Eduardo P. Sánchez (@darkslaker) 's Twitter Profile
Eduardo P. Sánchez

@darkslaker

@bishopfox Regional Director | Gamer, computer cyber sec enthusiast | Mex4’s | @bsidescdmx | Ex- @Lyft | Ex-@Scitum_Mx | @lasalle_mx | Tweets are by my own

ID: 18522563

linkhttps://linktr.ee/darkslaker calendar_today01-01-2009 03:34:30

2,2K Tweet

1,1K Followers

1,1K Following

Eduardo P. Sánchez (@darkslaker) 's Twitter Profile Photo

AI is changing the game—for attackers and defenders. Rob Ragan joins a Dark Reading panel to talk deepfakes, agentic AI, and what security teams need to do next. #AI #cybersecurity #genAI Watch the full interview: bfx.social/3YlGbau

BSides CDMX (@bsidescdmx) 's Twitter Profile Photo

¡Semana y media para cerrar #cfp de #bsidescdmx25 ! Si no han metido su propuesta corran que el tiempo se acaba. sessionize.com/bsidescdmx25

¡Semana y media para cerrar #cfp de #bsidescdmx25 ! Si no han metido su propuesta corran que el tiempo se acaba.

sessionize.com/bsidescdmx25
Eduardo P. Sánchez (@darkslaker) 's Twitter Profile Photo

Can Rust Language outpace C in malware development? Bishop Fox consultant Nick Cerne joins CyberWire Daily, by N2K’s Research Saturday to explore Rust’s stealth advantages, OPSEC tradeoffs, and red team value. Listen: bfx.social/4kp0oVv

Eduardo P. Sánchez (@darkslaker) 's Twitter Profile Photo

The one and only TomNomNom’s keynoting NahamCon tomorrow! His talk "Good Vibes Only: Should You Still Learn to Code?" gets into what it really takes to grow as a hacker today. Definitely worth checking out if you’re into red teaming or bug bounties. bfx.social/43oCq5M

The one and only <a href="/TomNomNom/">TomNomNom</a>’s keynoting NahamCon tomorrow!
His talk "Good Vibes Only: Should You Still Learn to Code?" gets into what it really takes to grow as a hacker today.
Definitely worth checking out if you’re into red teaming or bug bounties.

bfx.social/43oCq5M
Eduardo P. Sánchez (@darkslaker) 's Twitter Profile Photo

Really excited for this one. Brandon Kovacs is discussing how red teamers are attacking and defending against deepfakes. Super relevant with how fast AI threats are evolving. Should be a great session. Come hang out on May 21! bfx.social/4ji6JB4

Really excited for this one. <a href="/brandonkovacs/">Brandon Kovacs</a> is discussing how red teamers are attacking and defending against deepfakes.
Super relevant with how fast AI threats are evolving. Should be a great session.
Come hang out on May 21!
bfx.social/4ji6JB4
Eduardo P. Sánchez (@darkslaker) 's Twitter Profile Photo

Tools don’t make the hacker, but they can make the job faster, stealthier, and way more effective. These are the C2s our Red Teamers reach for. Featuring open-source tools by Moloch, Ronan Kervella, Cody Thomas, and Russel Van Tuyl. Take a look: bfx.social/404p65C

Tools don’t make the hacker, but they can make the job faster, stealthier, and way more effective. These are the C2s our Red Teamers reach for. Featuring 
open-source tools by <a href="/LittleJoeTables/">Moloch</a>, Ronan Kervella, <a href="/its_a_feature_/">Cody Thomas</a>, and <a href="/Ne0nd0g/">Russel Van Tuyl</a>.
Take a look: bfx.social/404p65C
Eduardo P. Sánchez (@darkslaker) 's Twitter Profile Photo

Want a peek into what our red team really uses on engagements? This breakdown hits on some of the tools we rely on to get the job done stealthily. Some familiar names, some underrated gems: bfx.social/4lyUoKv bfx.social/3FXi7Vs

