vivek@kali:~/blog$ grep -r "threat-intel" ./posts/

Exploits

Security research, ethical hacking tutorials, cybercrime case studies, and threat intelligence from the field.

CVE-2025-0282: Ivanti Connect Secure Zero-Day Exploited by Nation-State Hackers Before Anyone Knew It Existed CVE-2026-5178
Featured · 7 min read
CVE-2025-0282 is a critical pre-authentication stack buffer overflow in Ivanti Connect Secure VPN (CVSS 9.0). Exploited by China-nexus nation-state actors since December 2024, deploying SPAWN, DRYHOOK, and PHASEJAM…
Jul 22, 2026 Exploits
China APT CISA emergency CVE-2025-0282 DRYHOOK
Read Full Post →
CVE-2025-21298: Windows OLE Zero-Click RCE — Just Previewing an Email Triggers the Exploit CVE-2026-5176
Cyber Awareness
CVE-2025-21298 is a critical Windows OLE vulnerability with CVSS 9.8. Attackers send a malicious RTF email and viewing…
5 min
CVE-2025-21298 email attack OLE exploit
CVE-2024-4577: Critical PHP CGI Vulnerability on Windows Exploited by Ransomware Within Days CVE-2026-5174
Cyber Awareness
CVE-2024-4577 is a CVSS 9.8 argument injection in PHP CGI on Windows that bypasses the 12-year-old CVE-2012-1823 patch…
4 min
argument injection CGI exploit CVE-2024-4577
CVE-2024-3400: Palo Alto GlobalProtect Zero-Day with a Perfect CVSS 10.0 Score CVE-2026-5172
Exploits
CVE-2024-3400 is a command injection zero-day in Palo Alto Networks PAN-OS GlobalProtect with a perfect CVSS 10.0. Exploited…
5 min
command injection CVE-2024-3400 CVSS 10
CVE-2024-6387 (regreSSHion): The Critical OpenSSH RCE That Threatened 14 Million Servers CVE-2026-5170
Cyber Awareness
A signal handler race condition in OpenSSH allows unauthenticated remote code execution as root on millions of Linux…
5 min
CVE-2024-6387 ethical hacking Linux security