Wed 16 September 2026
Exploitation of multiple vulnerabilities in SPIP to gain remote code execution from unauthenticated privileges (CVE-2026-72708, CVE-2026-72709, CVE-2026-72710).
Tue 26 May 2026
Turning a SELECT-only PostgreSQL SQL injection into remote command execution when the injected role is a PostgreSQL superuser.
Tue 07 April 2026
A technical deep dive into the discovery of an unauthenticated zero-day vulnerability in the Ninja Forms - File Uploads WordPress extension, which allows arbitrary file uploads, remote code execution, and full server compromise.
Thu 11 September 2025
Uncovering bypasses, RCE, SSRF, CSRF, and account-takeover vulnerabilities in WSO2 products.
Wed 12 March 2025
Exploitation of multiple vulnerabilities in GLPI to gain remote code execution from unauthenticated privileges.
Thu 26 September 2024
A pre-authentication remote code execution vulnerability was found on Jupiter X Core Plugin <= 4.6.5 (CVE-2024-7772).
Check our offensive & continuous web security assessment service