Featured · 4 min read
CVE-2024-4577 is a CVSS 9.8 argument injection in PHP CGI on Windows that bypasses the 12-year-old CVE-2012-1823 patch using Windows Best-Fit encoding. Actively exploited by TellYouThePass ransomware.
Read Full Post →
🔐
CVE-2025-5156
Red Team
CVE-2021-36934 (HiveNightmare) continues powering Hunters International ransomware campaigns in 2025. Full exploitation chain, MITRE mapping, 4 validated Microsoft…