Back to updates
UpdatedAug 31, 2026

awesome-list — Updated!

Cybersecurity oriented awesome list

Share

Awesome Cybersecurity List

My personal collection of awesome blog posts, write-ups, and papers focusing on cybersecurity.

For a deeper dive into cybersecurity-related tools, check out the dedicated Cybersecurity Tools list.

Outline

2026

  • "A 0-click exploit chain for the Pixel 9"
    • [Part 1][1241]
    • [Part 2][1242]
    • [Part 3][1243]
  • ["A Brief Analysis of a Vulnerability in the Glibc (CVE-2025-4802)"][1277]
  • ["A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets"][1283]
  • ["Achieving remote code execution in LangSmith Playground using unsafe template formatting"][1271]
  • ["Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover"][1305]
  • ["Black Box Probing: a Security Analysis of Xiaomi's MJA1 Secure Chip"][1306]
  • ["BRIDGEROUTER: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux Kernel"][1293]
  • ["Carbonara: The MediaTek exploit nobody served"][1249]
  • ["CHECK Removed, Context Confused, Checkmate Achieved"][1287]
  • ["Clang Hardening Cheat Sheet - Ten Years Later"][1239]
  • ["CrackArmor: Multiple vulnerabilities in AppArmor"][1267]
  • ["Creative approaches to coding FUD Stagers"][1299]
  • "CVE-2025-38352":
    • ["In-the-wild Android Kernel Vulnerability Analysis + PoC"][1224]
    • ["Extending The Race Window Without a Kernel Patch"][1225]
    • ["Uncovering Chronomaly"][1265]
  • ["CVE-2026-0714 TPM-sniffing LUKS Keys on an Embedded Device"][1235]
  • ["CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller"][1303]
  • ["Damned OOB"][1297]
  • ["Defeating Anti-Reverse Engineering: A Deep Dive into the 'Trouble' Binary"][1237]
  • ["DiceCTF 2026 Quals - cornelslop: Turning an RCU Double Free into a Cross-Cache Kernel Exploit"][1266]
  • ["DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write"][1302]
  • [Dirty Frag][1300]
  • ["DIRTYFREE: Simplified Data-Oriented Programming in the Linux Kernel"][1238]
  • ["Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC"][1223]
  • ["Exploiting MediaTek's Download Agent"][1232]
  • ["From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)"][1245]
  • ["From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks"][1279]
  • ["General Graboids: Worms and Remote Code Execution in Command & Conquer"][1250]
  • ["Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs"][1248]
  • ["Here We Go Again: A Five-Bug Chain to Arbitrary APK Install on Samsung S25"][1295]
  • ["HDD Firmware Hacking Part 1"][1290]
  • "Hooked on Linux"
    • ["Rootkit Taxonomy, Hooking Techniques and Tradecraft"][1281]
    • ["Rootkit Detection Engineering"][1282]
  • ["Jenny was a Friend of Mine - MCPs and Friends"][1274]
  • ["Intercepting OkHttp at Runtime With Frida - A Practical Guide"][1253]
  • ["Leveling Up Secure Code Reviews with Claude Code"][1273]
  • ["Living off the Process"][1236]
  • ["Make it Blink: Over-the-air Exploitation of the Philips HUE Bridge"][1294]
  • ["Mitmproxy for Fun and Profit: Interception and Analysis of Application Traffic"][1284]
  • ["N-Day Research with AI: Using Ollama and n8n"][1263]
  • ["Needle in the haystack: LLMs for vulnerability research"][1275]
  • ["Now You See mi: Now You're Pwned"][1278]
  • ["Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race"][1276]
  • ["On the Clock: Escaping VMWare Workstation at Pwn2Own Berlin 2025"][1252]
  • ["Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs"][1301]
  • ["Page-level UAF exploitation"][1268]
  • ["PageJack in Action: CVE-2022-0995 exploit"][1270]
  • ["Pwning Supercomputers - A 20yo vulnerability in Munge"][1255]
  • ["Reverse Engineering the Tapo C260 and Tapo Discovery Protocol v2"][1219]
  • ["Revisiting Two-Shot Kernel Shellcode Execution From Control Flow Hijacking"][1288]
  • ["Some notes on the security properties of the pipe_buffer kernel object"][1285]
  • ["Static Devirtualization of Themida"][1292]
  • ["Table Manners: Diving into Linux Pagetables exp techniques"][1280]
  • ["TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere"][1291]
  • ["The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation"][1296]
  • ["The Hidden Risk of Side-Channel Attacks on Post Quantum Cryptography"][1298]
  • ["The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance"][1234]
  • ["Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold"][1304]
  • ["TP-Link ER605 DDNS Pre-Auth RCE: Chaining CVE-2024-5242, CVE-2024-5243, CVE-2024-5244"][1264]
  • ["Trailmark turns code into graphs"][1286]
  • ["TREVEX: A Black-Box Detection Framework For Data-Flow Transient Execution Vulnerabilities"][1289]
  • ["Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive"][1244]
  • ["V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome’s Memory"][1262]
  • VulHunt
    • ["A High-Level Look at Binary Vulnerability Detection"][1257]
    • ["Detecting a Remote Code Execution Vulnerability in rsync"][1258]
    • ["Vulnerability REsearch using VulHunt"][1259]
    • ["Inside the Binary Vulnerability Analysis Framework"][1260]
    • ["Agentic Vulnerability Research with VulHunt"][1261]
  • ["When NAS Vendors Forget How TLS Works"][1251]
  • ["Windows ARM64 Internals: Pardon The Interruption! Interrupts on Windows for ARM"][1246]

2025

  • ["A File Format Uncracked for 20 Years"][1202]
  • ["A First Glimpse of the Starlink User Ternimal"][1084]
  • ["A Fuzzy Escape - A tale of vulnerability research on hypervisors"][1151]
  • ["A look at an Android ITW DNG exploit"][1231]
  • ["A modern tale of blinkenlights"][1200]
  • ["A Quick Dive Into The Linux Kernel Page Allocator"][1098]
  • ["A Series of io_uring pbuf Vulnerabilities"][1083]
  • ["A Tour of eBPF in the Linux Kernel: Observability, Security and Networking"][1181]
  • ["Accidentally Uncovering a Seven Years Old Vulnerability in the Linux Kernel"][1021]
  • ["All You Need Is MCP - LLMs Solving a DEF CON CTF Finals Challenge"][1142]
  • ["Analysing a 1-day Vulnerability in the Linux Kernel's TLS Subsystem"][1174]
  • ["Analyzing IOS Kernel Panic Logs"][1037]
  • ["Android: Scudo"][1070]
  • ["Another Crack in the Chain of Trust: Uncovering (Yet Another) Secure Boot Bypass"][1240]
  • ["APPROTECT Bypass on NRF52832"][1139]
  • ["APT28 Operation Phantom Net Voxel"][1171]
  • ["Attacking GenAI applications and LLMs – Sometimes all it takes is to ask nicely!"][1132]
  • ["Attention, High Voltage: Exploring the Attack Surface of the Rockwell Automation PowerMonitor 1000"][1106]
  • ["Being Overlord on the Steam Deck with 1 Byte"][1044]
  • "BPFDoor"
    • ["Part 1 - The Past"][1101]
    • ["Part 2 - The Present"][1102]
  • ["Beating xloader at Speed: Generative AI as a Force Multiplier for Reverse Engineering"][1189]
  • ["Best practices for key derivation"][1023]
  • ["Binder Fuzzing"][1146]
  • ["Blasting Past iOS 18"][1038]
  • ["Bluetooth Headphone Jacking: Full Disclosure of Airoha RACE Vulnerabilities"][1254]
  • ["Booting into Breaches Hunting Windows SecureBoot's Remote Attack Surfaces"][1138]
  • ["Bootloader to Iris: A Security Teardown of a Hardware Wallet"][1199]
  • ["Breaking Disassembly — Abusing symbol resolution in Linux programs to obfuscate library calls"][1125]
  • ["Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer"][1196]
  • ["Rreaking the Beestation: Inside our Pwn2Own 2025 Exploit Journey"][1217]
  • ["Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages"][1039]
  • ["Broken Trust: Fixed Supermicro BMC Bug Gains a New Life in Two New Vulnerabilities"][1179]
  • ["Bug Tamer: Turning Limited Heap Overflow into Full VMware Escape"][1209]
  • ["Buried in the Log. Exploiting a 20 years old NTFS Vulnerability"][1124]
  • ["Bypassing disk encryption on systems with automatic TPM2 unlock"][1018]
  • ["Bypassing MTE with CVE-2025-0072"][1105]
  • ["Callback hell: abusing callbacks, tail-calls, and proxy frames to obfuscate the stack"][1222]
  • ["Case Study: Analyzing macOS IONVMeFamily Driver Denial of Service Issue"][1040]
  • ["Case Study: IOMobileFramebuffer NULL Pointer Dereference"][1041]
  • ["Challenges and Pitfalls while Emulating Six Current Icelandic Household Routers"][1107]
  • ["CimFS: Crashing in memory, Finding SYSTEM (Kernel Edition)"][1061]
  • ["Control Flow Hijacking in the Linux Kernel"][1114]
  • ["Control Flow Hijacking via Data Pointers"][1085]
  • ["corCTF 2025 - corphone"][1168]
  • ["Cracking the Pixel 8: Exploiting the Undocumented DSP to Bypass MTE"][1212]
  • ["Cross Cache Attack CheetSheet"][1006]
  • ["CVE-2023-52927 - Turning a Forgotten Syzkaller Report into kCTF Exploit"][1118]
  • ["CVE-2024-30088 Pwning Windows Kernel @ Pwn2Own Vancouver 2024 (Plus Xbox)"][1149]
  • ["CVE-2024-53141: an OOB Write Vulnerability in Netfiler Ipset"][1065]
  • ["CVE-2025-23016 - EXPLOITING THE FASTCGI LIBRARY"][1086]
  • ["CVE-2025-37752 wo Bytes Of Madness: Pwning The Linux Kernel With A 0x0000 Written 262636 Bytes Out-Of-Bounds"][1076]
