
Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from 2023-2026.
This repository contains a collection of technical reports, threat intelligence briefs, and offensive security research focused on the 2025-2026 cybersecurity landscape.
Reports are categorized using the following prefix system:
| File | Type | Description |
|---|---|---|
| OS-IS-CVE-2026-58457-07-2026.md | OS/IS | Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) Unauthenticated OS command injection |
| OS-IS-CVE-2026-13768-07-2026.md | OS/IS | Azure IoT Hub RCE via shared key access |
| OS-IS-CVE-2026-39047-07-2026.md | OS/IS | Epson L14150 (firmware FL27PB) a remote buffer overflow in Epson multifunction printers (notably the L14150 FL27PB) when processing malformed or oversized payloads over the RAW TCP printing protocol (typically port 9100). |
| OS-IS-CVE-2026-48558-07-2026.md | OS/IS | SimpleHelp OIDC Auth Bypass a critical authentication bypass vulnerability in SimpleHelp Remote Monitoring and Management (RMM) software. |
| OS-IS-CVE-2026-6307-07-2026.md | OS/IS | V8 Security (Longinus) Report Analysis of CVE-2026-6307, nicknamed "Longinus", a critical vulnerability in V8's TurboFan compiler affecting JavaScript-to-WebAssembly call inlining and FrameState merging. |
| OS-IS-IPV6FRAGESCAPE-06-2026.md | OS/IS | ipv6 LPE Analysis the ipv6_frag_escape proof‑of‑concept (PoC) exploit released in June 2026 |
| OS-IS-CHAOS-OP-06-2026.md | OS/IS | Engagement Report Details the offensive security operations conducted against the Supabase Edge Functions associated with the chaosfoundry.digital infrastructure |
| OS-IS-DIRTYSPLOITS-06-2026.md | OS/IS | A Mix of Linux Exploits Analysis of recent DirtyClone, DirtyFrag, Fragnesia, pedit-cow, PinTheft, CopyFail, dirtycbc, ssh-keysign-pwn, nft-catchall-uaf and pintheft(non uring_io) |
| OS-IS-EXPLOITARIUM-RESEARCH-06-2026.md(.yar) | OS/IS | Exploitarium Research: Analysis of Exploitarium 0-day exploits. Source: https://github.com/bikini/exploitarium |
| IS-LS-Q1-Q2-05-2026.md | LS/IS | 2026 Mid-Year Landscape: Analysis of Agentic AI, npm supply chain attacks (Axios/TanStack), and the Canvas LMS breach. |
| IS-REPORT-05-2026.md | IS | Supply Chain & Workflow Poisoning: Deep dive into TeamPCP, GitHub internal breaches, and Linux "Dirty Frag" vulnerabilities. |
| IS-IRAN-APT-03-2026.md | IS | Iranian Cyber Update: Coverage of the Stryker Corporation attack and the KadNap P2P botnet. |
| OS-REFAMPv2-02-2026.md | OS | DDoS & Botnets: Implementation of Reflection/Amplification attacks and Mirai-family C2 evasion. |
| IS-LS-PROJECTION-Q1-01-2026.md | LS | 2026 Projections: Early 2026 forecasts regarding Cloud infrastructure and polymorphic malware. |
| File | Type | Description |
|---|---|---|
| OS-IS-BYOVD-11-2025.md | OS/IS | Kernel Research: Bring Your Own Vulnerable Driver (BYOVD) tactics and Linux eBPF rootkit development. |
| OS-LS-ADVANCED-RCE-WEBVULN-11-2025.md | OS/LS | Web Vulnerabilities: Advanced RCE chains, V8 Type Confusion, and modern GraphQL/SAP exploitation. |
| IS-IRAN-0119-2025.md | IS | Iranian Capabilities: Comprehensive overview of IRGC/MOIS TTPs and their malware arsenal (MuddyWater, OilRig, etc.). |
To maintain a high level of technical clarity, these reports utilize specific formatting standards. Ensure your markdown viewer supports the following extensions for the best experience:
Several reports (specifically the DDoS and Kernel research) use LaTeX/KaTeX for expressing amplification factors, execution flows, and cryptographic projections.
$ \text{Factor} = \frac{\text{Response}}{\text{Request}} $We use GitHub-style callouts to highlight critical warnings, especially regarding legal ethical boundaries and lab safety.
> [!WARNING]
> This document is authorized exclusively for internal red-team exercises within air-gapped laboratory networks.
> [!NOTE]
> Information generated via A.T.L.A.S assisted research.
Architecture and attack flow diagrams are provided in ASCII format to ensure compatibility across all terminal-based and web-based markdown editors.
[Attacker] ---> [OIDC Token Abuse] ---> [Cloud Environment]
Code samples are provided with language-specific syntax highlighting. Offensive samples often include "Production-Quality" annotations to explain evasion mechanics line-by-line.
The following table summarizes all vulnerabilities discussed across the research reports, sorted by year.