HD Moore
hdm.io
HD Moore
@hdm.io
runZero & Metasploit
Hello Austin Gophers! This month's ATX Golang meetup is *tonight* September 9th, at STATION Austin, from 6:30-8:30. Note that we'll be downstairs (first floor) in Wall-E instead of Antones (16th) tonight. www.meetup.com/atxgolang/ev...
ATX Golang Meetup - September 2026, Wed, Sep 9, 2026, 6:30 PM | Meetup
***UPDATE FOR SEPTEMBER 2026*** For our meetup on September 9th, 2026, we will be meeting in the Wall-E room on the first floor of STATION Austin instead of the usual Anton
www.meetup.com
September 9, 2026 at 8:57 PM
The best part of BSidesLV/BlackHat/DEFCON is getting to meet the people you admire. I got a chance to nerd out with Thai Duong of calif.io today (photo proof!). Thai and team just posted their latest work - 3 remote exploits in FreeBSD:

blog.calif.io/p/the-taking...
August 6, 2026 at 9:51 PM
Reposted by HD Moore
BMCs make such good targets because they live in the org gap nobody owns. not quite the server team, not the network team, not security, so they sit on firmware nobody has touched in years. the access is almost a side effect of the ownership hole.
August 6, 2026 at 6:36 AM
Hello Las Vegas (and hackers following along at home)! I'm excited to share the first batch of our Out-of-Band / Baseboard Management Controller research at Black Hat USA today and DEFCON 34 this weekend. Read an exclusive by Ars Technica at:

arstechnica.com/security/202...
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
Baseboard management controllers from the world's biggest manufacturers are a security mess.
arstechnica.com
August 6, 2026 at 12:53 AM
Skipping Black Hat and DEFCON this year? Consider presenting at BSides Hanoi instead. Now in its second year, the conference takes place on August 5th, 2026, and a few more talk slots are still open - but the submission deadline is today. Apply here: www.bsideshanoi.net/en/call-for-...
Call for Paper - BSides Hanoi 2026
Submit your proposal for BSides Hanoi 2026 NoHuman.
buff.ly
June 30, 2026 at 3:56 AM
Reposted by HD Moore
We know vulnerability reports are not like ordinary issues. But why? It comes down to needing the scarce insight and temporary confidentiality to protect users.

However, now that LLMs can find more or less the same bugs for everyone, none of that matters, and vuln reports are not special anymore.
Vulnerability Reports Are Not Special Anymore
We needed the insight and confidentiality to protect our users, but now that anyone can get the same results from LLM?
words.filippo.io
June 23, 2026 at 1:17 PM
My favorite bugs are where the vendor doesn't consider it a vulnerability: How a USB-connected speaker can infect a PC without ever being touched: arstechnica.com/security/202...
How a USB-connected speaker can infect a PC without ever being touched
Seller of the Sound Blaster Katana V2X doesn't consider the behavior a vulnerability.
arstechnica.com
June 5, 2026 at 11:14 PM
ATX Go is TONIGHT (a week early this month):

Hey gophers! Join us Wednesday (May 6th, today), 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: 🍕 pizza, 🍻 beer, and a few short talks on Go.

www.meetup.com/atxgolang/ev...
ATX Golang Meetup - May 2026 (RESCHEDULED), Wed, May 6, 2026, 6:30 PM | Meetup
Join us for an evening of information, networking, friendship, beer, and pizza! You are invited to come discuss our favorite programming language and meet other Go develope
www.meetup.com
May 6, 2026 at 6:50 PM
ATX Go is a week early this month, tomorrow night!

Hey gophers! Join us Wednesday, 6:30–8:30pm at Station Austin (ie. Capital Factory) 16th floor, in "Antones" for our monthly meetup. You know the drill: 🍕 pizza, 🍻 beer, and a few short talks on Go:

www.meetup.com/atxgolang/ev...
ATX Golang Meetup - May 2026 (RESCHEDULED), Wed, May 6, 2026, 6:30 PM | Meetup
Join us for an evening of information, networking, friendship, beer, and pizza! You are invited to come discuss our favorite programming language and meet other Go develope
www.meetup.com
May 6, 2026 at 1:37 AM
Reposted by HD Moore
🚨 New runZero 4.9: We got you, defenders!

📈 Interactive attack path mapping
👁️ Multi-homed detection
🗺️ 2D/3D topology maps
🧠 Deep OT intel + field-level discovery
✅ Protocol exposures
🔥 Risk prioritization
💻 UI/UX enhancements

👉️ Release details at: www.runzero.com/blog/runzero...

#OTsecurity
April 30, 2026 at 1:34 PM
Tom Ptacek posted a great writeup titled "Vulnerability Research Is Cooked", covering the state of vulndev and its rapidly accelerating future:
sockpuppet.org/blog/2026/03...
Vulnerability Research Is Cooked — Quarrelsome
For the last two years, technologists have ominously predicted that AI coding agents will be responsible for a deluge of security vulnerabilities. They were right! Just, not for the reasons they…
sockpuppet.org
March 30, 2026 at 6:26 PM
Reposted by HD Moore
Up next on #runZeroDay at 12:30 PM PT – Force multiplied: Community-powered vuln detection.

