TGViewer
Channel Public Channel
Sys-Admin InfoSec

Sys-Admin InfoSec

@sysadm_in_channel

News of cybersecurity / information security, information technology, data leaks / breaches, cve, hacks, tools, trainings
* Multilingual (En, Ru).
* Chat - @sysadm_in
* Job - @sysadm_in_job
* DNS - OpenBLD.net
* ? - @sysadminkz
Subscribers
12.9K
Photos
250
Videos
2
Links
4.6K
Recent Posts 20 shown
Post #5498 1.04K

Forwarded from Yevgeniy G.

Open SysConf'26 - Доклад: поиск уязвимостей в эпоху AI

Кибербезопасность, AI - сегодня идут нога в ногу, в качестве союзников, иногда в качестве врагов.

Доклад от @Thatskriptkid - Malware analyst, threat hunter, vulnerability researcher, автора множества интерейснейших ресерчей и интересных докладов, автора канала Order of Six Angles - https://t.me/orderofsixangles, хорошего друга, человека, который поддерживает и с первого Open SysConf с нами.

Рассказ автора про свою хоум лабу, про проекты которые крутятся на ней, как были найдены баги в Pixel, Xiaomi, Mediatek в результате подготовки ресерча, опыт автора с локальными ЛЛМ, Android Exploitation, Фаззинг драйверов Windows и не только...

10 Октября, в 10 утра, SmartPoint зал "Freedom Amphitheatre", Алматы.

https://sysconf.io/2026
Post #5495 1.71K
Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended

The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS. Combining two of them allows an attacker to take full control of the device without authentication if the device supports remote access using the SSH protocol. To make this chain easier to identify, we have given it a common name, MikroTrick:

https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
cert.pl Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS, including two critical ones. The vulnerabilities are already being actively exploited to take over devices whose SSH service is accessible from…
Post #5492 1.64K

Forwarded from Yevgeniy G.

🦄️️️️️️ Open SysConf'26. Спикер - ты нам нужен.

Начало сентября означает не только начало учебного года, но и, что Open SysConf'26 ближе чем ты думаешь!

Мы ищем доклады и докладчиков, заявки оставлять здесь.

В этом году места ограничены, поэтому фиксируйся, что бы точно попасть здесь.

Какие доклады мы ищем - интересные, бизнесовые, технические, ресерчи - все то, что поможет каждому развиться и сделать шаг вперед.

Передай друзьям, знакомым - мы рады видеть всех, кто готов развиваться и показывать дела, а "не пиздеть - не мешки ворочить".

Будут вопросы - смело пиши.

Всем Мир ✌️
Post #5491 2.03K
Building Linux eBPF/XDP apps on macOS (Apple Silicon)

I spend a lot of time building high-performance DNS filters and network tools in Go. My primary development machine is an Apple Silicon Mac, but all the production deployments target Linux/AMD64 servers.

Recently, I started heavily integrating eBPF and XDP to drop abusive traffic (like random subdomain attacks) before it even hits the Go networking stack. However, compiling C eBPF code locally on macOS has always been a pain due to the missing Linux headers and the architectural differences...

I wrote down the exact step-by-step process, including a workaround for the notorious Debian multiarch header issue (asm/types.h) and a neat little smoke test using bpftool inside the container..:

https://openbld.net/blog/build-xdp-ebpf-macos-guide/
openbld.net ↗ Building Linux eBPF/XDP Applications on macOS with Colima, Docker, Clang, and Go | OpenBLD A practical guide to building, inspecting, cross-compiling, and running Linux eBPF/XDP applications on macOS using Colima, Docker, Clang, bpf2go, and Go.
Post #5490 1.73K
Post #5488 2.09K
Clop Returns with Custom Implant in Mass-Extortion Campaign

..“Clop's” exploitation of CVE-2026-12569 in PTC Windchill has returned the group to mass exploitation, delivering a custom web shell that provides full data-theft capability from the moment of deployment, with no additional tooling required..:

https://reliaquest.com/blog/clop-returns-with-custom-implant-in-mass-extortion-campaign/
ReliaQuest Clop Returns with Custom Implant in Mass-Extortion Campaign Clop's exploitation of CVE-2026-12569 in PTC Windchill returns the group to mass exploitation with a custom web shell built for full data theft.
Post #5487 2.44K

Forwarded from OpenBLD.net (Yevgeniy G.)

3 BILLION DNS queries.

Almost +1 billion in one week.

OpenBLD started in 2019 as a homegrown project handling around 35K DNS queries a day.

Today:

→ ~15M queries/hour
→ 4K+ queries/second
→ servers distributed around the world
→ billions of DNS queries processed

And it still runs mostly on regular VPS infrastructure - with plenty of performance headroom left.

Getting here required years of optimizing the entire stack: networking, DNS processing, caching, filtering, load balancing, observability, and the Go code itself.

Now the growth is public too:

Real-time OpenBLD network statistics are live on OpenBLD.net.

From 35K/day to 3 billion.

Still building. 🚀

Fast. Private. Open.
Post #5484 2.4K
Post #5482 3.13K
ClickLock Stealer: Paste Once, Lose Everything

Upon execution of the ClickFix command, the malicious script shows a terminal-based loading animation mimicking Cloudflare progress bar with browser verification flow..:

https://www.group-ib.com/blog/clicklock-stealer-macos-malware/
Group-IB ClickLock Stealer: Paste Once, Lose Everything Analysis of ClickLock, a modular macOS stealer delivered via ClickFix that uses fake dialogs, kill loops, and a GSocket backdoor to steal passwords, browser data, and crypto wallets.
Post #5481 2.94K
Post #5479 2.46K
Older posts →

About this channel

How can I read @sysadm_in_channel without a Telegram account?
TGViewer shows the public web preview Telegram publishes for Sys-Admin InfoSec: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does Sys-Admin InfoSec have?
Sys-Admin InfoSec (@sysadm_in_channel) has 12.9K subscribers on Telegram, refreshed roughly every 30 minutes.
Does Sys-Admin InfoSec know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →