Awesome Cybersecurity List
Ma collection personnelle d'articles de blog, de write-ups et de papers incontournables consacrés à la cybersécurité.
Pour une exploration plus approfondie des outils liés à la cybersécurité, consultez la liste dédiée Cybersecurity Tools.
Sommaire
2026
- "A 0-click exploit chain for the Pixel 9"
- [Part 1][1241]
- [Part 2][1242]
- [Part 3][1243]
- ["A Brief Analysis of a Vulnerability in the Glibc (CVE-2025-4802)"][1277]
- ["A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets"][1283]
- ["About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection"][1317]
- ["Achieving remote code execution in LangSmith Playground using unsafe template formatting"][1271]
- ["AI-FI: Reproducing adb to root on Google's TV Streamer using Claude in less than 15 minutes"][1307]
- ["Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover"][1305]
- ["Black Box Probing: a Security Analysis of Xiaomi's MJA1 Secure Chip"][1306]
- ["Break the Trust Chain of the Ethereum Phone"][1316]
- ["BRIDGEROUTER: Automated Capability Upgrading of Out-Of-Bounds Write Vulnerabilities to Arbitrary Memory Write Primitives in the Linux Kernel"][1293]
- ["Carbonara: The MediaTek exploit nobody served"][1249]
- ["CHECK Removed, Context Confused, Checkmate Achieved"][1287]
- ["Clang Hardening Cheat Sheet - Ten Years Later"][1239]
- ["CrackArmor: Multiple vulnerabilities in AppArmor"][1267]
- ["Creative approaches to coding FUD Stagers"][1299]
- "CVE-2025-38352":
- ["In-the-wild Android Kernel Vulnerability Analysis + PoC"][1224]
- ["Extending The Race Window Without a Kernel Patch"][1225]
- ["Uncovering Chronomaly"][1265]
- ["CVE-2026-0714 TPM-sniffing LUKS Keys on an Embedded Device"][1235]
- ["CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller"][1303]
- ["Damned OOB"][1297]
- ["Defeating Anti-Reverse Engineering: A Deep Dive into the 'Trouble' Binary"][1237]
- ["DiceCTF 2026 Quals - cornelslop: Turning an RCU Double Free into a Cross-Cache Kernel Exploit"][1266]
- ["DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write"][1302]
- [Dirty Frag][1300]
- ["DIRTYFREE: Simplified Data-Oriented Programming in the Linux Kernel"][1238]
- ["Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC"][1223]
- ["Exploiting CVE-2024-1065 via the Page Cache"][1315]
- ["Exploiting MediaTek's Download Agent"][1232]
- ["FatGid: A four-byte type, an eight-byte stride, one root shell"][1318]
- ["From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)"][1245]
- ["From KernelSnitch to Practical msg_msg/pipe_buffer Heap KASLR Leaks"][1279]
- "Fuzzing GPSD"
- ["The Lexer Harness"][1311]
- ["Lessons Learned"][1312]
- ["The Bugs"][1313]
- ["General Graboids: Worms and Remote Code Execution in Command & Conquer"][1250]
- ["Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs"][1248]
- ["Here We Go Again: A Five-Bug Chain to Arbitrary APK Install on Samsung S25"][1295]
- ["HDD Firmware Hacking Part 1"][1290]
- "Hooked on Linux"
- ["Rootkit Taxonomy, Hooking Techniques and Tradecraft"][1281]
- ["Rootkit Detection Engineering"][1282]
- ["How LLMs Actually Work"][1308]
- ["Jenny was a Friend of Mine - MCPs and Friends"][1274]
- ["Intercepting OkHttp at Runtime With Frida - A Practical Guide"][1253]
- ["Leveling Up Secure Code Reviews with Claude Code"][1273]
- ["Living off the Process"][1236]
- ["Make it Blink: Over-the-air Exploitation of the Philips HUE Bridge"][1294]
- ["Mitmproxy for Fun and Profit: Interception and Analysis of Application Traffic"][1284]
- ["N-Day Research with AI: Using Ollama and n8n"][1263]
- ["Needle in the haystack: LLMs for vulnerability research"][1275]
- ["Now You See mi: Now You're Pwned"][1278]
- ["Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race"][1276]
- ["On the Clock: Escaping VMWare Workstation at Pwn2Own Berlin 2025"][1252]
- ["Out-of-Cancel: A Vulnerability Class Rooted in Workqueue Cancellation APIs"][1301]
- ["Page-level UAF exploitation"][1268]
- ["PageJack in Action: CVE-2022-0995 exploit"][1270]
- ["Pwning Supercomputers - A 20yo vulnerability in Munge"][1255]
- ["Reverse Engineering the Tapo C260 and Tapo Discovery Protocol v2"][1219]
- ["Revisiting Two-Shot Kernel Shellcode Execution From Control Flow Hijacking"][1288]
- "Sleeping Beauty"
- ["Putting Adaptix to Bed with Crystal Palace"][1309]
- ["CFG, CET, and Stack Spoofing"][1310]
- ["SoK: All You Ever Wanted to Know About Bootloader Security But Were Afraid to Ask"][1314]
- ["Some notes on the security properties of the pipe_buffer kernel object"][1285]
- ["Static Devirtualization of Themida"][1292]
- ["Table Manners: Diving into Linux Pagetables exp techniques"][1280]
- ["TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere"][1291]
- ["The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation"][1296]
- ["The Hidden Risk of Side-Channel Attacks on Post Quantum Cryptography"][1298]
- ["The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance"][1234]
- ["Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold"][1304]
- ["TP-Link ER605 DDNS Pre-Auth RCE: Chaining CVE-2024-5242, CVE-2024-5243, CVE-2024-5244"][1264]
- ["Trailmark turns code into graphs"][1286]
- ["TREVEX: A Black-Box Detection Framework For Data-Flow Transient Execution Vulnerabilities"][1289]
- ["Unauthenticated RCE in NetSupport Manager - A Technical Deep Dive"][1244]
- ["V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome’s Memory"][1262]
- VulHunt
- ["A High-Level Look at Binary Vulnerability Detection"][1257]
- ["Detecting a Remote Code Execution Vulnerability in rsync"][1258]
- ["Vulnerability REsearch using VulHunt"][1259]
- ["Inside the Binary Vulnerability Analysis Framework"][1260]
- ["Agentic Vulnerability Research with VulHunt"][1261]
- ["When NAS Vendors Forget How TLS Works"][1251]
- ["Windows ARM64 Internals: Pardon The Interruption! Interrupts on Windows for ARM"][1246]