en
CVE-2025-48595: Android Framework Integer Overflow — Privilege Escalation and Stalkerware Chains
Technical root cause of the Android Framework integer overflow zero-day exploited in commercial surveillance spyware.
en
Technical root cause of the Android Framework integer overflow zero-day exploited in commercial surveillance spyware.
en
Full forensic analysis of the TeamPCP campaign: tag poisoning and entrypoint backdoors injected into Trivy, KICS, and Bitwarden CLI.
en
Technical root cause and active exploitation telemetry for the Citrix NetScaler SAML session memory overread flaw.
en
Technical breakdown of the 0-click unauthenticated remote code execution flaw in Windows Netlogon allowing Domain Controller takeover.
en
Weekly briefing: Megalodon backdoors 5,500 GitHub repos, Ghost CMS SQLi hijacks 700 sites for ClickFix, and MiniPlasma Windows 0-day.
en
Technical exploit breakdown of DirtyDecrypt: achieving local root privilege escalation via missing Copy-On-Write guards in Linux rxgk.
en
Technical root cause of YellowKey: bypassing BitLocker full-disk encryption via WinRE transaction replay without knowing user credentials.
en
Exploit analysis of MiniPlasma: triggering a race condition in cldflt.sys to spawn NT AUTHORITY\SYSTEM shells on fully patched Windows 11.
en
Technical breakdown of the Ghost CMS SQL injection exploited at scale to inject fake browser update (ClickFix) malware into 700+ websites.
en
How campaign Megalodon weaponized infostealer-harvested developer secrets to backdoor 5,561 GitHub repositories in automated CI runs.
en
Technical breakdown of CopyFail, Dirty Frag, and Fragnesia: how three page-cache memory flaws enabled unprivileged local root escalation in the Linux kernel.
en
Weekly briefing: Microsoft Exchange OWA zero-day XSS, TeamPCP GitHub breach (3.8K repos), Cisco SD-WAN UAT-8616, and Defender zero-days.