{"database":"public-feed","table":"feed","is_view":false,"human_description_en":"","rows":[[98,"Six days of hands-on training, then NetWars and SANS@Night talks in the evenings · x.com · TheHackersNews","cybersecurity",0,"2026-09-29T14:17:11+00:00","@TheHackersNews 发布消息称 SANS CDI 2026 将于 Dec 14-19 在 Washington, D.C. 举办，为期六天的动手培训后，晚间安排 NetWars 与 SANS@Night 讲座；配图标注 SANS、DECEMBER 14–19, 2026、WASHINGTON, D.C.，帖文附详情与报名链接。","[\"cybersecurity\", \"SANS\", \"培训\", \"x.com\"]","[跳转原文](https://x.com/TheHackersNews/status/2104938544158654853)"],[130,"🧠 The best DFIR responders don't collect everything. They collect the right thin · x.com · tryhackme","cybersecurity",0,"2026-09-29T13:45:00+00:00","tryhackme 在 x.com 发帖称，最优秀的 DFIR 响应者不会收集全部数据，而是快速收集正确的目标物证，并引导读者了解 KAPE 定向物证采集如何改变调查的节奏。配图列出 KAPE 的命令行参数及其用途：--tsource 指定 KAPE 扫描的驱动器或文件夹，通常为系统盘根目录如 C:；--tdest 指定采集到的原始目标写入的文件夹，该文件夹不存在时会自动创建；--target 指定要采集的 target 或复合 target，例如 !SANS_Triage 或单个 target 名称；--tflush 在采集前清空目标输出文件夹，使上一次运行的结果不与本次混合；--mdest 指定解析后模块输出写入的文件夹，与原始采集目标分开存放；--module 指定对已采集数据运行的模块或复合模块，例如 !EZParser；--mflush 在解析前清空模块输出文件夹；--mef 指定解析模块输出的导出格式，如 csv、html 或 json。帖子主张定向物证采集能改变调查的推进节奏，可跟进的线索为配图中给出的参数与 !SANS_Triage、!EZParser 示例。","[\"dfir\", \"kape\", \"digital-forensics\", \"incident-response\"]","[跳转原文](https://x.com/tryhackme/status/2104930444974162256)"],[147,"Built a home lab” probably isn’t selling your skills as well as you think. 👀 You · x.com · tryhackme","cybersecurity",0,"2026-09-29T13:20:06+00:00","账号 @tryhackme 在 x.com 发帖称，\"Built a home lab\" 这类表述对求职技能的展示效果不如写作者以为的那么好，网络安全项目应在简历上呈现你发现了什么、解决了什么、取得了什么成果，而不只是列出了用了哪些工具，帖子称应动手构建值得写进 CV 的技能与项目，并附两条 t.co 链接。","[\"cybersecurity\", \"求职\", \"home lab\", \"简历\"]","[跳转原文](https://x.com/tryhackme/status/2104924179388617164)"],[166,"🚀 Master Active Directory Penetration Testing — Online Training Now Open! · x.com · hackinarticles","cybersecurity",0,"2026-09-29T12:50:01+00:00","Ignite Technologies 在 x.com 发布动态，为其 Active Directory Penetration Training 在线培训开放 limited-seat batch 招生，发布方称课程面向希望超越理论、掌握真实攻击链的专业人士，适合认真从事红队工作或向 OSCP 级技能进阶者。课程表包含 Initial Active Directory Exploitation、Active Directory Post-Enumeration、Abusing Kerberos、Advanced Credential Dumping Attacks、Privilege Escalation Techniques、Persistence Methods 与 Lateral Movement Strategies，其中 DACL Abuse、ADCS Attacks、Sapphire & Diamond Ticket Attacks 三项标注为 New，另设 Bonus Sessions。发布方称 Active Directory 仍是企业入侵的 #1 目标，课程针对红队实战与 OSCP、CRTP、CRTE 备考，并称所练技能正是 hiring managers 与 engagement leads 所看重者（属发布方主张）。