Skip to content
Category:
Labs
Jul 28, 2026
Old Dives #01: The RPS Status Page That Gave Passwords Back (CVE-2023-3349 / CVE-2023-3350)
Jun 29, 2026
Source-Driven Recon: GLPI Plugin Mapping via Functional Paths
May 7, 2026
Cashdro Vulnerabilities: From Pentest to Stealing Money
Apr 29, 2026
PrestaShop: The Art of Core Module Fingerprinting
Mar 25, 2026
When Bills Come with Surprise: Donut of Python and Rat🤮
Mar 18, 2026
When Support Becomes the Backdoor: Bypassing MFA on a Major Security Vendor’s Portal
Mar 11, 2026
The Tensor in the Haystack: Weightsquatting as a Supply-Chain Risk
Feb 25, 2026
GLPI Agent: The “No-CVE” That Still Bought Us Domain Compromise Two Years Later
Feb 18, 2026
Supply Chain Necromancy: Reborn Namespaces in JitPack Coordinates
Feb 11, 2026
Bypassing the FortiGate Symlink Patch: The Double Slash Technique (CVE-2025-68686)
1
2
3
Next Page