  • ["CVE-2025-38001 Exploiting All Google kernelCTF Instances And Debian 12 With A 0-Day For $82k: An RBTree Family Drama"][1163]
  • ["CVE-2025-6554: The (rabbit) Hole"][1188]
  • ["Debugging the Pixel 8 kernel via KGDB"][1123]
  • ["Defeating String Obfuscation in Obfuscated NodeJS Malware using AST"][1068]
  • ["Denial of Ruzzing: Rust in the Windows Kernel"][1185]
  • ["Dirty Pageflags: Revisiting PTE Exploitation in Linux"][1166]
  • ["DirtyPipe-CVE-2022-0847 (0xnull007"][1229]
  • ["DirtyPipe-CVE-2022-0847 (stdnoerr"][1230]
  • ["Disassembling a binary: linear sweep and recursive traversal"][1019]
  • ["Dissecting the macOS 'AppleProcessHub' Stealer: Technical Analysis of a Multi-Stage Attack"][1047]
  • ["Don’t Phish-let Me Down: FIDO Authentication Downgrade"][1155]
  • ["EL3vated Privileges: Glitching Google WiFi Pro from Root to EL3"][1121]
  • ["Emulating an iPhone in QEMU"][1051]
  • ["Endless Exploits: The Saga of a macOS Vulnerability Struck Nine Times"][1052]
  • ["Exploit Development: Investigating Kernel Mode Shadow Stacks on Windows"][1211]
  • ["Exploitation of AIxCC Nginx bugs: Part I"][1035]
  • ["Exploitation Walkthrough and Techniques - Ivanti Connect Secure RCE (CVE-2025-0282)"][1014]
  • ["Exploiting a 13-years old bug on QEMU"][1218]
  • ["Exploiting CVE-2024-0582 via the Dirty Pagetable Method"][1081]
  • ["Exploiting CVE-2025-21479 on a Samsung S23"][1184]
  • ["Exploiting Retbleed in the real world"][1141]
  • ["Exploiting the Synology TC500 at Pwn2Own Ireland 2024"][1122]
  • ["Exploiting Zero-Day (CVE-2025–9961) Vulnerability in the TP-Link AX10 Router"][1164]
  • ["Exploiting Heroes of Might and Magic V"][1119]
  • ["Exploring Grapheneos Secure Allocator: Hardened Malloc"][1167]
  • ["Exploring Heap Exploitation Mechanisms: Understanding the House of Force Technique"][1029]
  • ["Eternal-Tux: Crafting a Linux Kernel KSMBD 0-Click RCE Exploit from N-Days"][1172]
  • ["Extraction of Synology Encrypted Archives - Pwn2Own Ireland 2024"][1152]
  • ["False Injections: Tales of Physics, Misconceptions and Weird Machines"][1120]
  • ["Fast & Faulty - A Use After Free in KGSL Fault Handling"][1182]
  • ["FiberGateway GR241AG - Full Exploit Chain"][1097]
  • ["First analysis of Apple's USB Restricted Mode bypass (CVE-2025-24200)"][1058]
  • ["FLOP: Breaking the Apple M3 CPU via False Load Output Predictions"][1059]
  • ["Fundamental of Virtual Memory"][1162]
  • ["From Chrome renderer code exec to kernel with MSG_OOB"][1153]
  • ["Game Hacking - Valve Anti-Cheat (VAC)"][1074]
  • ["Ghost in the Controller: Abusing Supermicro BMC Firmware Verification"][1215]
  • ["Gone in 5 Seconds: How WARN_ON Stole 10 Minutes"][1103]
  • ["Google CTF 2025 Quals Writeup"][1131]
  • ["Hack The Emulated Planet: Vulnerability Hunting on Planet WGS-804HPT Industrial Switches"][1031]
  • "Hacking the XBox 360 Hypervisor"
    • [Part 1][1109]
    • [Part 2][1110]
  • ["Hacking Sonoff Smart Home IoT Device - Extract, Modify, Boot, Intercept, Clone!"][1129]
  • ["Hacking the Nokia Beacon 1 Router: UART, Command Injection, and Password Generation with Qiling"][1198]
  • ["HITCON CTF 2025 -- calc"][1145]
  • ["How I ruined my vacation by reverse engineering WSC"][1077]
  • ["How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel’s SMB implementation"][1090]
  • ["How Much More Must We Bleed? - Citrix NetScaler Memory Disclosure (CitrixBleed 2 CVE-2025-5777)"][1115]
  • "Hydroph0bia (CVE-2025-4275)"
    • ["a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1143]
    • ["a bit more than just a trivial SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1144]