报名经帖子给出的注册链接、WhatsApp 链接或 info@ignitetechnologies.in 完成，发布方提示名额有限需尽快锁定，并呼吁读者在评论区打 🔥 或 @ 需要提升 AD 技能的朋友；所给正文未涉及开课日期、课时长度与价格。","[\"CyberSecurity\", \"PenTesting\", \"RedTeam\", \"ActiveDirectory\", \"Kerberos\", \"PrivilegeEscalation\"]","[跳转原文](https://x.com/hackinarticles/status/2104916609320333346)"],[167,"Pic of the Day · x.com · hackinarticles","cybersecurity",0,"2026-09-29T12:49:30+00:00","@hackinarticles 在 x.com 发布「Pic of the Day」短讯，配图为一则对比梗图：「Networking for MBAs」与「Networking for Scientists」并列，后者写的是「Can Anyone ping 165.18.113.12」，配图来源标注 imgflip.com。","[\"infosec\", \"cybersecurity\", \"cybersecuritytips\", \"pentesting\", \"cybersecurityawareness\"]","[跳转原文](https://x.com/hackinarticles/status/2104916476876718147)"],[176,"🔥 OSCP isn’t about knowing more tools. · x.com · hackinarticles","cybersecurity",0,"2026-09-29T12:45:49+00:00","账号 @hackinarticles 在 x.com 发帖推广 OSCP 培训项目，主张 OSCP 考试考察的不是掌握更多工具，而是在一切手段失效时知道下一步做什么。帖子列出课程内容：手动实验、Linux 与 Windows 提权、Web 渗透、Active Directory、Pivoting 与 Tunneling、考试风格练习以及报告与方法论，并称工具容易学、方法论才能通过考试。报名需填写表单由团队联系，帖子称名额有限、招生即将截止，留有邮箱 info@ignitetechnologies.in 与 WhatsApp 联系方式，未给出课程价格，上述能力与安排属发布方主张。","[\"OSCP\", \"CyberSecurity\", \"Pentesting\", \"EthicalHacking\", \"RedTeam\"]","[跳转原文](https://x.com/hackinarticles/status/2104915552359850343)"],[188,"AI 智能体安全公司 Reco 融资 5500 万美元，赛道竞争者密集 · aihot.news","cybersecurity",0,"2026-09-29T12:30:00+00:00","AI 智能体安全公司 Reco 完成 $55M 融资，TechCrunch 报道（作者 Ram Iyer）称该赛道竞争者密集：仅粗查 Crunchbase 与 PitchBook 公开档案，就至少有 two dozen 家公司在售卖某种形式的 AI 智能体安全产品。报道并列了不同路线：有的检查智能体所用的工具，有的限制智能体可触达的数据，CrowdStrike 在智能体运行的设备上构建检测与响应控制，Zenity 聚焦发现与处置未经批准的 AI 使用；报道指出这些产品的承诺相当相似，都涉及知识图谱、持续监控、运行时安全、工具访问与 MCP vetting。Reco 直到去年主要销售用于测绘并保护 SaaS 与 AI 平台的软件，作者称其现围绕更广的方案重新定位，用 context graph 将智能体与应用、人员、账号和权限连接起来供安全团队使用（该句在所给片段中被截断）。","[\"Reco\", \"AI智能体安全\", \"融资\", \"TechCrunch\", \"网络安全\"]","[跳转原文](https://aihot.news/items/epkgbpzjip7aj5bazs72to21n)"],[201,"We've launched our new partner and reseller platform. · x.com · DarkWebInformer","cybersecurity",0,"2026-09-29T11:51:35+00:00","WhiteIntel（@whiteintel_io）宣布推出新的合作伙伴与转售平台，邀请加入其伙伴计划，在暗网监控市场中按每个账户获得发布方所称的有竞争力的分成（属发布方主张，未经独立验证）。","[\"dark web monitoring\", \"partner program\", \"reseller\", \"Whiteintel\"]","[跳转原文](https://x.com/whiteintel_io/status/2104901902655975508)"],[435,"全平台 SSH 客户端 Termark 上架 iOS 了，抽个奖 · v2ex.com","cybersecurity",0,"2026-09-29T05:26:57+00:00","全平台 SSH 客户端 Termark 正式上架 iOS App Store 并同日发布 Android apk，楼主称其现已覆盖 macOS、Windows、Linux，一份授权所有平台通用，主机、凭据与配置可跨设备同步。其公布累计安装设备 5000+、日活 600+、月活 3000+（仅统计开启匿名上报的用户），7 月初至今已发 21 个稳定版，功能多由用户需求排入，Windows 用户占多数故专门做了自动发现本机 WSL。能力声明属发布方主张、未经独立验证：同步支持官方同步、WebDAV、S3、iCloud、本地目录且客户端加密后上传，SSH 会话内 AI 可读取最近终端输出并执行命令，Codex、Claude Code、OpenCode 可直接调用其资产，iOS 以灵动岛显示活跃会话数，兼容 GBK、keyboard-interactive（OTP 二次认证）与老旧 SSH 算法。