Articles

Articles

The long versions. CVE research, red team notes, and the occasional postmortem of a bug that turned out to be me.

all memory corruptionred teamactive directorymalwareweb
6 articles
CVE-2026-31337: A Heap Overflow Nobody Asked For

Three months of static analysis for a pre-auth RCE. The vendor's advisory called it a stability improvement.

Bypassing EDR by Asking Nicely

A study in userland unhooking, and a reminder that trusted process is doing a lot of work in that sentence.

From Zero to Domain Admin Before the Coffee Finished

An Active Directory chain that is somehow still your problem in 2026.

Reversing a Sample That Reversed Me First

Anti-analysis tricks, a packer with self-esteem issues, and one very smug string in the .rdata section.

The Length Field That Lied

A short one about trusting a size you did not compute yourself. Spoiler: don't.

A Race Condition and a Bad Decision

Two requests, one balance check, and a coupon system that briefly funded my coffee habit (in staging, relax).