Kerberos38 One Click, One Hash: Unpatched NTLM Coercion in Windows Search URI Handler
Huntress reveals an unpatched Windows search: URI handler flaw that can leak Net-NTLMv2 hashes with a single link click. The bug mirrors…
Kerberos38 Huntress reveals an unpatched Windows search: URI handler flaw that can leak Net-NTLMv2 hashes with a single link click. The bug mirrors…
Exploit Development66 Deep-dive writeup on a Linux kernel use-after-free in "fs/eventpoll.c". A 2023 optimisation traded a global "epmutex" for per-instance reference counting in epoll’s…
Exploit Development54 STAR Labs’ advisory on CVE-2026-41873 in Apache Pony Mail by Li Jiantao and Tevel Sho (disclosed 28 April 2026). Two independent bugs…
Hardware81 External PCIe DMA cheats are hard because the cheat code runs on another PC. Detection must move to PCIe fingerprints, IOMMU faults,…
MacOS69 CVE-2024-32002 turns git clone --recursive into RCE on case-insensitive filesystems. A crafted submodule + symlink can plant a Git hook in .git…
kernel-mode68 Dirty Frag is a Linux kernel local privilege escalation class abusing zero-copy networking, skb fragments, and in-place crypto to corrupt page cache…
Android75 The article shows how APK decompilation with Jadx exposed Cordova JavaScript code, hardcoded database keys, CryptoJS-derived secrets, backend endpoints, and a critical…
CI/CD35 A parsing flaw in BullFrog’s DNS-over-TCP handling allows attackers to bypass CI/CD egress filtering by pipelining DNS queries. The filter validates only…
MacOS40 A macOS Recovery Mode Safari flaw allowed attackers to write arbitrary files to system partitions. By placing a malicious LaunchDaemon in /Library/LaunchDaemons,…
Antivirus87 BlueHammer shows how Microsoft Defender’s update workflow can be abused to redirect privileged file access to a Volume Shadow Copy. By exploiting…
Active Directory50 The article explains how flat enterprise networks enable easy lateral movement and domain compromise. It shows how Active Directory tiering models segment…
Embedded51 Researchers discovered CVE-2026-0714 where a Moxa embedded device leaks its LUKS disk key in plaintext over the TPM SPI bus during boot.…