hashpwn.net/post/89

    #hashgen #hashgenerator #hashcracking #hashpwn #golang

  27. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  28. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  29. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  30. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  31. Released pcfg-go — a full Go rewrite of pcfg_cracker with ~3× faster training, ~40× faster guessing, $HEX[] and multi-byte support, improved trainer parsing...

    Full Details: forum.hashpwn.net/post/11277

    #pcfg #hashcracking #trainer #guesser #wordlist #generator #hashcat #hashpwn

  32. CsP’s @Waffle_Real just released a new tool called hashpipe, and it solves a problem many of us run into with large potfiles: messy, misidentified hash:password entries.

    hashpipe automatically validates founds by recomputing them, identifying the correct algorithm, and outputting verified results in an mdxfind format.

    If you maintain large cracking datasets or potfiles, this is a great way to verify and clean them up.

    Details:
    forum.hashpwn.net/post/11119

    GitHub repo:
    github.com/Cynosureprime/hashp

    #hashcracking #hashcat #jtr #hashpipe #CsP #cynosureprime #potfile #hashpwn