核心 SSH 与 SFTP 免费、其余功能付费，未说明 AI 所用模型与计费方式；楼主转述已购用户理由为好看顺手、免费用久后支持、提过需求基本做进去（称第三种最多）；为庆祝 iOS 上架抽 20 个 1 年会员兑换码，开奖 2026-09-30 14:00，兑换码 30 天内有效，官网 termark.app。","[\"SSH客户端\", \"iOS\", \"Termark\", \"开发者发布\", \"抽奖\"]","[跳转原文](https://www.v2ex.com/t/1245505)"],[453,"Cheatsheet for Beginners: Linux Commands 🐧 · x.com · Anastasis_King","cybersecurity",0,"2026-09-29T04:40:48+00:00","@Anastasis_King 在 x.com 发布一条题为 Cheatsheet for Beginners: Linux Commands 的短讯，标题末带 🐧 图标，配图给出一份面向初学者的 Linux 命令速查表。配图逐条列出命令与英文释义共约20条：ls 列出目录内容，cat 打印文件，grep 按模式搜索特定结果，clear 清空终端，cd 切换目录，pwd 打印当前工作目录，mkdir 创建目录，man 打印指定工具的手册页，which 返回可执行文件路径，find 在目录层级中搜索文件，locate 用预建数据库在系统内搜索文件，who/whoami 显示已登录用户与当前用户，id 返回用户 ID，chmod 修改文件或目录的权限与 MODE 标志，uname 打印操作系统名称，ifconfig 配置系统网络接口，ip 显示与配置网络参数，sudo/su 默认以 SuperUser 身份执行命令或开启会话，ps 列出运行中的进程状态，kill 向进程发送 KILL 信号；部分条目附助记括注，如 cat 源自 conCATenate、mkdir 拆解为 MaKe a DIrectory，另有 clear 的 CLEAR、uname 的 Unix NAME、ifconfig 的 InterFace CONFIGuration、chmod 的 CHanges 等大小写助记。配图左上带 HACKTHEBOX 标识。","[\"infosec\", \"cybersecurity\", \"hacking\", \"pentesting\", \"security\", \"linux\"]","[跳转原文](https://x.com/Anastasis_King/status/2104793493201625482)"],[708,"Ransomware groups were asked a simple question... do you like cats? 🐶 👇 · x.com · DarkWebInformer","cybersecurity",0,"2026-09-28T21:51:09+00:00","x.com 帖文 @DarkWebInformer 称其向数十个勒索软件团伙提出了「你们喜欢猫吗」这一问题，并称已得到结果、将以线索串公布；正文仅为导语与被引原帖，具体回答未出现在本文中。","[\"ransomware\", \"cats\", \"x.com\"]","[跳转原文](https://x.com/DarkWebInformer/status/2104690402389332219)"],[737,"Most beginners don’t need more web-hacking content. · x.com · theXSSrat","cybersecurity",0,"2026-09-28T20:20:15+00:00","x.com 用户 @theXSSrat 发帖称多数 Web 渗透入门者缺的不是更多内容而是一个学习顺序，并推介名为 906 的学习路线。帖子称该路线含 26 项条目，依次为 Linux 与网络、Web 应用、Burp/XSS/BAC、实验环境与 CxWAP 备考，另含 3 个月 RatCTF。配图以关键词标签形式列出 LINUX、PORT SCANNING、BURP、ACCESS CONTROL、WEB APP、XSS、NETWORKING、LABS 等模块。帖子给出促销码 FLASH50，价格由 €150 降至 €75，并称仅剩 2 个名额，附两个 t.co 短链。","[\"cybersecurity\", \"web-hacking\", \"education\", \"promotion\"]","[跳转原文](https://x.com/theXSSrat/status/2104667525397274970)"],[842,"🔥 OSCP isn’t about knowing more tools. · x.com · hackinarticles","cybersecurity",0,"2026-09-28T15:31:55+00:00","x.com 账号 @hackinarticles 发帖推广其 OSCP Training Program，称 OSCP 考试考验的不是掌握更多工具，而是当一切手段都不奏效时知道下一步该做什么，并称工具易学、方法论才是通过考试的关键。帖文列出课程内容包括动手实验、Linux 与 Windows 提权、Web 渗透、Active Directory、Pivoting 与 Tunneling、考试风格练习及报告与方法论，另称下一批次席位有限、招生即将截止，完整课程大纲、批次详情与培训费用需填写表单后由团队联系，联系邮箱为 info@ignitetechnologies.in，并提供 WhatsApp 渠道。（以上均为该帖推广主张）","[\"OSCP\", \"OSCPTraining\", \"CyberSecurity\", \"Pentesting\", \"EthicalHacking\", \"RedTeam\"]","[跳转原文](https://x.com/hackinarticles/status/2104594964143612128)"],[860,"\"#THMOnCampus is STILL OPEN 👀 Take TryHackMe to your campus however you want. Po · x.com · tryhackme","cybersecurity",0,"2026-09-28T15:15:12+00:00","TryHackMe 在 x.com 发文宣布 #THMOnCampus 校园征集活动仍在开放，参与者可自行将 TryHackMe 带到校园，形式不限于海报、cyber nights、lab sessions 与 campus chaos，截止日期为 9 月 30 日，帖子附投稿入口链接。