Tue 26 May 2026
Turning a SELECT-only PostgreSQL SQL injection into remote command execution when the injected role is a PostgreSQL superuser.
Tue 07 April 2026
A technical deep dive into the discovery of an unauthenticated zero-day vulnerability in the Ninja Forms - File Uploads WordPress extension, which allows arbitrary file uploads, remote code execution, and full server compromise.
Thu 12 February 2026
Exploiting Heap Buffer Overflow in the authentication daemon used by most High Performance Computer.
Thu 11 September 2025
Uncovering bypasses, RCE, SSRF, CSRF, and account-takeover vulnerabilities in WSO2 products.
Mon 01 September 2025
Tracking already-established BLE connections using SDR has its own challenges. With custom firmware and multi-channel listening, the presented approach quickly deduces the hidden hopping parameters needed to follow the connection.
Tue 15 July 2025
The article analyzes the Secp0 ransomware, which emerged in early 2025 and operates as conventional double-extortion ransomware, encrypting data while threatening public disclosure, targeting Linux systems.
Check our offensive & continuous web security assessment service