Escalation10 Backup to SYSTEM: Exploiting the IDrive Client Privilege Escalation Flaw
CVE-2026-1995 is a privilege escalation flaw in the IDrive Windows backup client. Weak file permissions allow low-privileged users to modify service arguments…
Escalation10 CVE-2026-1995 is a privilege escalation flaw in the IDrive Windows backup client. Weak file permissions allow low-privileged users to modify service arguments…
BIOS9 The article shows how modifying UEFI firmware at the flash level can disable BIOS security features even when the interface is locked,…
EDR4 The article presents T(ROP)H, a process injection technique that hijacks threads and uses a ROP chain to load a DLL without allocating…
Active Directory8 he article demonstrates an NTLM relay attack against Active Directory using tools like ntlmrelayx and PetitPotam. By relaying authentication to LDAP, attackers…
Active Directory6 The article explains how Windows DNS conditional forwarders interact with recursion. It shows that recursion settings can be overridden per zone and…
Exploit Development8 The article introduces the Out-of-Cancel vulnerability class in the Linux kernel, where workqueue cancellation APIs fail to guarantee object lifetime. This race…
Active Directory8 The article explains how flat enterprise networks enable easy lateral movement and domain compromise. It shows how Active Directory tiering models segment…
Active Directory6 Krb5RoastParser is a Python tool that extracts Kerberos authentication hashes from PCAP traffic and converts them into Hashcat-compatible formats, simplifying Kerberoasting and…
BYOVD632 KslKatz is a Windows credential-dumping tool that reads LSASS memory using a kernel driver to bypass user-mode protections. It merges techniques from…
Debug20 A technical walkthrough showing how to unpack a VMProtected Windows kernel driver using WinDbg and dynamic analysis. The guide demonstrates restoring the…
NVMe8 Microsoft has disabled a registry hack that enabled a hidden native NVMe driver in Windows 11 24H2/25H2. The tweak previously delivered major…
Debug4 A beginner-friendly guide to debugging Windows programs using WinDbg and WinDbgX. It explains debugger basics, breakpoints, symbols, memory inspection, and execution control—key…
Escalation9 CVE-2026-26119 is a high-severity privilege-escalation flaw in Windows Admin Center caused by improper authentication. Attackers with low-privileged access could gain admin rights…
.NET3.8k The article shows a proof-of-concept where DOOM is stored across ~2,000 DNS TXT records and executed directly from memory. A PowerShell loader…
Embedded8 Researchers discovered CVE-2026-0714 where a Moxa embedded device leaks its LUKS disk key in plaintext over the TPM SPI bus during boot.…
attaks14 The article analyzes CVE-2026-32746, a decades-old vulnerability in GNU Inetutils telnetd where a malformed LINEMODE SLC option triggers an out-of-bounds write, enabling…
AI Agents7 The article analyzes a real deployment of a low-privileged on-prem LLM server and shows that even restricted models can expose internal systems…