官方称奖品包括 MAX、swag、1:1 cyber/career AMA 与一台 laptop。","[\"#THMOnCampus\", \"TryHackMe\", \"cybersecurity\", \"campus\", \"AMA\"]","[跳转原文](https://x.com/tryhackme/status/2104590758493766128)"],[932,"AI is changing the way security professionals approach penetration testing. · x.com · hackinarticles","cybersecurity",0,"2026-09-28T13:53:17+00:00","@hackinarticles 在 x.com 发布 AI 渗透测试培训招生帖，发帖方称 AI 正在改变安全从业者开展渗透测试的方式，下一代网络安全从业者需要同时理解攻击性安全与 AI 驱动的工作流。帖文宣传的培训覆盖 AI 辅助渗透测试、侦察与枚举、实操实验、利用技术、权限提升、AI 红队、真实项目与面试准备，交付形式包括直播课程、实操实验与动手项目、工作日与周末班次，并以职业导向训练为卖点。帖文提供免费职业咨询与 Demo 课报名入口，以及站点、WhatsApp、安全博客、LinkedIn、X、Telegram 等跟进链接，上述课程能力与就业导向表述均属发布方主张，未经独立验证。","[\"AI penetration testing\", \"cybersecurity training\", \"red team\", \"infosec\"]","[跳转原文](https://x.com/hackinarticles/status/2104570141703094473)"],[933,"Looking to reach cybersecurity professionals who actually care about technology, · x.com · hackinarticles","cybersecurity",0,"2026-09-28T13:52:34+00:00","Ignite Technologies × HackingArticles 在 x.com 发布广告与媒体合作邀约，面向网络安全生态提供赞助与推广位。帖子称其社区触达 600,000+ LinkedIn Followers、300,000+ X Followers、23,000+ Telegram Members（均为发布方自报数据，未经独立验证），受众覆盖 Security Professionals、Penetration Testers、Red Teamers、Security Researchers、Developers & IT Professionals、Cybersecurity Students、Ethical Hackers 与安全爱好者。帖子列出的合作形式包括 Sponsored Posts、Product & Service Promotion、Product Launch Campaigns、Webinar & Event Promotion、Training & Certification Promotion、Recruitment Campaigns、Sponsored Technical Content 与 Cybersecurity Brand Awareness，适用对象为网络安全产品、SaaS 平台、认证、培训项目、安全服务、招聘活动、网络研讨会与技术方案。帖子称可帮助品牌面向高相关性网络安全受众建立曝光；获取 advertising rates、campaign proposals 与合作机会的联系邮箱为 raj@hackingarticles.in，其给出的渠道为 LinkedIn /company/hackingarticles、X @hackingarticles 与 Telegram 链接。","[\"advertising\", \"media partnership\", \"cybersecurity\", \"marketing\"]","[跳转原文](https://x.com/hackinarticles/status/2104569960148390321)"],[935,"Pic of the Day · x.com · hackinarticles","cybersecurity",0,"2026-09-28T13:51:47+00:00","x.com 账号 @hackinarticles 发布\"Pic of the Day\"，配图为 @TheSpacerr（带蓝色认证标志）的帖子截图，文字为\"Do not forget how to code. AI won't build illegal apps. You will.\"，该帖主张提醒人们不要忘记如何编码，称 AI 不会编写非法应用、会去写的是人。配图显示该帖发布于 13 Aug 26，获 793K Views、39K 点赞、3.2K 转发、537 评论。","[\"infosec\", \"cybersecurity\", \"cybersecuritytips\", \"pentesting\", \"cybersecurityawareness\"]","[跳转原文](https://x.com/hackinarticles/status/2104569763188084915)"],[938,"Security 360 Mindmap · x.com · hackinarticles","cybersecurity",0,"2026-09-28T13:49:54+00:00","x.com 账号 @hackinarticles 发布 Security 360 Mindmap，帖文称其提供网络安全领域、工具与方法论的完整概览，帮助安全从业者在一个地方理解 offensive、defensive 与 governance 三类安全实践。