GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full control of any Super-Admin account through REST API authtype manipulation.
Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check Point Security Gateway. Includes comprehensive SIEM analysis, firewall logs, raw web access log inspection (`/var/log/access.log`), IOCs, MITRE ATT&CK mapping, and post-exploitation validation.
My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and LLMNR/NBT-NS credential poisoning — each with step-by-step packet analysis, screenshots, and a full Wireshark filter/command reference. Personal SOC Analyst Tier 1 learning log.
System Vulnerability Checklist & Network Security Hardening project featuring reconnaissance, vsFTPd backdoor analysis (CVE-2011-2523), and active transport-layer mitigation using IPTables.
Kestra Unauthenticated RCE Exploit (CVE-2026-53576)
Defensive WordPress incident-response plugin for the "wp2shell" attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin IOCs and deletes a selected account in a controlled, logged way. Does not remove malware.
PD2229B的43499(ghostlock)可行性研究
CVE-2026-8239 is an Insecure Direct Object Reference (IDOR) vulnerability affecting Concrete CMS 9.5.0 and earlier.
CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).
First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. IOCs + YARA + Sigma + Suricata included.
CVE-2026-8337 is an Insecure Direct Object Reference (IDOR) vulnerability in Concrete CMS that affects the Survey feature. Unlike CVE-2026-8347 (which involved Express associations), this vulnerability allows an unauthenticated attacker to participate in a restricted/private survey under specific site configurations.
▎ Open, runnable proof of concept + IEC 62443-4-2 (SL 2) mapping + a phased rollout for CVE-2021-22681 — the unpatchable Rockwell Logix hardcoded-key flaw behind the 2026 water-sector attacks. Reproduces the fix principle with open tooling; sized for small water utilities.
GhostLock (CVE-2026-43499) exploit for POCO F3 GT (aresin) — MediaTek Dimensity 1200, Linux 4.14.186 ARM64 kernel privilege escalation via futex PI chain manipulation
CVE-2026-66066 + File Read, RCE, Scanner, Lab
GhostLock (CVE-2026-43499) kernel exploit for Poco M6 Pro (emerald) with locked bootloader
Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc's iconv()
Unauthenticated RCE in DBGate <= 7.1.8
Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers
Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc's iconv()
Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD Security Risks, with PoCs, remediation, and interview-ready summaries.