About OFFCEPT
Built by operators who spent years breaking into networks before building a company around it.
Learn More

From the operators

Blog

Research, walkthroughs, and opinions from our operators. The same work that goes into our engagements, shared publicly.

Technical Research18 July 20265 min read

wp2shell (CVE-2026-63030 & CVE-2026-60137): Unauthenticated SQL Injection in WordPress Core

wp2shell chains a REST API batch route confusion with a SQL injection in WP_Query into unauthenticated blind SQLi, now patched in WordPress Core. RCE is possible but not automatic. It needs a cracked admin password and plugin uploads enabled. Here is the real chain and how to patch it.

Read More →
Advisory29 May 202612 min read

TIBER-EU and DORA: What Financial Institutions Need to Understand Before the Notification Arrives

DORA is live. TLPT regulatory standards are active. Notifications are being sent. Here is what financial institutions in the EU need to understand about TIBER-EU before the letter arrives.

Read More →
Advisory25 May 202610 min read

NIS2 Compliance in Portugal: Evidence Over Documentation

Decree-Law 125/2025 is in force. We break down what Article 27 requires, what CNCS auditors actually check, and where organisations in Portugal are failing.

Read More →
Technical Research24 May 202614 min read

Killing EDR visibility at the kernel: BYOVD

Most EDRs rely on kernel callbacks to see what happens on an endpoint. We show how BYOVD attacks zero those callbacks, why ML detection does not save you, and what defenders should actually do about it.

Read More →
Technical Research18 May 20268 min read

ACL Abuse Havoc, a BOF toolkit for AD ACL exploitation via Havoc C2

We're releasing acl-abuse-havoc, an open-source BOF toolkit for abusing Active Directory ACL misconfigurations through Havoc C2. The centrepiece is acl-shadow, a full Shadow Credentials attack chain that runs entirely in-memory.

Read More →