Skip to content
Labs at ITRES

Category: Offensive

  • Sep 14, 2026

    Source-Driven Recon: When the Patch Becomes the PoC and what CVE-2026-61797 taught us about Disclosure OPSEC

  • Sep 9, 2026

    Prestashop Trust Issues: Reading the Wrong End of X-Forwarded-For

  • Jul 28, 2026

    Old Dives #01: The RPS Status Page That Gave Passwords Back (CVE-2023-3349 / CVE-2023-3350)

  • Jun 29, 2026

    Source-Driven Recon: GLPI Plugin Mapping via Functional Paths

  • May 7, 2026

    Cashdro Vulnerabilities: From Pentest to Stealing Money

  • Mar 18, 2026

    When Support Becomes the Backdoor: Bypassing MFA on a Major Security Vendor’s Portal

  • Mar 11, 2026

    The Tensor in the Haystack: Weightsquatting as a Supply-Chain Risk

  • Feb 25, 2026

    GLPI Agent: The “No-CVE” That Still Bought Us Domain Compromise Two Years Later

  • Feb 18, 2026

    Supply Chain Necromancy: Reborn Namespaces in JitPack Coordinates

  • Feb 11, 2026

    Bypassing the FortiGate Symlink Patch: The Double Slash Technique (CVE-2025-68686)

1 2 3
Next Page

penny for your thoughts

LABS@ITRESIT.es

IMPROVE Your CYBERSECURITY MINDSET

Don’t miss out. Subscribe now to receive two updates per month. No FUD. No spam. Guaranteed.

← Back

Thank you for your response. ✨

BACK TO MAIN PAGE

ENGAGE LABS

DISCLOSURE POLICY

PUBLISHED VULNERABILITIES

FOLLOW AT ITRES

LEGAL