Want a peek into what our red team really uses on engagements?
This breakdown hits on some of the tools we rely on to get the job done stealthily.
Some familiar names, some underrated gems: bfx.social/4lyUoKv bfx.social/3FXi7Vs
BSides CDMX (@bsidescdmx) 's Twitter Profile Photo

¡Gracias por ser parte de esta increíble edición de #BSidesCDMX ! Nos emociona seguir creciendo junto a esta comunidad 💙 🎥 Ya puedes ver las charlas en nuestro YouTube: youtube.com/@bsidescdmx?si… 📸 Y revivir los mejores momentos con las fotos oficiales: securitybsidescdmx.pixieset.com/bsidescdmx25/

Eduardo P. Sánchez (@darkslaker) 's Twitter Profile Photo

Cloud enumeration can eat up your whole day. Spend ~60 minutes with us and we’ll fix that. Live Discord workshop with Mitchell Sperling on CloudFox - Aug 21. Aug 21 | 2pm EST | bfx.social/45L6vOc

Cloud enumeration can eat up your whole day.
Spend ~60 minutes with us and we’ll fix that.

Live Discord workshop with Mitchell Sperling on CloudFox - Aug 21.

Aug 21 | 2pm EST | bfx.social/45L6vOc
Eduardo P. Sánchez (@darkslaker) 's Twitter Profile Photo

Giving AI control over infrastructure isn’t sci-fi anymore. Vinnie Liu, Nathan Case (TPO Group), and Zach Moreno on OpenClaw / MoltBot, early-stage AI tooling, and why basic security hygiene still matters especially now. From this week's Initial Access: bfx.social/3OgckOm

Eduardo P. Sánchez (@darkslaker) 's Twitter Profile Photo

AI risk is very different from traditional software risk. For starters: No CVE-style ecosystem. Infinite input space. Major supply chain blind spots. Kris Kimmerle of RealPage from our recent AI & Security Risk cyber leadership panel: (Full write up: bfx.social/3OyqZoo)

AI risk is very different from traditional software risk.

For starters:
No CVE-style ecosystem.
Infinite input space.
Major supply chain blind spots.

<a href="/KrisKimmerle/">Kris Kimmerle</a> of <a href="/RealPage/">RealPage</a> from our recent AI &amp; Security Risk cyber leadership panel:

(Full write up: bfx.social/3OyqZoo)
Bishop Fox (@bishopfox) 's Twitter Profile Photo

Moving from Electron to frameworks like Tauri doesn’t necessarily eliminate risk, but it does change the mechanics of exploitation. New Bishop Fox research shows how XSS & permissive configuration can still lead to RCE in desktop apps. Full scoop: bfx.social/4cHVl1R

Moving from Electron to frameworks like Tauri doesn’t necessarily eliminate risk, but it does change the mechanics of exploitation.

New Bishop Fox research shows how XSS &amp; permissive configuration can still lead to RCE in desktop apps.

Full scoop: bfx.social/4cHVl1R
Eduardo P. Sánchez (@darkslaker) 's Twitter Profile Photo

strongSwan EAP-TTLS integer underflow allows unauthenticated DoS of VPN servers • Impacts 15+ years of versions • Low-effort exploitation • Sometimes requires just 2 connections Upgrade to 6.0.5 or disable EAP-TTLS Details & testing tool: bfx.social/48aqwiY

strongSwan EAP-TTLS integer underflow allows unauthenticated DoS of VPN servers

• Impacts 15+ years of versions
• Low-effort exploitation
• Sometimes requires just 2 connections

Upgrade to 6.0.5 or disable EAP-TTLS

Details &amp; testing tool: bfx.social/48aqwiY
Eduardo P. Sánchez (@darkslaker) 's Twitter Profile Photo

We’re launching a new open-source tool on March 31: Cirro To walk through it, we’re hosting a 2-part workshop on: • Mapping Attack Paths in Azure • Schemas and Extensible Identity Graphs Register once for both sessions: bfx.social/4dfaqZ2

We’re launching a new open-source tool on March 31: Cirro

To walk through it, we’re hosting a 2-part workshop on:

• Mapping Attack Paths in Azure
• Schemas and Extensible Identity Graphs

Register once for both sessions: bfx.social/4dfaqZ2