帖文列出的关键领域包括 Network Security、Web Application Security、Cloud Security、Mobile Security、OSINT & Reconnaissance、Red Team & Offensive Security、Blue Team & Defensive Security、Governance, Risk & Compliance、Vulnerability Assessment & Pentesting。帖文称思维导图将工具、技术与概念结构化组织，便于快速学习与查阅，并给出 Telegram、Twitter 频道及思维导图链接；未给出该图的作者、覆盖深度或更新时间。","[\"cybersecurity\", \"mindmap\", \"infosec\", \"redteam\", \"blueteam\", \"pentesting\"]","[跳转原文](https://x.com/hackinarticles/status/2104569290259316831)"],[940,"🚨 9,000+ GitHub Stars — Cybersecurity Mindmap Collection 🧠🔥 · x.com · hackinarticles","cybersecurity",0,"2026-09-28T13:49:18+00:00","@hackinarticles 在 x.com 发帖（2026年9月28日 13:49）推介其创建的 Cybersecurity Mindmap 仓库，称该仓库已获 9,000+ GitHub Stars 与 1,800+ Forks。帖子开头列举网络安全学习的痛点：数百种工具、各异的攻击方法、复杂的技术与过多难以记忆的命令，并据此主张可视化思维导图极为有用，称其仓库为一份持续扩充的实用网络安全思维导图合集，覆盖技术、工具、方法论与安全领域。帖子列出的覆盖主题包括 Active Directory Pentesting、Red Teaming、Web Application Security、Blue Team、OSINT、Burp Suite、Nmap、Metasploit、Mimikatz、Impacket、Docker、Cloud Security、Wireshark、Wireless Pentesting、Enumeration、OWASP、Password Attacks 以及 Google & GitHub Dorks，并称还有更多主题。帖子指明仓库适合 OSCP Students、Red Teamers、Blue Teamers、Penetration Testers 与 Cybersecurity Learners，随帖给出 GitHub 仓库链接及 Telegram、Twitter 社群入口，并号召读者 star 仓库、收藏与转发分享。","[\"cybersecurity\", \"OSCP\", \"RedTeam\", \"Pentesting\", \"InfoSec\", \"GitHub\"]","[跳转原文](https://x.com/hackinarticles/status/2104569140807864491)"],[958,"Making Analysis Easy with Forensic-Timeliner · x.com · co11ateral","cybersecurity",0,"2026-09-28T13:25:30+00:00","x.com 用户 @co11ateral 发帖介绍 Forensic-Timeliner，称其把 KAPE、Chainsaw 与 Hayabusa 输出的杂乱 CSV 转成彩色、可读且便于分析的时间线（帖子主张）。配图为 Timeline Explorer v2.1.0 界面，已加载文件 20260225_055635_ForensicTimeliner.csv，表格列为 Tag、Date Time、Timestamp、Artifact Name、Tool、Description、Data Details、Data Path，并提供按列分组拖放区与搜索框。截图条目时间自 2025-03-12 15:08:32 起，涵盖 MFT、Event Logs、Prefetch、Registry、WindowsTimelineActivity 等 artifact 类型，Tool 列标为 EZ Tools，描述含 Created、Run Time、Last Executed、Program Execution 及 UserAssist、FeatureUsage 等条目。帖子附两个 t.co 短链可作跟进线索。","[\"forensics\", \"timeline\", \"KAPE\", \"Chainsaw\", \"Hayabusa\", \"digital-forensics\"]","[跳转原文](https://x.com/co11ateral/status/2104563151920361569)"],[977,"If you’re into exploit dev, reverse engineering, low-level programming, hacking, · x.com · cr3ghost","cybersecurity",0,"2026-09-28T13:00:01+00:00","@cr3ghost 在 x.com 发帖推荐技术杂志 Paged Out!，称其完全免费、由社区制作，每篇文章只占一页，面向 exploit dev、逆向工程、底层编程、黑客、复古计算与安全研究读者，内容为技巧、研究、想法与作品，无注水。帖子称 Issue #9 下载量已超 221,000 次，全部存档免费可取，并提醒 Issue #10 投稿截止时间为 September 30 AoE，附链接与 #InfoSec 标签，末尾询问读者在该杂志读到的最佳文章。","[\"InfoSec\", \"Paged Out!