Step-5 preview has been tested for about two weeks with impressive results. The earlier Step-3.7 was a long‑time favorite on the Nous Portal for many Hermes users. The author claims Step-5 preview beats DeepSeek-4.1-flash in their CTI.
Key points
Testing duration: two weeks
Claim: Step-5 preview beats DeepSeek-4.1-flash in CTI
Sources
Hands‑on SOC Home Lab with AD, Splunk, pfSense, and Hardened Endpoints
A lab is being built that includes an Active Directory domain, a Splunk SIEM that ingests live authentication events, pfSense with Suricata for network defense, and hardened Windows and Linux endpoints. The repository documents each component with commands, errors, and resolutions, and shows a detection pipeline that flags an unauthorized account creation using a custom SPL query mapped to MITRE ATT&CK T1136.
Key points
Active Directory domain controller with Splunk Universal Forwarder installed
Splunk Enterprise SIEM detects Event ID 4720 (unauthorized account creation) via a custom SPL query linked to MITRE ATT&CK T1136
Sources
InnoEdge Labs exploits Philips Hue Bridge Pro at Pwn2Own
Hank Chen of InnoEdge Labs exploited the Philips Hue Bridge Pro. The exploit used a chain of five bugs, including one zero‑day. The win was $6,000 and 2.5 Master of Pwn points at #Pwn2Own.
Key points
Exploit: 5‑bug chain with 1 zero‑day disclosure
Reward: $6,000 and 2.5 Master of Pwn points
Sources
Synacktiv Speedrun CTF at Booth Day 1
Synacktiv is hosting a speedrun capture‑the‑flag competition at its booth on Day 1. Qualifiers consist of a 15‑minute attempt on one challenge, with the eight fastest participants moving to the finals. The finals are scheduled for Friday the 16th at 9 PM as a social event, using a 1v1 best‑of‑3 bracket across Pwn, Web, Crypto, and Reverse categories.
Key points
Qualifiers: 15‑minute try, 1 challenge; top 8 fastest advance.
Finals: Friday 16th @ 9 PM, 1v1 BO3 bracket, categories Pwn, Web, Crypto, Reverse.
Sources
MATCHBOIL C# downloader analyzed by ESETresearch
MATCHBOIL is a C# downloader used by a Russia-aligned APT group to download, install, and persist another payload. ESETresearch has analyzed its evolution.
Key points
Analysis: ESETresearch examined changes in MATCHBOIL over time.
Usage: MATCHBOIL is employed by the APT group to fetch and maintain additional malware.
Sources
- Original post
- Linked resource - Linked in the post
Cartography integrates 30+ platforms into Neo4j for security analysis
Cartography pulls infrastructure assets and their relationships from over 30 cloud, identity, and SaaS platforms. It stores the data in a Neo4j graph. The graph can be used for security queries and rule‑based analysis.
Key points
Platforms: integrates more than 30 cloud, identity, and SaaS services.
Storage: uses a Neo4j graph for security queries and rule‑based analysis.
Sources
- Original post
- Linked resource - Linked in the post
Red Team Operations training at BHEU, London Dec 7-10
The team will lead Red Team Operations training at BHEU in London. The course runs four days from 7 to 10 December. It offers hands‑on tradecraft in a simulated enterprise environment. Registration is available via the provided link.
Key points
Date: 7‑10 December
Location: BHEU, London
Sources
- Original post
- Linked resource - Linked in the post
Lexmark CX532adwe exploited with two unique bugs at Pwn2Own
Lexmark CX532adwe was compromised using two unique bugs. The exploit earned the team $5,000 and 2 Master of Pwn points. The participants were Cong Thanh, Duc Hieu, and Nam Dung.
Key points
Bugs: Two unique vulnerabilities were used.
Reward: $5,000 and 2 Master of Pwn points were awarded.
