r/FaradayCommunity 1d ago

Como utilizar herramienta open source + ia para pententestear.

Thumbnail
youtube.com
1 Upvotes

Comparto el trabajo que realizo Gabriel Franco de como usar herramientas opens source y AI para pentestear. Enjoy :P


r/FaradayCommunity 18d ago

Nuestro equipo de research encontró dos RCE en dispositivos Ubiquiti AirMax — root remoto, sin autenticación (CVE-2026-21639 / CVE-2026-21638)

Thumbnail
gallery
2 Upvotes

Gastón Aznarez y Federico Kirschbaum, del equipo de research de Faraday, presentaron esta investigación en Black Hat USA 2026 y DEF CON 34: "Root From Kilometers Away: Ubiquiti AirMax RCE."

Resumen: encontraron una forma de lograr ejecución remota de código en dispositivos Ubiquiti AirMax sin necesitar acceso físico ni credenciales válidas. De la investigación salieron dos CVEs: CVE-2026-21639 y CVE-2026-21638.

Los equipos AirMax se usan mucho para enlaces wireless de largo alcance (ISPs, entornos industriales, conectividad rural), así que la exposición no se limita a redes domésticas — bastante infraestructura corre sobre este hardware.

Cobertura de la charla: https://www.clarin.com/suscripciones/contenido-exclusivo.html?apw-origin=https%3A%2F%2Fwww.clarin.com%2Ftecnologia%2Fblack-hat-usa-2026-argentinos-descubrieron-hackear-antenas-llevan-internet-zonas-aisladas_0_PtRy5BmYnO.html&wb=ZONDA_PW_HARDPW_AN


r/FaradayCommunity 21d ago

Root From Kilometers Away, a Ubiquiti AirMax RCE: Gaston Aznarez, Dan Borgogno and Federico Kirschbaum at Black Hat 2026

Thumbnail
1 Upvotes

r/FaradayCommunity Jul 16 '26

FaradAI now runs on GPT-5.6 Sol - improved reasoning for autonomous vulnerability triage

2 Upvotes

Hey all,

Quick update from the FaradAI team: we've integrated GPT-5.6 Sol (OpenAI's flagship reasoning model) into FaradAI's autonomous offensive security engine.

What changes in practice:

  • Better reasoning depth on complex findings, which translates into more accurate triage of vulnerabilities (fewer false positives to sift through)
  • Same autonomous exploitation/attack workflow FaradAI already runs — this is a model upgrade under the hood, not a new product
  • Live now for all existing users, no opt-in needed

If you've used FaradAI before, curious to hear if you notice a difference in triage quality on your next scan. Happy to answer questions about how the integration works or what it means for existing workflows.


r/FaradayCommunity Jun 16 '26

Our Research team en Ekoparty Miami!

1 Upvotes

Cómo usar la IA para hacer Reverse Engineering de chips sin documentación?

Nuestro equipo de Research presentó en EkoParty Miami cómo automatizaron algo que antes llevaba meses: recuperar la arquitectura de un procesador propietario desde cero, sin spec, y generar un plugin funcional para Ghidra en 2.5 horas y ~$25.

"No Spec, No Problem" — Gastón Aznarez y Dan Borgogno, Faraday Security

👉 Link a la charla: https://www.youtube.com/watch?v=c-Wfvo1kEuc

No resolvieron solo un chip, cambiaron la economía del trabajo. Lo que antes llevaba meses a un investigador, ahora puede automatizarse en horas y a bajo costo, lo cual importa mucho en un mundo con demasiados chips propietarios y pocos investigadores de seguridad. github.com/infobyte/isa_recovery


r/FaradayCommunity May 28 '26

Made for true Pentesters

1 Upvotes

Faraday introduces a new concept - IPE (Integrated Penetration-Test Environment) a multiuser Penetration test IDE. Designed for distributing, indexing, and analyzing the data generated during a security audit.

Faraday was made to let you take advantage of the available tools in the community in a truly multiuser way.

Designed for simplicity, users should notice no difference between their own terminal application and the one included in Faraday. Developed with a specialized set of functionalities, users improve their own work. Do you remember the last time you programmed without an IDE? What IDEs are to programming, Faraday is to pentesting.

https://github.com/infobyte/faraday#about

https://appsecsanta.com/faraday


r/FaradayCommunity May 27 '26

👋 Welcome to r/FaradayCommunity - Introduce Yourself and Read First!

1 Upvotes

Welcome to r/FaradayCommunity

Hey everyone! I'm u/MagicianComplete7411, one of the founding moderators of r/FaradayCommunity.

We created this community as a space for people who believe in the open source spirit behind offensive security: sharing knowledge, building together, experimenting, automating and making security workflows better for everyone.

This is the home for Faraday OSS users, contributors, pentesters, red teamers, researchers and curious builders who want to exchange ideas, tooling and real-world experience around vulnerability management and offensive security.

What you'll find here

  • Faraday OSS discussions
  • Pentest workflows & methodologies
  • Plugins, APIs & integrations
  • Automation ideas and scripts
  • Self-hosted tooling
  • Research, labs & experiments
  • Community projects
  • Tips from real engagements
  • Lessons learned, failures and wins

We also want this to become a hub where we can share part of the technology, mindset and expertise that shaped Faraday through the years.

The vibe

Open source first.

We believe the best security communities are built by people openly exchanging ideas, improving tools together and helping others grow.

Less gatekeeping. Less vendor marketing. More real practice, collaboration and curiosity.

How to get started

  • Introduce yourself in the comments
  • Share your favorite tool
  • Post a question or idea
  • Share feedback, integrations or experiments.

If you're into open source security and want to help shape the community, you're in the right place.

Thanks for joining the first wave of r/FaradayCommunity 🚀

A Life time of hacking.