Blogs

BlogsSharePoint CVE-2026-50522 / CVE-2026-58644 Teardown: Pwn2Own-Demonstrated Deserialization-to-RCE and the Authentication-Bypass Chain That Makes It Pre-AuthThree CVSS 9+ SharePoint flaws from Pwn2Own Berlin - two deserialization RCEs and a JWT bypass - combine into a pre-auth kill…Jul 20, 2026 · 18 min readRead →BlogsHelloNet Exposed: Reversing the APT That Weaponized ViPNet’s Trusted Update ChannelHelloNet abused ViPNet's signed updater to sideload a modular implant chain into svchost.exe - no new service, no run key, just a…Jul 20, 2026 · 19 min readRead →BlogsCVE-2026-56190 Anatomy: Uninitialized-Resource RCE in Windows RDP – Pre-Auth Memory Corruption to Remote Code Execution Without a Single Packet of AuthenticationCVE-2026-56190 is a CVSS 9.8 pre-authentication RCE in the Windows RDP server caused by an uninitialized-resource flaw in termsrv.dll. Learn how the…Jul 20, 2026 · 18 min readRead →BlogsLegacyHive Exposed: Dissecting Chaotic Eclipse’s Unpatched Windows Registry Hive-Loading Zero-Day and the Adversarial Pattern Behind Nine Back-to-Back Uncoordinated DisclosuresLegacyHive is an unpatched Windows privilege escalation zero-day abusing a deterministic TOCTOU race in ProfSvc to redirect hive loads via Object Manager…Jul 17, 2026 · 16 min readRead →BlogsPolinRider: North Korea’s 108-Package Open-Source Supply Chain Campaign DissectedPolinRider compromised 108 packages and 1,951 GitHub repos using VS Code auto-run task hijacking, blockchain dead-drop C2, and expired-domain account takeover to…Jul 13, 2026 · 17 min readRead →BlogsUAT-7810 / LapDogs ORB Network Dissected: LONGLEASH Malware, Internet-Facing Device Compromise, and the Architecture of China’s Operational Relay Box EcosystemUAT-7810's LapDogs ORB network weaponizes unpatched Ruckus access points using LONGLEASH, a purpose-built intermediate C2 relay implant. This deep dive covers binary…Jul 12, 2026 · 18 min readRead →BlogsJADEPUFFER Dissected: Inside the World’s First Confirmed Fully-Agentic Ransomware Attack – Langflow RCE, LLM-Driven Lateral Movement, and What It Means for DefendersJADEPUFFER is the first confirmed fully-agentic ransomware attack - an LLM ran recon, credential theft, lateral movement, and encryption with no human…Jul 10, 2026 · 17 min readRead →BlogsCVE-2026-43499 “GhostLock” + IonStack Full-Chain Teardown: Futex Requeue-PI Stack Use-After-Free to Root and Container EscapeCVE-2026-43499 'GhostLock' turns a one-word logic error in Linux's PI futex code into a stack use-after-free, root escalation, and full container escape…Jul 8, 2026 · 20 min readRead →BlogsCVE-2026-43456: Dissecting the 19-Year Linux Kernel Bonding Driver Type Confusion That Achieves Root in Under One SecondA 2007 pointer copy in the Linux bonding driver enables a type confusion exploit that chains 329 GRE interfaces to achieve deterministic…Jul 6, 2026 · 21 min readRead →BlogsChocoPoC RAT: How Attackers Are Weaponizing the Researcher ToolchainChocoPoC RAT precision-targets vulnerability researchers through trojanized GitHub PoC repos, hiding payloads in transitive PyPI dependencies and using Mapbox datasets as a…Jul 6, 2026 · 16 min readRead →BlogsAvalon Malware Framework Internals: ISO-Lnk Delivery, MSBuild Abuse, ETW Tampering, and the CrownX Ransomware EndgameA deep technical teardown of the Avalon malware framework: how it chains ISO-LNK delivery, MSBuild LOLBin abuse, and usermode ETW patching to…Jul 6, 2026 · 21 min readRead →BlogsCVE-2026-46242 “Bad Epoll” Anatomy: Linux Kernel Use-After-Free from Unprivileged User to Root, and Why Anthropic’s Mythos AI Missed the Bug It NeighborsBad Epoll (CVE-2026-46242) exploits a race between ep_remove_file() and __fput() to achieve a use-after-free write in kmalloc-192, escalating any unprivileged user to…Jul 6, 2026 · 21 min readRead →