WarthogTK
banner
warthogtk.bsky.social
WarthogTK
@warthogtk.bsky.social
Pentester | Ex MD (Intensivist & Healthcare Simulation) | (Black) Arch Enthusiast |
Infosec - AD - Windows Internals/Maldev enthusiast |
Geopolitics, Defense, Disinformation, Hybrid warfare | DCS, Gaming, Metal
(OU=FR,DC=WORLD,DC=UNIVERSE)
Notepad-Plus Fuss: Notepad++ Supply Chain Attack Analysis

www.levelblue.com/blogs/spider...
Notepad-Plus Fuss: Notepad++ Supply Chain Attack Analysis
LevelBlue SpiderLabs’ Cyber Threat Intelligence Team investigated the ongoing supply-chain compromise affecting Notepad++, a widely used open-source text editor.
www.levelblue.com
February 10, 2026 at 9:04 PM
HVCK
Created with the Heyzine flipbook maker
heyzine.com
February 10, 2026 at 7:34 PM
Prompt injection in Google Translate reveals base model behaviors behind task-specific fine-tuning
www.lesswrong.com/posts/tAh2ke...
Prompt injection in Google Translate reveals base model behaviors behind task-specific fine-tuning — LessWrong
tl;dr Argumate on Tumblr found you can sometimes access the base model behind Google Translate via prompt injection. The result replicates for me, an…
www.lesswrong.com
February 8, 2026 at 9:03 AM
L'enfer des prisons israéliennes | ARTE
YouTube video by ARTE
youtu.be
February 8, 2026 at 8:56 AM
Méthodologie d’intrusion dans les systèmes d’IA : Attaquer l’apprentissage machine de bout-en-bout, de la source au service

aet1us.github.io/article_ia
Méthodologie d’attaques sur IA
ENGLISH version Auteur: Jules BADER, penetration tester et auditeur cyber au Cyslab de CGI Business Consulting France.
aet1us.github.io
February 7, 2026 at 10:23 AM
Introducing Augustus: Open Source LLM Prompt Injection Tool

www.praetorian.com/blog/introdu...
Introducing Augustus: Open Source LLM Prompt Injection Tool
Explore LLM fingerprinting and its role in exposing vulnerable Ollama servers online to unauthorized access risks.
www.praetorian.com
February 7, 2026 at 9:58 AM
A CTF-Style XSS Chain in the Wild: DOM Clobbering, Gadgets, and CSP Bypass · antoniusblock

blog.antoniusblock.net/posts/dom-cl...
A CTF-Style XSS Chain in the Wild: DOM Clobbering, Gadgets, and CSP Bypass
A bug bounty target that unexpectedly felt like a CTF. What began as simple recon turned into a nice chain of discoveries that ultimately led to a valid XSS
blog.antoniusblock.net
February 6, 2026 at 8:03 PM
The Notepad++ supply chain attack – unnoticed execution chains and new IoCs securelist.com/notepad-supp...
The Notepad++ supply chain attack – unnoticed execution chains and new IoCs
Kaspersky GReAT experts discovered previously undocumented infection chains used in the Notepad++ supply chain attacks. The article provides new IoCs related to those incidents which employ DLL…
securelist.com
February 3, 2026 at 10:35 AM
Reposted by WarthogTK
In our latest article, @niozow.bsky.social dives into the inner workings of #Windows access tokens, privileges and logon rights.
As these rights often constitute a blind spot for AD enumeration tools, the article describes our PRs to integrate them into BloodHound ⬇️
www.synacktiv.com/en/publicati...
Beyond ACLs: Mapping Windows Privilege Escalation Paths with
Beyond ACLs: Mapping Windows Privilege Escalation Paths with
www.synacktiv.com
February 2, 2026 at 3:30 PM
Exploiting PostMessage vulnerabilities: A complete guide

www.intigriti.com/researchers/...
A Tiny Privilege Escalation by Abusing Dangling Templates
Hello, friends!
www.intigriti.com
February 1, 2026 at 7:21 PM
A Tiny Privilege Escalation by Abusing Dangling Templates

jakehildreth.github.io/blog/2026/01...
A Tiny Privilege Escalation by Abusing Dangling Templates
Hello, friends!
jakehildreth.github.io
January 31, 2026 at 9:28 PM
Shadow Directories: A Unique Method to Hijack WordPress Permalinks
blog.sucuri.net/2026/01/shad...
Shadow Directories: A Unique Method to Hijack WordPress Permalinks
A new WordPress malware technique uses fake directories to override permalinks and serve spam to search engines. Learn the signs and fixes.
blog.sucuri.net
January 31, 2026 at 11:45 AM
Rafale C F3R ? 👀

youtube.com/watch?v=Likr...
DCS 2026 AND BEYOND
YouTube video by Eagle Dynamics: Digital Combat Simulator
youtube.com
January 31, 2026 at 10:47 AM
Rafale C F3R ? 👀

youtube.com/watch?v=Likr...
DCS 2026 AND BEYOND
YouTube video by Eagle Dynamics: Digital Combat Simulator
youtube.com
January 31, 2026 at 10:39 AM