    • ["a fixed SecureBoot bypass for UEFI-compatible firmware based on Insyde H2O"][1108]
  • ["Hypervisors for Memory Introspection and Reverse Engineering"][1099]
  • ["Kernel Exploitation Techniques: Turning The (Page) Tables"][1100]
  • ["Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel"][1180]
  • ["Inside Riot Vanguard's Dispatch Table Hooks"][1073]
  • ["Intercepting HTTPS Communication in Flutter: Going Full Hardcore Mode with Frida"][1079]
  • "iOS 17: New Version, New Acronyms":
    • [Part 1][1042]
    • [Part 2][1043]
  • ["kASLR Internals and Evolution"][1095]
  • ["Kernel-Hack-Drill: Environment For Developing Linux Kernel Exploits"][1082]
  • ["KernelSnitch: Side-Channel Attacks on Kernel Data Structures"][1005]
  • ksmbd (doyensec):
    • ["ksmbd vulnerability research"][1033]
    • ["Fuzzing Improvements and Vulnerability Discovery"][1175]
    • ["Exploiting CVE-2025-37947"][1176]
  • ["Laser Fault Injection on a Budget: RP2350 Edition"][1017]
  • ["Last barrier destroyed, or compromise of Fuse Encryption Key for Intel Security Fuses"][1072]
  • ["Let Me Cook You a Vulnerability: Exploiting the Thermomix TM5"][1137]
  • ["Lifting Binaries, Part 0: Devirtualizing VMProtect and Themida: It's Just Flattening?"][1147]
  • ["Linux Kernel Exploitation For Beginners"][1113]
  • ["Linux Kernel Hfsplus Slab-out-of-bounds Write"][1066]
  • ["Linux kernel Rust module for rootkit detection"][1026]
  • ["Llama's Paradox - Delving deep into Llama.cpp and exploiting Llama.cpp's Heap Maze, from Heap-Overflow to Remote-Code Execution"][1011]
  • ["LunoBotnet: A Self-Healing Linux Botnet with Modular DDoS and Cryptojacking Capabilities"][1177]
  • ["Mali-cious Intent: Exploiting GPU Vulnerabilities (CVE-2022-22706 / CVE-2021-39793)"][1050]
  • ["Malware Just Got Its Free Passes Back!"][1221]
  • ["MCTF 2025 - Write-up Sec Mem - Pwn"][1080]
  • ["mediatek? more like media-rekt, amirite."][1220]
  • ["Mindshare: Using Binary Ninja API to Detect Potential Use-after-free Vulnerabilities"][1069]
  • ["Modern (Kernel) Low Fragmentation Heap Exploitation"][1127]
  • ["My Emulation Goes to the Moon... Until False Flag"][1094]
  • ["NASA cFS version Aquila Software Vulnerability Assessment"][1056]
  • ["nRF51 RBPCONF bypass for firmware dumping"][1154]
  • ["One‑Click Memory Corruption in Alibaba’s UC Browser: Exploiting patch-gap V8 vulnerabilities to steal your data"][1193]
  • ["Oops! It's a kernel stack use-after-free: Exploiting NVIDIA's GPU Linux drivers"][1186]
  • ["Out-of-bound read in ANGLE CopyNativeVertexData from Compromised Renderer"][1148]
  • ["Overview of Map Exploitation in v8"][1075]
  • ["Paint it Blue: Attacking the Bluetooth Stack"][1216]
  • ["Patch-Gapping the Google Container-Optimized OS for $0"][1032]
  • ["PatchGuard Internals"][1092]
  • ["PerfektBlue Universal 1-click Exploit to Pwn Automotive Industry"][1213]
  • ["Phoenix: Rowhammer Attacks on DDR5 with Self-Correcting Synchronization"][1170]
  • ["Print Scan Hacks: Identifying multiple vulnerabilities acro ss multiple Brother devices"][1136]
  • ["Project Rain:L1TF"][1178]
  • ["Pwn2Own 2025: Pwning Lexmark’s Postscript Processor"][1194]
  • ["Pwn2Own Ireland 2024: Canon imageCLASS MF656Cdw"][1104]
  • ["Pwn2Own Ireland 2024 – Ubiquiti AI Bullet"][1117]
  • ["pyghidra-mcp: Headless Ghidra MCP Server for Project-Wide, Multi-Binary Analysis"][1134]
  • ["Python Dirty Arbitrary File Write to RCE via Writing Shared Object Files Or Overwriting Bytecode Files"][1087]
  • ["Qualcomm DSP Kernel Internals"][1135]
  • ["Race Against Time in the Kernel’s Clockwork"][1160]
  • ["Recovering Metadata from .NET Native AOT Binaries"][1089]
