Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver. A specially crafted NTFS volume can ca…
[ SECTION // VULNS // 52 ITEMS ]
3 groups across 14 tags
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver. A specially crafted NTFS volume can ca…
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert Mikhail Lozhnikov discovered a flaw that could cause a sudden system sh…
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely known Mimikatz tool, but unlike it, VMkatz's goal is to extract…
⚠️ Turned on Wi-Fi debugging — got Mamont In early May, a vulnerability CVE-2026-0073 was discovered on Android devices that allows remote execution of commands…
Dirty Frag 🐧💥 A week after the widely discussed Copy.Fail, researcher v4bel disclosed a new privilege escalation technique in the Linux kernel — Dirty Frag. As…
Why IDA doesn't fold constants and how to fix it 👨💻 Recently, obfuscation has been increasingly common in software where constants are replaced with arithmetic…
Recognizing STL code with ease 😐 During reverse engineering, we often encounter STL code whose analysis at first glance seems difficult. An inexperienced eye ma…
CFG again 👋 A common task when extracting malware configurations at scale is obtaining function boundaries and references. The most typical example is string de…
Deobfuscating .NET function names manually 🙌 .NET malware loves packers, obfuscation (of names, CFG, and other things), and multi-stage reflective image loading…
Idea for a SIEM correlation rule 💡 Although tracking the entire attack chain described in the posts above provides a complete picture, the strongest and simples…
Continuing to reproduce the attack from the post above 🔼 3️⃣ Creating a public API Gateway trigger (screenshot 1) At the end, we need to expose the function to…
Confusion Around WSUS Vulnerabilities: Setting the Record Straight 🕷 One of the most pressing vulnerabilities in Windows Server Update Services (WSUS) is a crit…
Attackers compromised dozens of NPM packages with ~2 billion downloads 🐾 What happened As part of a phishing campaign, maintainer Josh "Qix" Junon was…
Pass Back vulnerabilities: what they are and how dangerous they are 🧐 There is a whole class of vulnerabilities that at first glance look harmless, and even hav…
🧤 Now about the exploitation of the vulnerability CVE-2025-33073: • A domain account with the most ordinary privileges. • SMB signing is not enforced on the tar…
Reflection Relay. It never happened before, and now it's happening again (CVE-2025-33073) 😐 One of the most popular techniques for privilege escalation in an Ac…
[SCCM NTLM Relay] Hello everyone! 👋 My article about SCCM attacks was recently published. It describes in sufficient detail the testing lab, the attacks themsel…