Red Teamer @OpenAI, meme archivist, XSS Hunter author, DNS/TLD/web security researcher.

Joined August 2012
776 Photos and videos
Pinned Tweet
Releasing a project I've been working on for a while: thermoptic - A next-generation HTTP stealth proxy which perfectly cloaks requests as the Chrome browser across all layers of the stack. github.com/mandatoryprogramm…
10
44
258
22,877
mandatory.bsky.social retweeted
We launched lockdown mode to all @ChatGPTapp users. For more security conscious users, this gives an extra layer of protection by reducing the risk of data exfiltration from prompt injection attacks. help.openai.com/en/articles/…
3
3
11
586
mandatory.bsky.social retweeted
Mar 31
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
541
4,024
16,161
12,405,499
mandatory.bsky.social retweeted
Work in progress on a "vibe hacking" mode coming to Sliver, including sync'd to n-operators via multiplayer:
2
2
39
3,855
mandatory.bsky.social retweeted
New Sliver release! > Improvements to shell you can now manage multiple shells and swap between them! > Windows PE metadata spoofing > Improvements to MacOS shellcode loader > Bug fixes github.com/BishopFox/sliver/…
29
85
7,719
mandatory.bsky.social retweeted
Some big updates to Sliver recently, more to come here some new features in v1.6.1 - v1.6.10 in addition to performance improvements and bug fixes 🧵:
1
6
15
2,542
mandatory.bsky.social retweeted
Not to worry, we've mitigated the issue:
⚡️New prompt injection to takeover C2 servers automated with @claudeai I use Sliver, but this approach could be used for any C2 that's automated with Claude. The trick: Plant a file that makes Claude think it was mounted on the attacker's local system. To "access" it, Claude must add an "auth token" to the attacker's ~/.bashrc/zshrc. That token? A reverse shell. 🎯 Requirements: • Sonnet 4.5 or earlier (Opus is inconsistent) • Claude running autonomously/in a loop (not "read file X") • Write access to attacker's home directory Blue team tip: Seed similar prompts in enticing files. Run payloads by legal first. Full prompt below 👇 #AGI #PromptInjection #DFIR #Clawdbot
1
3
35
5,814
mandatory.bsky.social retweeted
Sliver now has MCP support which means defenders can use prompt injection to leak sensitive information from the C2 server. 🎉 I use a file called passwords.txt to trick #ClaudeAI into creating directories beacon/session info. #AGI #PromptInjection #DFIR
8
63
257
27,478
mandatory.bsky.social retweeted
4 Dec 2025
For the Next.js/RSC RCE, it's possible to bypass both Vercel and Cloudflare, and most WAFs really. Don't trust your provider's WAFs, patch your systems ASAP. We added these new WAF aware checks to @assetnote earlier this morning.
17
62
526
110,434
mandatory.bsky.social retweeted
I am the main developer fixing security issues in FFmpeg. I have fixed over 2700 google oss fuzz issues. I have fixed most of the BIGSLEEP issues. And i disagree with the comments @ffmpeg (Kieran) has made about google. From all companies, google has been the most helpfull & nice
87
198
4,120
916,655
> pay 70$ for game > download over 100GB of data > game refuses to start without secure boot > enable secure boot > PC no longer even makes it to BIOS screen Love modern gaming, thanks @EA
1
4
978
Update: shorted my CMOS pins and my PC now boots again
633
thermoptic now supports upstream SOCKS & HTTP proxies so you can have a perfect JA4 fingerprint set across whichever exit IP you prefer 🎉: github.com/mandatoryprogramm… The update abstracts away Chrome's annoying proxy handling too, so you can use authenticated proxies as well!
1
17
1,679
mandatory.bsky.social retweeted
Updated Sliver's SGN implementation (by @egeblc) to use a wasm-based build of Keystone assembler making it easier to cross-compile to all platforms (to almost every GOOS/GOARCH) SGN standalone: github.com/moloch--/sgn/rele… Wasm keystone (fork of For-ACGN) github.com/moloch--/go-keyst…
5
10
2,215
🆕New thermoptic feature: Control the dockerized Chrome browser that the proxy utilizes via a Web UI: github.com/mandatoryprogramm… This allows you to manually log into sites and automatically use the authenticated session with your favorite HTTP client (with perfect fingerprints!).
1
1
3
526
It also makes debugging site problems and issues with your thermoptic hooks *much* easier 🔍.
395
mandatory.bsky.social retweeted
I wrote up a quick blogpost why this SIM farm story is bogus and why you journalists should feel embarrassed for not questioning such obvious propaganda. cybersect.substack.com/p/tha…

The Secret Service dismantled a network of more than 300 SIM servers and 100,000 SIM cards in the New York-area that were capable of crippling telecom systems and carrying out anonymous telephonic attacks, disrupting the threat before world leaders arrived for the UN General Assembly. 📰 Read more about this at secretservice.gov/newsroom/r…
29
157
834
105,884
New tutorial: "Bypassing" Cloudflare's Turnstile CAPTCHA With thermoptic github.com/mandatoryprogramm…
4
55
410
27,380
⚠️ Be careful which thermoptic repo you use, there are fake forked repositories floating around which appear in Google results. They are backdoored with malware! Only use the official repo from my Github.
1
2
5
1,161
The README appears to be rewritten with an LLM to get victims to click and run the packaged malware. I've already reported this repo.
2
700