  • ["Reliable system call interception"][1010]
  • ["Replacing a Space Heater Firmware Over WiFi"][1020]
  • ["Reverse Engineering Hanwha Security Camera Firmware File Decryption with IDA Pro"][1093]
  • ["Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes"][1201]
  • ["Reversing, Discovering, And Exploiting A TP-Link Router Vulnerability — CVE-2024–54887"][1013]
  • ["Reversing Samsung's H-Arx Hypervisor Framework - Part 1"][1036]
  • ["Reversing the QardioArm"][1048]
  • ["Reviving Discarded Vulnerabilities: Exploiting Previously Unexploitable Linux Kernel Bugs Through Control Metadata Fields"][1226]
  • ["Reviving the modprobe_path Technique: Overcoming search_binary_handler() Patch"][1071]
  • ["Root Shell on Credit Card Terminal"][1112]
  • ["Rooting the TP-Link Tapo C200 Rev.5"][1130]
  • ["ROPing our way to RCE"][1028]
  • ["Running code in a PAX Credit Card Payment Machine"][1272]
  • ["RV130X Firmware Analysis"][1025]
  • ["Security through Transparency: Tales from the RP2350 Hacking Challenge"][1256]
  • ["smoltalk: RCE in Open Source Agents"][1045]
  • ["Solo: A Pixel 6 Pro Story (When one bug is all you need)"][1128]
  • ["SoK: Security of EMV Contactless Payment Systems"][1088]
  • ["Sound and Efficient Generation of Data-Oriented Exploits via Programming Language Synthesis"][1034]
  • ["Stack Overflows, Heap Overflows, and Existential Dread"][1150]
  • ["State of Linux Snapshot Fuzzing"][1078]
  • ["STM32L05 Voltage Glitching"][1111]
  • ["Streaming Zero-Fi Shells to Your Smart Speaker"][1096]
  • ["Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit"][1228]
  • ["System Register Hijacking: Compromising Kernel Integrity By Turning System Registers Against the System"][1197]
  • ["The Art of Linux Kernel Rootkits"][1008]
  • ["The cryptography behind electronic passports"][1214]
  • "The Evolution of Dirty COW":
    • [Part 1][1062]
    • [Part 2][1063]
  • ["The Journey of Bypassing Ubuntu’s Unprivileged Namespace Restriction"][1116]
  • ["TLS NoVerify: Bypass All The Things"][1165]
  • ["Tp-Link Router Deep Research"][1203]
  • ["Tracing Back to the Source | SPTM Round 3"][1046]
  • ["Turning Camera Surveillance on its Axis"][1158]
  • ["Untangling the Knot: Breaking Access Control in Home Wireless Mesh Networks"][1126]
  • ["Use-After-Free Vulnerability in the Can BCM Subsystem Leading to Information Disclosure (CVE-2023-52922)"][1133]
  • ["VMware Workstation guest-to-host escape"][1161]
  • ["We are ARMed no more ROPpery Here"][1016]
  • "When a Wi-Fi SSID Gives You Root on an MT02 Repeater"
    • [Part 1][1156]
    • [Part 2][1157]
  • ["When Good Kernel Defenses Go Bad: Reliable and Stable Kernel Exploits via Defense-Amplified TLB Side-Channel Leaks"][1067]
  • ["Windows arm64 Internals: Deconstructing Pointer Authentication"][1190]
  • ["Windows Heap Exploitation - From Heap Overflow to Arbitrary R/W"][1195]
  • "Windows Inter Process Communication A Deep Dive Beyond the Surface"
    • [Part 1][1204]
    • [Part 2][1205]
    • [Part 3][1206]
    • [Part 4][1207]
    • [Part 5][1208]
  • ["WireTap: Breaking Server SGX via DRAM Bus Interposition"][1183]
  • ["Workshop: Firmware Reverse Engineering"][1269]
  • ["Writing a Ghidra processor module"][1064]
  • ["Writing Sync, Popping Cron: DEVCORE's Synology BeeStation RCE & A Novel SQLite Injection RCE Technique (CVE-2024-50629~50631)"][1247]
  • ["yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242)"][1210]
  • ["You Already Have Our Personal Data, Take Our Phone Calls Too"][1140]
  • ["Zen and the Art of Microcode Hacking"][1027]
  • ["Zyxel Router Vulnerability Research Zyxel DX3301-T0/EX3301-T0"][1227]

