research

Vulnerability Research (7)

CVE-2026-1579 Critical

CVE-2026-1579: Unauthenticated Remote Command Execution in PX4 Autopilot via MAVLink

An unauthenticated attacker within network range can run arbitrary shell commands on a PX4 drone flight controller through the MAVLink SERIAL_CONTROL handler (CVSS 9.8).

CVE-2025-14894

Unauthenticated RCE in Livewire Filemanager (CVE-2025-14894)

An unauthenticated attacker can upload a PHP web shell to the Livewire Filemanager package for Laravel and execute it, achieving remote code execution (CVSS 9.8).

CVE-2025-13184

CVE-2025-13184 - TOTOLINK X5000R (AX1800 router) Authentication Bypass

An authentication bypass in the TOTOLINK X5000R (AX1800) router gives anyone on the local network full admin access without valid credentials.

CVE-2025-65199 Medium

CVE-2025-65199 - Windscribe VPN Local Privilege Escalation

On Linux, a local user in the windscribe group can abuse the Windscribe VPN root helper over its Unix socket to escalate to root.

CVE-2025-13654 High

CVE-2025-13654: Stack Buffer Overflow in Duc via Integer Underflow

An integer underflow in Duc, a disk-usage tool in the Debian repositories, triggers a stack buffer overflow that causes denial of service and possible information disclosure.

Heap Out-of-Bounds Read in Hermes JavaScript Engine: A Technical Deep Dive

A heap out-of-bounds read in the SerializedLiteralParser of Meta's Hermes JavaScript engine, leading to denial of service and memory disclosure.

Walkthrough: Pre-auth DoS in IBM Verify FreeRADIUS reference module (unchecked realloc)

An unchecked realloc in IBM Verify's FreeRADIUS reference module lets a remote, unauthenticated attacker crash the service (pre-auth denial of service).

Malware Analysis (12)

Malware Analysis: Android Malware Disguised as GB WhatsApp

An analysis of an Android APK from the Joker malware family that hides inside the GB WhatsApp mod to mask its malicious behavior.

Redline Stealer: A Technical Examination of Modern Malware Tactics

A static and dynamic analysis of a Redline Stealer sample, showing how modern info-stealers harvest credentials, cookies, and system data.

Comprehensive Malware Analysis: Dissecting Agent Tesla’s Evasion Tactics, Persistence, and Network Behavior

A deep analysis of an Agent Tesla sample, examining its evasion tactics, persistence mechanisms, and network exfiltration behavior.

Shamoon - An Advanced Static and Dynamic Analysis of Iran’s Wiper Malware

A static and dynamic analysis of Shamoon, a destructive wiper malware tied to Iranian state-sponsored groups, and how it erases data.

Micropsia: In-Depth Analysis of a Hamas-Linked Cyber Warfare RAT

An in-depth analysis of Micropsia, a RAT linked to the AridViper group, covering its surveillance features and command infrastructure.

Karkoff: Static & Dynamic Analysis of an Iranian Trojan

Static and dynamic analysis of Karkoff, a stealthy Iranian trojan, detailing its persistence and command-and-control behavior.

Static & Dynamic Analysis on An Unknown Sample

Static and dynamic analysis of an unknown sample (the SickoMode challenge from PMAT Labs), confirming and dissecting its trojan behavior.

Malicious Excel Document - Basic Static Analysis

A static analysis of a malicious Excel document on REMnux, extracting its embedded payload and indicators of compromise.

Advanced Static Analysis - Reverse Shell

A deep static analysis of a reverse shell malware sample, breaking down its structure and capabilities without running it.

Basic Static & Dynamic Analysis - SillyPutty

A basic static and dynamic analysis of a trojanized PuTTY (SillyPutty) sample to uncover its hidden malicious payload.

Analyzing A Reverse Shell

Analysis of a reverse-shell RAT sample, tracing how it calls back to its operator and what it can do on an infected host.

Dynamic Analysis - An Unknown RAT

A dynamic analysis of an unknown RAT, observing its runtime behavior, persistence, and network activity in a sandbox.

Reverse Engineering (2)

CTF & Walkthroughs (7)