๐ต Threat analysis writeup for Follina (CVE-2022-30190) โ Microsoft MSDT RCE zero-day exploited in the wild. Covers static analysis, VirusTotal, OSINT, MITRE ATT&CK T1059, and detection engineering using Windows Event ID 4688.
Threat analysis writeup for Follina (CVE-2022-30190) โ Microsoft MSDT RCE zero-day exploited in the wild. Covers static analysis, VirusTotal, OSINT, MITRE ATT&CK T1059, and detection engineering using Windows Event ID 4688.
Apache Syncope: User self-service privilege escalation
CVE-2026-63030 - WordPress REST Batch Route-Confusion SQL Injection Proof of Concept
Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining CVE-2026-63030 and CVE-2026-60137, potentially leading to full site compromise.
Version-pinned archival PoC for CVE-2025-9242 on WatchGuard Fireware 12.7 build 640389. Includes safe detection, offline payload analysis, and an explicitly gated reverse-shell exploit using a caller-supplied IPv4 callback endpoint.
wp2shell PoC with Cloudflare WAF bypass via body padding (CVE-2026-63030)
WordPress REST API SQLi to RCE (CVE-2026-63030)
WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-60121, CVE-2026-61498 - Draft
An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)
Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.
Proof-of-concept exploit for CVE-2026-63030, a pre-authentication vulnerability in WordPress (versions 6.9.0 through 7.0.1).
PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell
CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab.
PressVector - Advanced WordPress Vulnerability Scanner CVE-2026-63030 (REST batch route confusion) / CVE-2026-60137 (SQLi) Developer: Vulnquest
The wp2shell vulnerability chain represents one of the most significant WordPress Core security issues in recent years. Because exploitation begins with an unauthenticated request and can ultimately result in Remote Code Execution, organizations should treat remediation as an emergency.
Non-intrusive exposure checker for the WordPress wp2shell pre-auth RCE chain (CVE-2026-63030 / CVE-2026-60137).