2024

  • ["1-click Exploit in South Korea's biggest mobile chat app"][965]
  • ["4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways"][959]
  • "64 bytes and a ROP chain – A journey through nftables":
    • [Part 1][865]
    • [Part 2][866]
  • "nix libX11: Uncovering and exploiting a 35-year-old vulnerability":
    • [Part 1][703]
    • [Part 2][704]
  • ["A few notes on AWS Nitro Enclaves: Images and attestation"][738]
  • "A first look at Android 14 forensics"
  • ["A "Gau-Hack" from EuskalHack"][893]
  • ["A Journey From sudo iptables To Local Privilege Escalation"][1009]
  • ["A Practical Guide to PrintNightmare in 2024"][709]
  • ["A Technical Deep Dive: Comparing Anti-Cheat Bypass and EDR Bypass "][714]
  • ["A Trip Down Memory Lane"][715]
  • [AArch64 memory and paging][1015]
  • ["An Introduction to Chrome Exploitation - Maglev Edition"][882]
  • ["An unexpected journey into Microsoft Defender's signature World"][876]
  • ["Analysis of CVE-2024-21310 Pool Overflow Windows Cloud Filter Driver"][952]
  • ["Advanced CyberChef Techniques For Malware Analysis - Detailed Walkthrough and Examples"][736]
  • ["AES-GCM and breaking it on nonce reuse"][912]
  • ["Analyzing Mutation-Coded - VM Protect and Alcatraz English"][834]
  • ["ARLO: I'M WATCHING YOU"][810]
  • ["ASLRn’t: How memory alignment broke library ASLR"][731]
  • ["Attack of the clones: Getting RCE in Chrome’s renderer with duplicate object properties"][911]
  • ["Attacking Android Binder: Analysis and Exploitation of CVE-2023-20938"][852]
  • ["Automotive Memory Protection Units: Uncovering Hidden Vulnerabilities"][1173]
  • "Base64 Beyond Encoding"
    • [Part 1][945]
    • [Part 2][946]
  • ["Becoming any Android app via Zygote command injection"][863]
  • ["Beyond Control: Exploring Novel File System Objects for Data-Only Attacks on Linux Systems"][895]
  • ["BGGP4: A 420 Byte Self-Replicating UEFI App For x64"][728]
  • ["Binary type inference in Ghidra"][905]
  • ["Blackbox-Fuzzing of IoT Devices Using the Router TL-WR902AC as Example"][803]
  • ["Breaking the Barrier: Post-Barrier Spectre Attacks"][970]
  • ["Breaking Down Adversarial Machine Learning Attacks Through Red Team Challenges"][987]
  • ["Breaking Down Multipart Parsers: File upload validation bypass"][966]
  • "Breaking the Flash Encryption Feature of Espressif’s Parts"
  • ["Bus Pirate 5: The Swiss ARRRmy Knife of Hardware Hacking"][886]
  • ["Buying Spying Insights into Commercial Surveillance Vendors"][733]
  • ["Bypassing EDRs With EDR-Preloading"][716]
  • ["Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws"][920]
  • "Chaining N-days to Compromise All":
    • [Part 1][836]
    • [Part 2][837]
    • [Part 3][838]
    • [Part 4][839]
    • [Part 5][840]
  • ["Check Point - Wrong Check Point (CVE-2024-24919)"][875]
  • ["Code injection on Android without ptrace"][874]
  • "CodeQL zero to hero": [Part 1][858] [Part 2][859] [Part 3][860] [Part 4][1191] [Part 5][1192]
  • ["Commonly Abused Linux Initial Access Techniques and Detection Strategies"][896]
  • ["Compiler Options Hardening Guide for C and C++"][877]
  • ["Continuously fuzzing Python C extensions"][734]
  • ["corCTF 2024: trojan-turtles writeup"][929]
  • ["corMine 1 and 2"][948]
  • ["Cross-Process Spectre Exploitation"][969]
  • ["CVE-2024-20356: Jailbreaking a Cisco appliance to run DOOM"][861]
  • ["CVE-2022-2586 Writeup"][849]
  • ["CVE-2020-27786 ( Race Condition + Use-After-Free )"][967]
  • ["CVE-2022-4262"][864]
  • ["CVE-2024-5274: A Minor Flaw in V8 Parser Leading to Catastrophes"][1012]
  • ["CVE-2023-6246: Heap-based buffer overflow in the glibc's syslog()"][697]
  • ["Declawing PUMAKIT"][989]
  • [Deep Dive into RCU Race Condition: Analysis of TCP-AO UAF (CVE-2024–27394)][1003]
  • ["Denial of Pleasure: Attacking Unusual BLE Targets with a Flipper Zero"][699]
  • ["Deobfuscating Android ARM64 strings with Ghidra: Emulating, Patching, and Automating"][683]
  • ["Dissecting a complex vulnerability and achieving arbitrary code execution in Ichitaro Word"][805]
  • ["Diving Deep into F5 Secure Vault"][918]
  • ["DJI - The ART of obfuscation"][705]
  • ["Docker Security – Step-by-Step Hardening (Docker Hardening)"][729]
  • ["Driving forward in Android drivers"][908]
  • ["Emulating RH850 architecture with Unicorn Engine"][853]
  • "Everyday Ghidra: Ghidra Data Types"
    • [Part 1][973]
    • [Part 2][974]
  • ["Exploit detail about CVE-2024-26581"][944]
  • ["Exploring AMD Platform Secure Boot"][701]
  • ["Exploring GNU extensions in the Linux kernel"][878]
  • ["Exploiting Android’s Hardened Memory Allocator"][1030]
  • ["Exploiting Empire C2 Framework"][723]
