Archive

Archive

1481 bookmarks
Custom sorting
SLEEPWALKER: A Passive Backdoor With Its Own Command Language
SLEEPWALKER: A Passive Backdoor With Its Own Command Language
Losing access to VirusTotal Intelligence at the start of the year was surprisingly productive. Unable to hunt for interesting new malware, I stopped adding to my “TODO” pile and finally worked through my backlog from last year. That led to a detailed examination of BeheMOF as well as the discovery of this malware. Upon closer inspection, a sample that did not seem too noteworthy at first turned out to have a distinctive design once I looked under the hood: a passive backdoor that opens no obvious listening port and carries no payload inside itself. It waits in memory doing nothing at all until one specifically crafted network packet reaches the machine, which is why I am calling it SLEEPWALKER.
·r136a1.dev·
SLEEPWALKER: A Passive Backdoor With Its Own Command Language
File Drop to RCE – CVE-2026-20217
File Drop to RCE – CVE-2026-20217
I remember watching Simon Scannell's REcon 2023 talk, You Have Become the Very Thing You Swore to Destroy, and being deeply impressed by how he turned ClamAV's own detection logic into an oracle for exploiting a service with no direct output channel. I remember hoping that, someday, I might have the
·securifera.com·
File Drop to RCE – CVE-2026-20217
BOFScale: A CDN-Fronted Tailnet from a BOF-PE - NetSPI
BOFScale: A CDN-Fronted Tailnet from a BOF-PE - NetSPI
Introduction Running Tailscale as a network layer for C2 traffic is not a new idea. What makes this implementation different is that the entire Tailscale daemon runs inside the implant process with no driver, no service, no disk state, and no child processes. Traffic relays over standard WebSockets that are indistinguishable at the edge from […]
·netspi.com·
BOFScale: A CDN-Fronted Tailnet from a BOF-PE - NetSPI
Can AI do novel security research? Meet the HTTP Terminator
Can AI do novel security research? Meet the HTTP Terminator
Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi
·portswigger.net·
Can AI do novel security research? Meet the HTTP Terminator
Hunting Exchange Server 0day like a detective
Hunting Exchange Server 0day like a detective
Hunting Exchange Server 0day like a detective It has been a while since my last blog post, not because I didn’t do anything (or I?), I just don’t have any time/ any motivation to start new blog …
·testbnull.medium.com·
Hunting Exchange Server 0day like a detective
Vulnerability discovery in Java applications
Vulnerability discovery in Java applications
Intro Something different this time. This post is based on a speech I’m giving on June 24th at Ya!vaConf in Poland. So, we will analyze WebGoat application which is written in Java to discover some vulnerabilities in the source code and then write an exploit using Python.
·0xpat.github.io·
Vulnerability discovery in Java applications
0day Rubbish | AI-Driven Vulnerability Discovery
0day Rubbish | AI-Driven Vulnerability Discovery
Autonomous multi-LLM vulnerability research: full root-cause analyses and reproducible PoCs for 0-day RCE chains across enterprise, ICS/SCADA, ERP, and NMS products.
·0day-rubbish.com·
0day Rubbish | AI-Driven Vulnerability Discovery