Our guest is Rishiraj Sharma from ProjectDiscovery.

Don’t miss a minute!

Watch it live at: www.runzero.com/rsac-live-20...
March 25, 2026 at 7:15 PM
Joseph Menn, renowned journalist & author of "The Cult of the Dead Cow," joins us for a special book signing event at RSAC! runZero and Mallory are thrilled to co-host a private book signing with renowned investigative journalist Joseph Menn during RSA:

www.runzero.com/joseph-menn-...
Joseph Menn Book Signing
Complete security visibility across IT, OT, IoT, cloud, mobile, and remote assets.
www.runzero.com
March 23, 2026 at 8:45 PM
Join author Caroline Wong for the release of "The AI Cybersecurity Handbook" at RSAC! runZero and Mallory are thrilled to co-host a private book signing with the AI cybersecurity strategist Caroline Wong during RSA Conference 2026!

www.runzero.com/caroline-won...
Caroline Wong Book Signing
Complete security visibility across IT, OT, IoT, cloud, mobile, and remote assets.
www.runzero.com
March 23, 2026 at 7:29 PM
Reposted by HD Moore
#RSAC session today at 10:50 AM PT – Preparing for AI Vulnerability Exploitation: Preventing Cataclysm.

👀 Don’t miss this panel featuring @runzero.com’s CEO @hdm.io, @argv.bsky.social (Google), and @gadievron.bsky.social (Knostic).

🗓️ TODAY at 10:50 AM PT
March 23, 2026 at 4:30 PM
Reposted by HD Moore
AI vulnerability discovery is here. Don’t miss the #RSAC 2026 session-Preparing for AI Vulnerability Exploitation: Preventing Cataclysm-featuring our CEO @hdm.io, Google’s @argv.bsky.social & Knostic’s @gadievron.bsky.social.

🗓️ Mon, Mar 23 @ 10:50 AM PT
path.rsaconference.com/flow/rsac/us...
March 18, 2026 at 7:24 PM
runZero Hour 0x1C is live NOW: www.youtube.com/live/EF633eU...
March 18, 2026 at 5:12 PM
"The @phrack CFP with demoscene cracktro is live. Turn up the volume and enjoy the awesome stylings of @PiotrBania with some hopefully inspiring text from phrack staff :)" phrack.org (via @richinseattle)
PHRACK CALL FOR PAPERS
phrack.org
March 7, 2026 at 6:11 PM
Reposted by HD Moore
The Phrack Staff is on the latest episode of the DarknetDiaries episode!

darknetdiaries.com/episode/170/
Phrack – Darknet Diaries
Phrack is legendary. It is the oldest, and arguably the most prestigious, underground hacking magazine in the world. It started in 1985 and is still running today. In this episode we interview the Phr...
darknetdiaries.com
February 4, 2026 at 10:07 PM
Reposted by HD Moore
Huh -- this week, the FBI uploaded 35 pages on Phrack to its FOIA Library vault.fbi.gov/phrack/phrac...
Phrack (Final)
vault.fbi.gov
February 26, 2026 at 5:05 PM
Reposted by HD Moore
I spy a Phrack gnome in the latest FIRE #ansi pack! Thanks @nail7.bsky.social, it's so cool!
March 4, 2026 at 5:35 AM
New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises: arstechnica.com/security/202...

AirSnitch resets WiFi security back to the bad-old-days of ARP spoofing and trivial MITM.
New AirSnitch attack breaks Wi-Fi encryption in homes, offices, and enterprises
That guest network you set up for your neighbors may not be as secure as you think.
arstechnica.com
February 26, 2026 at 5:26 PM
Hello Austin Go hackers! Tonight (2026-02-11) is our next ATX Golang meetup, located in Station Austin (aka Capital Factory ). We will have pizza, drinks, and various short talks and discussions related to the Go ecosystem: www.meetup.com/atxgolang/ev...
ATX Golang Meetup - February 2026, Wed, Feb 11, 2026, 6:30 PM | Meetup
Join us for an evening of information, networking, friendship, beer, and pizza! You are invited to come discuss our favorite programming language and meet other Go develope
www.meetup.com
February 11, 2026 at 6:37 PM
runZero users get a new feature today (including Community Edition) - recurring internet speed tests for all deployed Explorers! This (very optional) capability lets you identify backhaul/connectivity issues for sites that you can't physically get to: www.runzero.com/blog/interne...
Run Internet speed tests from runZero Explorers
Get an early signal into usability before you scan. Measure internet connectivity via runZero Explorers to remove uncertainty, with audit logs included.
www.runzero.com
February 3, 2026 at 4:20 PM