vivek@kali:~/blog$ grep -r "threat-intel" ./posts/

Security Research & Threat Intelligence

Field notes from active engagements - ethical hacking tutorials, cybercrime case studies, zero-day analysis, and blue team detection strategies.

CVE-2024-4577: Critical PHP CGI Vulnerability on Windows Exploited by Ransomware Within Days CVE-2026-5174
Featured - 4 min read
CVE-2024-4577 is a CVSS 9.8 argument injection in PHP CGI on Windows that bypasses the 12-year-old CVE-2012-1823 patch using Windows Best-Fit encoding. Actively exploited by TellYouThePass ransomware.
Jul 22, 2026 Cyber Awareness
argument injection CGI exploit CVE-2024-4577 PHP vulnerability
Read Full Post →
CVE-2024-3400: Palo Alto GlobalProtect Zero-Day with a Perfect CVSS 10.0 Score CVE-2026-5172
Exploits
CVE-2024-3400 is a command injection zero-day in Palo Alto Networks PAN-OS GlobalProtect with a perfect CVSS 10.0. Exploited…
5 min
command injection CVE-2024-3400 CVSS 10
CVE-2024-6387 (regreSSHion): The Critical OpenSSH RCE That Threatened 14 Million Servers CVE-2026-5170
Cyber Awareness
A signal handler race condition in OpenSSH allows unauthenticated remote code execution as root on millions of Linux…
5 min
CVE-2024-6387 ethical hacking Linux security
NightmareEclipse 2026: LegacyHive Windows 0-Day Exposed — Full Attack Chain, MDE Detection Queries & Blue Team Playbook CVE-2026-5158
Blue Team
LegacyHive is an unpatched Windows 0-day (July 2026) targeting the User Profile Service. Full technical analysis of the…
Jul 16, 2026 19 min
Blue Team CVE-2026-50656 Defender Bypass
🔐
CVE-2025-5156
Red Team
CVE-2021-36934 (HiveNightmare) continues powering Hunters International ransomware campaigns in 2025. Full exploitation chain, MITRE mapping, 4 validated Microsoft…
Jul 16, 2025 15 min
Blue Team Credential Dumping CVE-2021-36934