  • "Exploiting Enterprise Backup Software For Privilege Escalation":
    • [Part 1][906]
    • [Part 2][907]
  • "Exploiting Reversing (ER) series":
  • ["Exploiting Steam: Usual and Unusual Ways in the CEF Framework"][898]
  • ["Exploring object file formats"][684]
  • ["Extracting Secure Onboard Communication (SecOC) keys from a 2021 Toyota RAV4 Prime"][735]
  • "Fault Injection Attacks against the ESP32-C3 and ESP32-C6"
  • ["Fault Injection – Down the Rabbit Hole"][993]
  • "Finding Bugs in Kernel":
    • [Part 1][996]
    • [Part 2][997]
  • ["Flatlined: Analyzing Pulse Secure Firmware and Bypassing Integrity Checking"][883]
  • ["Flipping Pages: An analysis of a new Linux vulnerability in nf_tables and hardened exploitation techniques"][804]
  • ["From fault injection to RCE"][990]
  • ["From object transition to RCE in the Chrome renderer"][940]
  • ["Fuzzing between the lines in popular barcode software"][968]
  • ["Gaining kernel code execution on an MTE-enabled Pixel 8"][808]
  • ["Ghidra nanoMIPS ISA module"][873]
  • ["Going Native - Malicious Native Applications"][842]
  • "Google Chrome V8 CVE-2024-0517 Out-of-Bounds Write Code Execution"
  • ["GhostRace: Exploiting and Mitigating Speculative Race Conditions"][802]
  • ["GPUAF - Two ways of Rooting All Qualcomm based Android phones"][994]
  • ["GraphStrike: Anatomy of Offensive Tool Development"][712]
  • ["Hacking a 2014 tablet... in 2024!"][932]
  • ["Hacking a Smart Home Device"][691]
  • ["Hacking Android Games"][949]
  • ["Heap exploitation, glibc internals and nifty tricks"][938]
  • ["HEAP HEAP HOORAY — Unveiling GLIBC heap overflow vulnerability (CVE-2023–6246)"][818]
  • "Hi, My Name is Keyboard"
  • ["Hiding Linux Processes with Bind Mounts"][925]
  • ["How I Also Hacked my Car"][976]
  • ["How to Bypass Golang SSL Verification"][941]
  • ["Hunting Bugs in Linux Kernel With KASAN: How to Use it & What's the Benefit?"][995]
  • "Hunting down the HVCI bug in UEFI"
  • "Hunting for Unauthenticated n-days in Asus Routers"
  • "Iconv, Set the Charset to RCE":
    • [Part 1][870]
    • [Part 2][871]
  • ["Java Deserialization Tricks"][815]
  • ["JTAG Hacking with a Raspberry Pi"][851]
  • ["Kuiper Ransomware’s Evolution"][702]
  • ["Inside a New OT/IoT Cyberweapon: IOCONTROL"][1001]
  • ["Inside the LogoFAIL PoC: From Integer Overflow to Arbitrary Code Execution"][692]
  • ["Introduction to Fuzzing Android Native Components"][984]
  • "Learning LLVM":
    • [Part 1][934]
    • [Part 2][935]
  • ["LeftoverLocals: Listening to LLM responses through leaked GPU local memory"][687]
  • "Leveraging Binary Ninja il to Reverse a Custom ISA: Cracking the “pot of gold” 37C3"
  • ["Linux Kernel Attack Surface: beyond IOCTL. DMA-BUF"][999]
  • "Linux Kernel Exploitation":
    • ["Environment"][922]
    • ["ret2usr"][923]
  • ["Listen Up: Sonos Over-The-Air Remote Kernel Exploitation and Covert Wiretap – BlackHat USA 2024 Whitepaper"][939]
  • "ManageEngine ADAudit - Reverse engineering Windows RPC to find CVEs":
    • [Part 1][901]
    • [Part 2][902]
    • [Part 3][903]
  • ["Mind the Patch Gap: Exploiting an io_uring Vulnerability in Ubuntu"][809]
  • ["Mali GPU Kernel LPE"][786]
  • ["MalpediaFLOSSed"][814]
  • ["Microsoft BitLocker Bypasses are Practical"][718]
  • ["Modern implant design: position independent malware development"][690]
  • ["My new superpower"][688]
  • ["Not the Drones You're Looking For"][825]
  • "Operation triangulation":
    • ["Keychain module analysis"][823]
    • ["audio module analysis"][824]
  • ["OtterRoot: Netfilter Universal Root 1-day"][986]
  • ["Out-of-bounds read & write in the glibc's qsort()"][698]
  • ["PageJack: A Powerful Exploit Technique With Page-Level UAF"][951]
  • ["Page-Oriented Programming: Subverting Control-Flow Integrity of Commodity Operating System Kernels with Non-Writable Code Pages"][1000]
  • ["Patch Tuesday Diffing: CVE-2024-20696 - Windows Libarchive RCE"][835]
  • ["Pinning User-space Pages in the Linux Kernel: Exploring get_user_pages, pin_user_pages, and Page Table Walking"][983]
  • ["PixieFail: Nine vulnerabilities in Tianocore's EDK II IPv6 network stack"][711]
  • "Playing with libmalloc in 2024"
  • ["Puckungfu 2: Another NETGEAR WAN Command Injection"][730]
  • ["Pumping Iron on the Musl Heap – Real World CVE-2022-24834 Exploitation on an Alpine mallocng Heap"][910]
  • ["Pwn2Own Automotive 2024: Hacking the ChargePoint Home Flex (and their cloud...)"][933]
  • ["Pwning browsers like a kernel"][957]
  • "Pwn2Own: WAN-to-LAN Exploit Showcase":
    • ["Pwn2Own: WAN-to-LAN Exploit Showcase, Part 1"][950]
    • ["Pwn2Own: Pivoting from WAN to LAN to Attack a Synology BC500 IP Camera, Part 2"][942]
