BLOG2022-08-12T20:52:23+00:00

Survey Says…. Remote Code Execution: CVE-2026-90817

By |September 27th, 2026|Categories: BUG BOUNTY, EXPLOITS, PENTESTING, RED TEAM|Tags: , , , , |

A double-decoding flaw exposed REDCap's Data Import controller to public survey users. A client-controlled PHP stream then turned CSV BOM cleanup into a Blade cache overwrite and unauthenticated RCE.

One Login, Two RCEs: CVE-2026-90822 and CVE-2026-90823

By |September 21st, 2026|Categories: BUG BOUNTY, EXPLOITS, PENTESTING, RED TEAM|

A stack overflow in FatPipe's privileged authentication helper looked like the hard path to root. Tracing its web reachability exposed a second flaw in the middle: unauthenticated command injection in xtremed.

CVSS Is Not A Negotiation

By |September 15th, 2026|Categories: BUG BOUNTY, EXPLOITS, PENTESTING, RED TEAM|Tags: , , , , |

CVSS scoring disputes often come down to mixing intrinsic vulnerability severity with deployment assumptions, exploit-development effort, remediation pressure, and bounty economics. This guide explains how to keep those factors in the right metrics.

Python Dependency Confusion All the Way Down

By |March 30th, 2026|Categories: RED TEAM|Tags: , , , , , |

With the recent LiteLLM supply chain compromise making headlines, we wanted to take a deep dive into how an advanced attacker can go far beyond a basic dependency confusion attack against modern technology companies — and what defenders should be looking for.

Go to Top