What We Do
The Process
Latest Posts
[Technical Research]BYOVD: Detection and Prevention on a Hardened Windows 11 Endpoint
[Technical Research]The State of Exposed VPNs in Europe
[Technical Research]wp2shell (CVE-2026-63030 & CVE-2026-60137): Unauthenticated SQL Injection in WordPress Core
[Advisory]TIBER-EU and DORA: What Financial Institutions Need to Understand Before the Notification Arrives
[Advisory]NIS2 Compliance in Portugal: Evidence Over Documentation
From the operators
Research, walkthroughs, and opinions from our operators. The same work that goes into our engagements, shared publicly.
We ran a Europe-wide responsible disclosure campaign to find organizations still exposed to known VPN vulnerabilities, trace the vulnerable devices to their owners, and get them patched. Around 800 organizations assessed. Only a minority responded.
Read More →wp2shell chains a REST API batch route confusion with a SQL injection in WP_Query into unauthenticated blind SQLi, now patched in WordPress Core. RCE is possible but not automatic. It needs a cracked admin password and plugin uploads enabled. Here is the real chain and how to patch it.
Read More →DORA is live. TLPT regulatory standards are active. Notifications are being sent. Here is what financial institutions in the EU need to understand about TIBER-EU before the letter arrives.
Read More →Decree-Law 125/2025 is in force. We break down what Article 27 requires, what CNCS auditors actually check, and where organisations in Portugal are failing.
Read More →Most EDRs rely on kernel callbacks to see what happens on an endpoint. We show how BYOVD attacks zero those callbacks, why ML detection does not save you, and what defenders should actually do about it.
Read More →We're releasing acl-abuse-havoc, an open-source BOF toolkit for abusing Active Directory ACL misconfigurations through Havoc C2. The centrepiece is acl-shadow, a full Shadow Credentials attack chain that runs entirely in-memory.
Read More →