Featured - 4 min read
CVE-2024-4577 is a CVSS 9.8 argument injection in PHP CGI on Windows that bypasses the 12-year-old CVE-2012-1823 patch using Windows Best-Fit encoding. Actively exploited by TellYouThePass ransomware.
Read Full Post →
Exploits
CVE-2024-3400 is a command injection zero-day in Palo Alto Networks PAN-OS GlobalProtect with a perfect CVSS 10.0. Exploited…
Cyber Awareness
A signal handler race condition in OpenSSH allows unauthenticated remote code execution as root on millions of Linux…
CVE-2026-5158
Blue Team
LegacyHive is an unpatched Windows 0-day (July 2026) targeting the User Profile Service. Full technical analysis of the…
🔐
CVE-2025-5156
Red Team
CVE-2021-36934 (HiveNightmare) continues powering Hunters International ransomware campaigns in 2025. Full exploitation chain, MITRE mapping, 4 validated Microsoft…