What We Do
The Process
Latest Posts
[Technical Research]We warned 800 organizations about their exposed VPNs. Most never replied.
[Technical Research]wp2shell (CVE-2026-63030 & CVE-2026-60137): Unauthenticated SQL Injection in WordPress Core
[Advisory]TIBER-EU and DORA: What Financial Institutions Need to Understand Before the Notification Arrives
[Advisory]NIS2 Compliance in Portugal: Evidence Over Documentation
[Technical Research]Killing EDR visibility at the kernel: BYOVD
From the operators
Research, walkthroughs, and opinions from our operators. The same work that goes into our engagements, shared publicly.
wp2shell chains a REST API batch route confusion with a SQL injection in WP_Query into unauthenticated blind SQLi, now patched in WordPress Core. RCE is possible but not automatic. It needs a cracked admin password and plugin uploads enabled. Here is the real chain and how to patch it.
Read More →DORA is live. TLPT regulatory standards are active. Notifications are being sent. Here is what financial institutions in the EU need to understand about TIBER-EU before the letter arrives.
Read More →Decree-Law 125/2025 is in force. We break down what Article 27 requires, what CNCS auditors actually check, and where organisations in Portugal are failing.
Read More →Most EDRs rely on kernel callbacks to see what happens on an endpoint. We show how BYOVD attacks zero those callbacks, why ML detection does not save you, and what defenders should actually do about it.
Read More →We're releasing acl-abuse-havoc, an open-source BOF toolkit for abusing Active Directory ACL misconfigurations through Havoc C2. The centrepiece is acl-shadow, a full Shadow Credentials attack chain that runs entirely in-memory.
Read More →