  • "Pwn2Own Toronto 2023":
    • ["How it all started"][829]
    • ["Exploring the Attack Surface"][830]
    • ["Exploration"][831]
    • ["Memory Corruption Analysis"][832]
    • ["The Exploit"][833]
  • ["Pwning a Brother labelmaker, for fun and interop!"][897]
  • "Pwntools 10x":
    • [Part 1][867]
    • [Part 2][868]
    • [Part 3][869]
  • ["Pygmy Goat"][972]
  • ["Recovering an ECU firmware using disassembler and branches"][921]
  • ["regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)"][919]
  • ["Resolving Stack Strings with Capstone Disassembler & Unicorn in Python"][846]
  • ["Retrofitting encrypted firmware is a Bad Idea"][1024]
  • ["Reverse engineering a car key fob signal "][801]
  • ["Reverse Engineering and Dismantling Kekz Headphones"][962]
  • ["Reverse Engineering Protobuf Definitions From Compiled Binaries"][820]
  • ["Reverse engineering the 59-pound printer onboard the Space Shuttle"][943]
  • ["Reverse Engineering the AM335x Boot ROM"][947]
  • ["Reverse Engineering The Stream Deck Plus"][1004]
  • "Ring Around The Regex"
    • [Part 1][955]
    • [Part 2][956]
  • ["RISCVuzz: Discovering Architectural CPU Vulnerabilities via Differential Hardware Fuzzing"][958]
  • ["RomCom exploits Firefox and Windows zero days in the wild"][981]
  • ["ROPing Routers from scratch: Step-by-step Tenda Ac8v4 Mips 0day Flow-control ROP -> RCE"][892]
  • ["Route to Safety: Navigating Router Pitfalls"][816]
  • ["Rooting a Hive Camera"][819]
  • ["SAME70 Emulator"][879]
  • "Say Friend and Enter":
    • [Part 1][812]
    • [Part 2][813]
  • ["Samsung NX related posts"][887]
  • ["Scavy: Automated Discovery of Memory Corruption Targets in Linux Kernel for Privilege Escalation"][975]
  • ["SECGlitcher (Part 1) - Reproducible Voltage Glitching on STM32 Microcontrollers"][862]
  • ["SELinux bypasses"][963]
  • ["SLUB Internals for Exploit Developers"][980]
  • ["SLUBStick: Arbitrary Memory Writes through Practical Software Cross-Cache Attacks within the Linux Kernel"][937]
  • ["Shell We Assemble?"][689]
  • ["Shellcode evasion using WebAssembly and Rust"][726]
  • "SMM isolation":
    • ["SMI deprivileging (ISRD)"][847]
    • ["Security policy reporting (ISSR)"][848]
  • ["SoK: Where’s the “up”?! A Comprehensive (bottom-up) Study on the Security of Arm Cortex-M Systems"][1049]
  • "Strengthening the Shield: MTE in Heap Allocators"
  • ["Take a Step Further: Understanding Page Spray in Linux Kernel Exploitation"][913]
  • ["The architecture of SAST tools: An explainer for developers"][739]
  • ["The Dark Side of UEFI: A technical Deep-Dive into Cross-Silicon Exploitation"][880]
  • ["The Definitive Guide to Linux Process Injection"][971]
  • ["The 'Invisibility Cloak' - Slash-Proc Magic"][924]
  • ["The Qualcomm DSP Driver - Unexpectedly Excavating an Exploit"][1007]
  • ["The rev.ng decompiler goes open source + start of the UI closed beta"][694]
  • ["The tale of a GSM Kernel LP"][850]
  • ["The Wild West of Proof of Concept Exploit Code (PoC)"][926]
  • "The Windows Registry Adventure":
    • [Part 1][914]
    • [Part 2][915]
    • [Part 3][916]
  • ["TIKTAG: Breaking ARM’s Memory Tagging Extension with Speculative Execution"][894]
  • ["Tony Hawk’s Pro Strcpy"][928]
  • ["Toolchain Necromancy: Past Mistakes Haunting ASLR"][732]
  • ["TP-Link Firmware Decryption C210 V2 cloud camera bootloaders"][988]
  • ["TP-Link TDDP Buffer Overflow Vulnerability"][695]
  • ["Two Bytes is Plenty: FortiGate RCE with CVE-2024-21762"][787]
  • ["Understanding AddressSanitizer: Better memory safety for your code"][889]
  • ["Understanding Unix Garbage Collection and its Interaction with io_uring"][891]
  • ["Understanding Windows x64 Assembly"][693]
  • ["Using Symbolic Execution to Devirtualise a Virtualised Binary"][936]
  • ["Utilizing Cross-CPU Allocation to Exploit Preempt-Disabled Linux Kernel"][985]
  • ["VBA: having fun with macros, overwritten pointers & R/W/X memory"][843]
  • ["Vulnerabilities of Realtek SD card reader driver"][1002]
  • ["Why Code Security Matters - Even in Hardened Environments"][953]
  • ["Windows Secure-Launch on Qualcomm devices"][811]
  • ["Windows Sockets: From Registered I/O to SYSTEM Privileges"][998]
  • ["Windows vs Linux Loader Architecture"][844]
  • ["Windows Wi-Fi Driver RCE Vulnerability – CVE-2024-30078"][954]
  • "Writing a Debugger From Scratch"
  • ["Writing a system call tracer using eBPF"][931]
  • ["Your NVMe Had Been Syz’ed: Fuzzing NVMe-oF/TCP Driver for Linux with Syzkaller"][854]
  • ["x64 Return Address Spoofing"][991]
  • ["x64 Call Stack Spoofing"][992]

2023

2022

2021

2020

2019

2018

2017

2016

2014

2011

Misc

Other Lists


Read more

Categories