\", \"zine\", \"exploit dev\", \"reverse engineering\", \"security research\", \"submission\"]","[跳转原文](https://x.com/cr3ghost/status/2104556738204901837)"],[989,"Real talk 🐀 — only 1 seat left in my 12-week \"Zero to Hero\" 1:1 bug bounty coach · x.com · theXSSrat","cybersecurity",0,"2026-09-28T12:36:11+00:00","账号@theXSSrat 在 x.com 发帖为其 12 周 \"Zero to Hero\" 1:1 bug bounty 教练路径招生，称仅剩 1 个席位。帖子以 \"Real talk\" 起头，称该路径针对一直卡在随机教程里空转、迟迟不动手的读者，是促使他们动手的一次提醒，并称通过帖中链接预订可享折扣。帖子同时给出第二个链接，推荐读者查看其证书以提升简历，全篇内容属发布方自述的名额、优惠与推荐信息，标签为 #bugbounty 与 #mentorship。","[\"bugbounty\", \"mentorship\", \"bug bounty coaching\"]","[跳转原文](https://x.com/theXSSrat/status/2104550738521137374)"],[1068,"🐀 Five hosts. One breach. You're the incident responder. · x.com · theXSSrat","cybersecurity",0,"2026-09-28T09:10:35+00:00","安全账号 @theXSSrat 在 x.com 发帖推广其 Purple Team 系列课程，场景设定为「五台主机、一次入侵，你来当事件响应者」。发帖者称课程结束时参与者将亲手配置 fail2ban、拦截一名真实攻击者，并走通一条完整 kill chain：webshell → SIEM logs → SOC alerts → git history → active defense。发帖者强调该系列的产出是「用过的技能，而不只是读过的」，并附课程链接，另称也在提供 1:1 coaching 式的一对一辅导。帖文带 #purpleteam 与 #infosec 标签。","[\"purpleteam\", \"infosec\", \"x.com\"]","[跳转原文](https://x.com/theXSSrat/status/2104498996882411983)"],[1100,"微软 Win11 被曝删除照片后仍保留缩略图，实测与官方文档均不支持该说法 · aihot.news","cybersecurity",0,"2026-09-28T08:16:00+00:00","IT之家援引 Windows Latest 报道，称 X 平台流传的“Windows 暗中保存所有已删除照片缩略图”说法（即删除照片后仍保留其缩略图）被夸大，实测与官方文档均不支持该说法。报道承认 Windows 确实存在为提升浏览速度而设的缩略图缓存机制，但测试显示删除图片后缓存文件并未更新，单纯创建或复制图片也不会生成缓存条目。报道同时澄清了 USBSTOR、Wi-Fi 密码存储及剪贴板历史等常见误解，并给出清除或禁用缩略图缓存的方法；未说明测试环境与样本量。信息层级为 IT之家转述 Windows Latest 报道，属转述内容，未经独立验证。","[\"Microsoft\", \"Windows 11\", \"缩略图缓存\", \"隐私\", \"行业动态\"]","[跳转原文](https://www.ithome.com/1/007/868.htm)"],[1106,"Ever picture your own hacking playground with YOUR logo slapped all over it? 🐀🚩  · x.com · theXSSrat","cybersecurity",0,"2026-09-28T08:08:58+00:00","@theXSSrat 在 x.com 发帖推介 RatCTF 的白标 CTF 服务，称用户可搭建带有自己标识的比赛环境，包含 jeopardy challenges、真实机器与实时 leaderboard，玩家可在数分钟内开始捕获 flag。帖子给出的定价为 $20/month，含 setup，可随时取消，目标用户为大学社团、举办 hacking day 的公司及希望拥有自有赛场的社区，属发布方主张，未经独立验证。该账号同时提供 1:1 coaching，帖内附运行入口与辅导两个链接。","[\"ctf\", \"infosec\", \"网络安全\", \"白标服务\", \"x.com短讯\"]","[跳转原文](https://x.com/theXSSrat/status/2104483491505193110)"],[1461,"🔎 OSINT INVESTIGATION PLAYBOOK · x.com · DailyDarkWeb","cybersecurity",0,"2026-09-27T22:59:43+00:00","x.com 账号 @DailyDarkWeb 于 2026 年 9 月 27 日发布一条 OSINT 调查手册短讯，主张好 OSINT 不在于收集更多线索，而在于用结构、验证与严谨分析把线索转化为情报。帖子列出的工作流包括：搜索前先定义目标，从用户名、截图、域名、IP 等简单 pivot 起步，扩展到 GitHub、DNS 与历史基础设施，从截图元数据与反向图片搜索提取情报，用地理定位与社交媒体关联检验可能联系，建立时间线，并回头检查原始文档中被忽略的 pivot、比较多条证据链而非依赖单一线索。帖子强调的核心教训是 Correlation is not attribution：匹配的用户名、相似头像、同城或关联域名都只能提示联系，单独都不足以证明身份或责任。