Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver. A specially crafted NTFS volume can ca…
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver. A specially crafted NTFS volume can ca…
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert Mikhail Lozhnikov discovered a flaw that could cause a sudden system sh…
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely known Mimikatz tool, but unlike it, VMkatz's goal is to extract…
⚠️ Turned on Wi-Fi debugging — got Mamont In early May, a vulnerability CVE-2026-0073 was discovered on Android devices that allows remote execution of commands…
Dirty Frag 🐧💥 A week after the widely discussed Copy.Fail, researcher v4bel disclosed a new privilege escalation technique in the Linux kernel — Dirty Frag. As…
Copy.Fail 🐧 Researchers discovered a bug in the Linux kernel that has existed in systems since 2017 and affects virtually all distributions. Vulnerability CVE-2…
Confusion Around WSUS Vulnerabilities: Setting the Record Straight 🕷 One of the most pressing vulnerabilities in Windows Server Update Services (WSUS) is a crit…
How to CVE-2025-54916? Low-effort vulnerability research 💻 Hi, ESC-VR here. The Telegram post format is rarely suitable for analyzing complex vulnerabilities, b…
Pass Back vulnerabilities: what they are and how dangerous they are 🧐 There is a whole class of vulnerabilities that at first glance look harmless, and even hav…
Continuing previous publications, we explain how to detect the CVE-2025-33073 vulnerability 🕵️♂️ 1️⃣ Monitor DNS queries with a Marshalled suffix In Reflection…
🧤 Now about the exploitation of the vulnerability CVE-2025-33073: • A domain account with the most ordinary privileges. • SMB signing is not enforced on the tar…