KKernelzerainkernelzera.hashnode.dev·5d ago · 9 min readMalware Write-up: Analyzing a PDF-Disguised Multi-Stage .NET LoaderDisclaimer: This post describes malware analysis in an isolated lab. Do not run samples on a daily-use machine. Hashes and IOCs are shared for research and defense. Introduction I am an IT profession00
CGCristiano Gabrieliincrisdigital.hashnode.dev·5d ago · 15 min readBackend Exploits in ICS Systems — and Why Enclaves Matter More Than Ever Introduction There are moments in engineering where physics whispers a truth that software keeps forgetting. A diode does not negotiate. A photodiode does not improvise. They do not “trust” the signal00
VGVivek Goswamiinvivekgoswami.hashnode.dev·6d ago · 2 min readZico2 - Vulnhub 2026 WriteupBox: Zico2: 1 Author: Rafael Difficulty: Beginner–Intermediate Download: https://www.vulnhub.com/entry/zico2-1,210/ Goal: Get a foothold on the web server, pivot to a local user, then escalate to root10
AKAndriy Kovalenkoindeadpacket.hashnode.dev·Sep 4 · 24 min readThe Ransomware Attack Starts Before Encryption: The Warning Signs Security Teams Cannot Ignore in 2026Most people still picture ransomware as a malicious program that suddenly lands on a computer and starts encrypting files. That image is dangerously incomplete. In a modern enterprise attack, encrypti00
Xxvzf_optinxvzfopt.hashnode.dev·Sep 1 · 5 min readHarvesting OSINT from Search Engine results with SerpApi and Recon-NGXIntroduction In today’s short blog we’ll be taking a look at how I’ve recently harnessed the power of SerpApi to create the latest Recon-NGX module: the SerpApi LinkedIn Harvester. This is a slight de00
NNanoinblog.0xnano.com·Aug 31 · 7 min readMagical Palindrome | CTF WriteUpIf we take a look at the source code from the website, we'll see that there is a POST request being made with the data we send as the palindrome, based on the request, we'll get a different response 10
Mmehveteroinmehvetero.com·Aug 27 · 9 min readHow $951 Bought a $8.5M Vote: The Term Finance Governance ExploitZero bugs. Zero hacks. Just a vote. On August 23, 2026, at 06:25 UTC, an attacker executed a single parameterless function call on Ethereum and walked away with $8.5 million from Term Finance's vaults42H
ZZeroProtocolinwebpentestingdeepdive.hashnode.dev·Aug 21 · 6 min readMapping a Web App’s Attack SurfaceBefore any serious security testing begins, skilled penetration testers spend a surprising amount of time simply looking. Long before an exploit is fired off, an attacker is quietly reading URLs, para00
JAJoyce Abijaincybersage.hashnode.dev·Aug 20 · 6 min readYou don't have to be important to be Hacked"I’m just an ordinary person, I don't work for the government or FBI. Why would anyone want to hack me?” This question reflects one of the biggest misconceptions people have about cybersecurity: the b00
KRKaustubh Raiinraikaustubh.com·Aug 20 · 5 min readThe BApp That Almost Worked: Building curl2repeater 🔧There's always that one extension everyone has installed and nobody's actually checked. For BurpSuite, mine was Paste cURL to Repeater. I'd had it installed for months before I bothered actually looki30