From a Regular Red Team Exercise to Developing a Custom C2 Channel over MS Teams – SCRT Team Blog
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)
Hello! Yes, it's all a disaster again!
Let's get this party started:
0:00
/0:12
1×
No comments today, so imagine this:
* We wrote something that we find very funny,
* Nobody else gets it,
* But everyone humors us
Just like a typical watchTowr Labs blog introduction.
As with all
【続・マルウェア解析】Atomic Stealer攻撃チェーンの解析 - Qiita
【続・マルウェア解析】Atomic Stealer攻撃チェーンの解析
AWS Cognitoの罠10選 | 技術者ブログ | 三井物産セキュアディレクション株式会社
Cognitoの罠10選と称して、Cognitoにおける設定ミス等を引き起こしやすい勘違いポイントを10項目紹介します。
Multiple XSS Vulnerabilities Found in Mailcow, Including Unauthenticated Account Takeover
Multiple Cross-Site Scripting (XSS) Vulnerabilities in Mailcow
QUIC-er Races: HTTP/3 won’t save you from TOCTOU vulnerabilities - International Journal of Information Security
Race conditions in web applications represent a persistent class of vulnerabilities that allow adversaries to bypass business logic through synchronized request bursts. While the transition from TCP-based HTTP/2 to UDP-based HTTP/3 (QUIC) introduces stochastic processing delays and independent stream delivery, the security implications of these protocol shifts remain under-explored. This work investigates the effectiveness of race condition exploits across modern transport protocols. Our experimental results demonstrate that while the user-space implementation of QUIC provides a resilience threshold against low-volume attacks, this protection is an artifact of scheduling jitter and is inherently fragile. We identify a critical concurrency threshold ( $$N=100$$ N = 100 ) where the density of a Single Datagram Attack (SDA) saturates the protocol parser, achieving an exploitation efficiency (f) that exceeds traditional HTTP/2 methods. However, we also identify a “smothering effect” unique to high-density bursts, where extreme transaction arrival rates trigger database-level lost updates that can paradoxically limit total economic impact. Furthermore, we show that infrastructure-level defenses, such as network pacing, are effectively neutralized by the reverse proxy’s de-multiplexing process. We conclude that protocol-level evolution does not mitigate application-layer concurrency risks; rather, it shifts the attack surface dynamics toward more efficient but higher-contention exploitation primitives.
Zero-Click RCE in Figma Desktop: A Race-Conditioned Prototype Pollution Chain That Escapes the Plugin Sandbox
A prototype pollution bug in Figma’s variant counter, chained through a plugin-context race against $INTERNAL_DO_NOT_USE$RERUN_PLUGIN$, a jsx_debugging feature-flag flip, and a forgotten writeFileToPath IPC in the Electron desktop app, to achieve zero-click cross-platform RCE from a published plugin. Reported to Figma and patched within hours.
Bypassing Windows authentication reflection mitigations for SYSTEM
PhantomRPC: A new privilege escalation technique in Windows RPC
Kaspersky researcher discovered a vulnerability in RPC architecture that enables an attacker to create a fake RPC server and escalate their privileges.
Abusing WinML for In-Memory Staging and EDR Evasion
Abusing legitimate machine learning infrastructure for payload delivery, in-memory staging, and EDR evasion on Windows 10/11.
Introduction
Every red team operator knows the arms race: EDR vendors get better at flagging suspicious API sequences, shellcode patterns, and reflective loaders. Meanwhile, Windows keeps shipping new legitimate subsystems that are rarely audited from an offensive perspective.
Windows Machine Learning (WinML) - shipped since Windows 10 1809 (build 17763) - is one su
EDR/XDR Bypass and Detection Evasion Techniques: An Investigation of Advanced Evasion Strategies…
“” is published by Excalibra in MeetCyber.
Dissecting FudCrypt: A Real-World Malware Crypting Service Analysis
A full technical teardown of FUD Crypt (Cryptor-as-a-Service) and surrounding activity performed by this threat actor
Secure Code Review: Finding XML vulnerabilities in Code [1/2] – mqst
SSRF Master Guide: Exploitation and Mitigation Strategies
Learn how to identify and exploit SSRF vulnerabilities in cloud-native environments, from metadata services to filter bypass.
