The Username Was a File Descriptor: Inside MikroTrick
CVE-2026-86060 turned a crafted RouterOS SSH identity into administrative policy. Trace MikroTrick, a safe lab, detection logic, and trusted recovery.
CVE-2026-86060 turned a crafted RouterOS SSH identity into administrative policy. Trace MikroTrick, a safe lab, detection logic, and trusted recovery.
CVE-2026-81963 is an exploited Windows Update link-following flaw. Trace the SYSTEM escalation model, safe mechanism lab, detection logic, and patch validation.
CVE-2026-60004 turns duplicate Gitea diffpatch requests into an executable Git hook. Analyze the attack chain, detection signals, and containment.
ShieldBreak (CVE-2026-69414) abuses file-path resolution around Microsoft Defender. Trace the privilege chain, detection telemetry, and interim controls.
Unit 42’s Pass-ta-key research exposes device-trust and recovery attacks around Google-synced passkeys. Trace the mechanics, detection, and defensive choices.
Gunra’s locker is the last stage. Detect the earlier handoff from VPN compromise to remote access, exfiltration, backup deletion, and offline encryption.
A macOS ClickFix campaign hid its lure behind browser fingerprinting. This analysis reproduces the gate safely and builds detection across web, endpoint and identity telemetry.
CVE-2026-63077 exposes every TeamCity On-Premises version to unauthenticated RCE through the agent polling protocol. This deep dive maps the trust failure, runs a safe deserialization mechanism lab, and shows how to detect, contain, and validate CI/CD integrity.
TA488 turned ordinary webmail rendering into browser-resident access. Trace OWAReaper from reading pane to persistence, then hunt its mailbox and browser artifacts.
CVE-2025-68686 is not initial access. It is a FortiOS SSL-VPN symlink patch bypass that turns prior filesystem compromise into remote data exposure.
wp2shell chains WordPress REST route confusion with SQL injection to reach pre-auth RCE. Learn the mechanics, affected versions, evidence sources, and safe response workflow.
Active SharePoint exploitation demands more than patching. Validate every farm node, hunt IIS and EDR telemetry, rotate trust material, and harden the complete attack path.
Technical analysis of enterprise AI attack chains: indirect prompt injection, memory poisoning, tool abuse, MCP exposure, and detection.
Advanced guide to AI threat modeling for RAG, agents, and MCP, with trust boundaries, context provenance, and identity separation.
A practical AI Red Team guide to A2A reconnaissance, canary agent registration, agent-card spoofing, and delegation auditing in an authorized lab.