帖子附分析员注记，称强 OSINT 不是试图证明一个理论而是试图推翻它，最佳调查者会保留原件、记录每个来源、用多个独立指标交叉验证、质疑假设、寻找矛盾、构建时间线并自问「什么能证明我错了」，并以 Search less、Think more、Verify everything 收尾。","[\"OSINT\", \"ThreatIntelligence\", \"CyberSecurity\", \"OpenSourceIntelligence\", \"DigitalInvestigation\", \"Geolocation\", \"Metadata\", \"Forensics\", \"DDW\"]","[跳转原文](https://x.com/DailyDarkWeb/status/2104345269206704452)"],[1589,"Become Job-Ready in Cyber Security with Practical Labs · x.com · hackinarticles","cybersecurity",0,"2026-09-27T14:51:16+00:00","Ignite Technologies 在 x.com 发布 Ethical Hacking Proactive Training Program 招生短讯，称该课程以直播形式结合核心实操训练，面向初学者及希望强化渗透测试技能者，并称价格可负担、席位有限。发布方列出的课程清单含 16 个条目，包括 Introduction to Ethical Hacking、Old School Learning Methodology、Networking Fundamentals、Reconnaissance (Footprinting, Scanning & Enumeration)、System Hacking、Post Exploitation & Persistence、Web Server Penetration Testing、Website Hacking Techniques、Malware Threats & Analysis、Wireless Network Security、Cryptography & Steganography、Sniffing Attacks、Denial of Service (DoS)、Evading IDS, Firewalls & Honeypots、Social Engineering Techniques、Mobile Platform Security。发布方称该培训按真实攻击场景组织实操知识，开放报名链接、WhatsApp 与邮箱 info@ignitetechnologies.in 并可预约演示课；上述能力与定位均为发布方主张，未经独立验证。帖子署名 @hackinarticles。","[\"cybersecurity\", \"ethical-hacking\", \"pentesting\", \"training\", \"OSCP\"]","[跳转原文](https://x.com/hackinarticles/status/2104222345791696948)"],[1591,"🔥 OSCP isn’t about knowing more tools. · x.com · hackinarticles","cybersecurity",0,"2026-09-27T14:50:47+00:00","@hackinarticles 在 x.com 发帖推广 OSCP Training Program，帖文主张 OSCP 的关键不在掌握更多工具而在方法论：列举 Nmap、Burp、Metasploit、PrivEsc，称工具容易学，Methodology 才能通过考试。课程模块列有 Hands-on Labs、Linux 与 Windows PrivEsc、Web Pentesting、Active Directory、Pivoting & Tunneling、Exam-Style Practice、Reporting & Methodology，均为课程宣传条目。帖文称完整课程、开班详情与学费需填写表单后由其团队联系，另给出 WhatsApp、邮箱 info@ignitetechnologies.in 与报名表单链接，并多次提示 upcoming batch 名额有限、招生即将截止。","[\"OSCP\", \"CyberSecurity\", \"Pentesting\", \"EthicalHacking\", \"RedTeam\", \"OSCPTraining\"]","[跳转原文](https://x.com/hackinarticles/status/2104222224169488888)"],[1592,"Pic of the Day · x.com · hackinarticles","cybersecurity",0,"2026-09-27T14:49:59+00:00","x.com 账号 @hackinarticles 发布 \"Pic of the Day\" 短讯，配图为上下两格对话框：上格写 \"But how did the hackers escape?\"，下格回答 \"It appears they just ransomware.