Reverse Engineering547 CVE-2026-58532: An Integer Overflow in Windows tcpip.sys
A user-controlled 64-bit record count multiplied by the 0x228 record size wraps to zero in the Windows tcpip.sys WFP ALE deserialiser, defeating…
Reverse Engineering547 A user-controlled 64-bit record count multiplied by the 0x228 record size wraps to zero in the Windows tcpip.sys WFP ALE deserialiser, defeating…
Privilege Escalation395 Cisco Talos disclosed CVE-2026-58613, a kernel use-after-free in cldflt.sys — the Windows Cloud Files Mini Filter Driver behind OneDrive Files On-Demand. An…
EDR Evasion397 Direct $MFT parsing walks the on-disk NTFS Master File Table through a raw volume handle, producing a full inventory of files, deleted…
Exploit Development1.1k CVE-2026-58635 is a CWE-77 command injection in the Windows Narrator Braille (BRLTTY/BrlAPI) component: a standard user writes globally-writable parameter 29 with an…
AI Security Research449 Anthropic's Frontier Red Team showed Claude Opus 4.6 building a working browser exploit for CVE-2026-2796, a type-confusion bug in Firefox's SpiderMonkey WebAssembly…
Exploit Development636 Nightmare-Eclipse's LegacyHive is an unpatched Windows privilege-escalation flaw: a standard user coerces the SYSTEM-level User Profile Service into loading another user's registry…
Hardware292 Runic Labs dissects a QNAP QTS disclosure cycle — four bugs across three plugins (Notes Station 3, QmailAgent, QVPN) — and shows…
Full technical writeup of two critical unauthenticated RCEs in Unitree Go2 robots (V1.1.7-V1.1.11): CVE-2026-27509 DDS-based RCE and CVE-2026-27510 mobile database tampering, with…
Security Patches251 Dustin Childs reviews the July 2026 security patch cycle, covering 88 Adobe CVEs and a record-breaking 621 Microsoft vulnerabilities, including critical RCEs…
Secure Boot295 ESET research reveals 11 old, Microsoft-signed UEFI shim bootloaders (versions 0.9 and below) that can bypass UEFI Secure Boot on any UEFI…
Exploit Development302 A novel technique combining thread pool execution, enum callback trampolining, and indirect syscalls to produce fully legitimate call stacks during syscall execution,…
buffer overflow266 A two-bug nginx 1.30.0 chain: CVE-2026-42945 (Rift) heap overflow + CVE-2026-9256 (PoolSlip) heap over-read combine into an ASLR-independent remote system() call at…