Skip to content
Labs at ITRES

Category: Defensive

  • Sep 14, 2026

    Source-Driven Recon: When the Patch Becomes the PoC and what CVE-2026-61797 taught us about Disclosure OPSEC

  • Sep 9, 2026

    Prestashop Trust Issues: Reading the Wrong End of X-Forwarded-For

  • Mar 11, 2026

    The Tensor in the Haystack: Weightsquatting as a Supply-Chain Risk

  • Feb 18, 2026

    Supply Chain Necromancy: Reborn Namespaces in JitPack Coordinates

  • Feb 11, 2026

    Bypassing the FortiGate Symlink Patch: The Double Slash Technique (CVE-2025-68686)

  • Feb 4, 2026

    The €10 Mirror: Why Enterprise Security Looks Like a Kid’s Toy

  • Jan 9, 2026

    CVE-2024-30376 Unpatched: Advanced IP Scanner still ships a Qt LPE in the same build that leaks NTLM

  • Jan 7, 2026

    CVE-2025-1868 Unpatched: Advanced IP Scanner still silently exposing NTLM during scans 9 months later

  • Oct 29, 2025

    Beyond CVE-2025-31702: P2P relay exposure and auto-update mismatches (Part II)

  • Oct 15, 2025

    CVE-2025-31702: What a DFIR on Dahua devices taught us

1 2
Next Page

penny for your thoughts

LABS@ITRESIT.es

IMPROVE Your CYBERSECURITY MINDSET

Don’t miss out. Subscribe now to receive two updates per month. No FUD. No spam. Guaranteed.

← Back

Thank you for your response. ✨

BACK TO MAIN PAGE

ENGAGE LABS

DISCLOSURE POLICY

PUBLISHED VULNERABILITIES

FOLLOW AT ITRES

LEGAL