\"。","[\"infosec\", \"cybersecurity\", \"cybersecuritytips\", \"pentesting\", \"cybersecurityawareness\"]","[跳转原文](https://x.com/hackinarticles/status/2104222023245554007)"],[1593,"Pic of the Day · x.com · hackinarticles","cybersecurity",0,"2026-09-27T14:49:48+00:00","@hackinarticles 在 x.com 发帖称“Pic of the Day”，配图显示文字“my bed, me, 2 AM, still hacking”，右下角标有 @kidnapping，帖子附 #infosec 等标签与一个短链。","[\"infosec\", \"cybersecurity\", \"cybersecuritytips\", \"pentesting\", \"cybersecurityawareness\"]","[跳转原文](https://x.com/hackinarticles/status/2104221976625897781)"]],"truncated":false,"filtered_table_rows_count":64,"expanded_columns":[],"expandable_columns":[],"columns":["rowid","title","category","severity","created_on","summary","tags","origin_url"],"primary_keys":[],"units":{},"query":{"sql":"select rowid, title, category, severity, created_on, summary, tags, origin_url from feed","params":{"category":"cybersecurity","severity":"0"}},"facet_results":{"category":{"name":"category","type":"column","hideable":false,"toggle_url":"https://topic.fit/public-feed/feed?severity=0","results":[{"value":"misc","label":"misc","count":467,"toggle_url":"https://topic.fit/public-feed/feed?category=misc&severity=0","selected":false},{"value":"ai","label":"ai","count":275,"toggle_url":"https://topic.fit/public-feed/feed?category=ai&severity=0","selected":false},{"value":"robotics","label":"robotics","count":184,"toggle_url":"https://topic.fit/public-feed/feed?category=robotics&severity=0","selected":false},{"value":"cybersecurity","label":"cybersecurity","count":64,"toggle_url":"https://topic.fit/public-feed/feed?category=cybersecurity&severity=0","selected":true},{"value":"industry","label":"industry","count":10,"toggle_url":"https://topic.fit/public-feed/feed?category=industry&severity=0","selected":false}],"truncated":false},"severity":{"name":"severity","type":"column","hideable":false,"toggle_url":"https://topic.fit/public-feed/feed?category=cybersecurity","results":[{"value":2,"label":"2","count":448,"toggle_url":"https://topic.fit/public-feed/feed?category=cybersecurity&severity=2","selected":false},{"value":1,"label":"1","count":155,"toggle_url":"https://topic.fit/public-feed/feed?category=cybersecurity&severity=1","selected":false},{"value":3,"label":"3","count":121,"toggle_url":"https://topic.fit/public-feed/feed?category=cybersecurity&severity=3","selected":false},{"value":0,"label":"0","count":64,"toggle_url":"https://topic.fit/public-feed/feed?category=cybersecurity&severity=0","selected":true}],"truncated":false}},"suggested_facets":[{"name":"created_on","type":"date","toggle_url":"https://topic.fit/public-feed/feed?category=cybersecurity&severity=0&_facet_date=created_on"},{"name":"tags","type":"array","toggle_url":"https://topic.fit/public-feed/feed?category=cybersecurity&severity=0&_facet_array=tags"}],"next":"1593","next_url":"https://topic.fit/public-feed/feed?category=cybersecurity&severity=0&_next=1593","private":false,"allow_execute_sql":false,"query_ms":191,"source":"本地采集管线定期导出的快照"}