Creative approaches to coding FUD Stagers
I have had several discussions over the years with folks on tackling EDR bypass as it pertains to fully undetected (FUD) code. In my opinion, there isn’t really a perfect silver bullet approach to tackling FUD. Especially with ML (machine learning) / AI integrated in most modern EDR solutions, you really have to adjust your approach to FUD as you go. I will say that I truly believe script interpreter type languages such as Python, Ruby, Perl, even PHP, are great candidates to meet this need. Scripting languages are not heavily scrutinized when we’re comparing with compiled (PE executable) code. Now I can already hear the disgruntled offsec folks questioning my rationale when they have tried countless times to make their powershell and javascript/vbscript code into FUD worthy code. I get it and I’m with you. It’s not a one size fits all right? Powershell, while also a script interpreter type language, has been so abused by threat actors that it’s incredibly difficult to tackle FUD due to its prolific use in malicious campaigns, but it’s certainly not impossible. Let’s get to it!
SCADA (ICS) Hacking and Security: Attacking the Modbus Protocol with ROfuzz – Hackers Arise
Exploiting stale ADIDNS entries – SCRT Team Blog
Patch Diffing CVE-2026-21509: Microsoft Office OLE Security Bypass
Overview
publications/MADBugs/ladybird at main · califio/publications
Publications from Calif. Contribute to califio/publications development by creating an account on GitHub.
Bad Apples: Weaponizing native macOS primitives for movement and execution
Cisco Talos documents several macOS living-off-the-land (LOTL) techniques, demonstrating that native pathways for movement and execution remain accessible to those who understand the underlying architecture.
ClickFix RockFest
Initial Access: Modern Intrusion Techniques
Red Teamer & Low-Level Developer. Deep dives into Windows Internals, Kernel Exploitation, Driver Analysis, and Red Team techniques.
CVE-2026-1731 | AttackerKB
On February 6, 2026, BeyondTrust published an advisory for a new critical command injection vulnerability, CVE-2026-1731, affecting their products Remote Suppo…
BeyondTrust
CVE-2025-24000 - Post SMTP Plugin - Lark Docs
Post SMTP Plugin (= 3.2.0) Privilege Escalation Vulnerability Walkthrough Vulnerability Report CVE ID: CVE-2025-24000 Plugin: Post SMTP Type: Privilege Escalation via Broken Authentication Vulnerable Version: = 3.2.0 Fixed Version: 3.3.0 Patch Priority: High CVSS Score: 8.8 (High) OWASP Classification: A7: Identification and Authentication Failures Discovered by: Denver Jackson Published: July 21, 2025 Overview The WordPress plugin "Post SMTP"
RainLoop Webmail - Emails at Risk due to Code Flaw
Sonar researchers discovered a critical stored cross-site scripting vulnerability in RainLoop Webmail that allows attackers to hijack user sessions and steal emails simply by sending a malicious email. The article explains the root cause, exploitation, and security implications.
RainLoop
Ledger hardware implant slides
No Agent, No Problem: Discovering Remote EDR
As the reader, I’m sure you’re thinking — “oh great, another EDR internals or bypass post”. I can fully understand that sentiment, as…
Zero Day Initiative — CVE-2026-33824: Remote Code Execution in Windows IKEv2
In this excerpt of a TrendAI Research Services vulnerability report, Richard Chen and Lucas Miller of the TrendAI Research team detail a recently patched double free vulnerability in the Windows Internet Key Exchange (IKE) service. This bug was originally discovered by WARP & MORSE team at
The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure. The findings expose how suspected commercial surveillance vendors (CSVs) exploit the global telecom interconnect ecosystem, leverage private operator networks, and conduct covert location tracking operations that can persist undetected for years.
CVE-2026-25874: HuggingFace LeRobot Unauthenticated RCE via Pickle Deserialization in gRPC PolicyServer - Chocapikk's Cybersecurity Blog
A critical unauthenticated RCE vulnerability in HuggingFace's LeRobot project (21.5k stars). The gRPC PolicyServer deserializes attacker-controlled data with pickle.loads() in two RPC handlers, allowing instant code execution without authentication.