Exploit Development221 KERAT: Static Detection of Kernel TOCTOU Bugs Caused by Races
USENIX Security 2026: KERAT mines atomicity rules for check-use pairs on Linux and FreeBSD shared fields, then FSM-walks LLVM IR. 351 real…
Quarkslab shows Android hardware attestation end to end, then a Frida relay: a clean phone signs the backend nonce, the rooted analysis phone presents that genuine chain. Fix: check attestationApplicationId after Verified boot state.
Exploit Development221 USENIX Security 2026: KERAT mines atomicity rules for check-use pairs on Linux and FreeBSD shared fields, then FSM-walks LLVM IR. 351 real…
Active Directory159 Hope Walker's SpecterOps sequel to manual LDAP querying: OR parentheses that lie, nested Domain Admins, Kerberoastable SPNs, userAccountControl sticker-math, passwords in schema…
Active Directory128 When BloodHound and PowerView will not load, Active Directory is still a phone book. Hope Walker's SpecterOps lab shows how to query…
Cisco192 Aaron Thacker jailbroke a Cisco C195 ESA by splicing a newer BIOS so CIMC came online, exploiting command injection in expRemoteFwUpdate (CVE-2024-20356)…
iOS Security166 Yuval Hanoch Hirschenbein Sadde traced a DEF CON 34 demo crash to one character in XNU: unp_ino++ assigns inode 0 to the…
Defender195 On 8–9 September 2026 Nightmare Eclipse published ShieldCrash, a skeleton proof of concept that Microsoft's September engine update for ShieldBreak (CVE-2026-69414) closed…
Authentication & Access Control196 Rapid7 researchers discovered two critical authentication bypass vulnerabilities in N-able N-Central RMM platform. When chained together, CVE-2026-86206 and CVE-2026-86207 allow unauthenticated attackers…
Android203 A critical SQL injection vulnerability in Android 17's ContactsProvider allows apps using the system contact picker to exfiltrate all contacts on a…
Active Directory370 Demonstrate a sophisticated privilege escalation technique exploiting Windows IIS AppPool identity elevation to obtain machine account certificates from AD CS, leading to…
Virtualization256 Comprehensive security analysis of SIM-originating AT commands via the RUN AT proactive command in cellular devices, including the CATANA toolkit, device survey,…
Virtualization624 An unauthenticated authentication bypass in Proxmox VE 7.0–8.0.3 allows attackers to mint a full root@pam ticket with a single HTTP request. The…
Linux239 How Singularity rootkit bypasses Elastic Defend 9.5's enhanced module load detection through source obfuscation, BPF hook manipulation, and exploitation of trusted process…