top of page
Work Overview
LATEST PROJECTS
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque

Blog
Search


F5 BIG-IP APM CVE-2026-94127: hunt the OAuth server that took unauth traffic
CVE-2026-94127 turns unauthenticated traffic to an F5 BIG-IP APM OAuth Authorization Server VIP into remote code execution. CVSS 9.8, exploited, on CISA KEV with a forensic triage requirement. Here is the vendor hunt triad in KQL, Falcon CQL, Splunk and Kibana.
8 min read


Arista VeloCloud Orchestrator CVE-2026-93952: hunt the SD-WAN brain that answered without a login
CVE-2026-93952 lets an unauthenticated caller reach privileged VeloCloud Orchestrator internals when certificate-based Edge auth is on. CVSS 10.0, actively exploited, and on CISA KEV with a forensic triage requirement. Here is how to hunt it in KQL, Falcon CQL, Splunk and Kibana.
9 min read


Plugin4Shell: when the pin lies about the plugin
SHA pinning was supposed to freeze a reviewed plugin at one commit. Four major AI coding agents check out the pinned hash without verifying what landed. What Plugin4Shell allows, which agents are patched, and how to hunt it on developer endpoints.
9 min read


Hunt the JWT that should have been rejected
WSO2 fixed CVE-2026-5430 in May. In September, honeypots started catching forged admin JWTs. What the flaw allows, why patching does not end the question, and how to hunt the gap in KQL, Falcon CQL, Splunk and Kibana.
8 min read


Hunt the Check Point root that arrived before login
A pre-authentication stack overflow in Check Point's login path gives an unauthenticated attacker root on Security Management Server, Multi-Domain, and Log Server. What it means for policy and log trust, how to patch, and hunt queries you can run today.
7 min read


Hunt the Cisco ISE login that never needed a password
Cisco ISE CVE-2026-76460 is on CISA KEV with a 19 September deadline, and the API it abuses never asked for an admin session. Patch the branch, then hunt the access logs for what arrived before you did: unauthenticated API calls, root, and credentials that moved.
6 min read


Spain’s Reported AI Agent Data Breach: Could Your Business Stop the Same Attack?
A reported AI-driven intrusion in Spain raises a harder question than which model was used: what could one successful login reach? Our analysis examines attack hypotheses, evidence gaps, preventive controls, and a practical SMB response plan.
11 min read


PasteSwitch ClickFix: Hunt the Paste That Turns a Brand Ad Into a Stealer
A trusted-looking brand ad can lead to a dangerous paste. Learn how PasteSwitch ClickFix works, what to hunt across four security platforms, and how to contain endpoint and identity exposure.
7 min read


Is AI Putting Your Business at Risk? 10 Things SMBs Need to Do Now
A helpful AI tool can become a data exposure risk when access and rules are unclear. Follow these 10 AI security steps for small businesses, plus a practical 30-day plan for protecting data and managing compliance.
8 min read


Sogou CVE-2026-51990: How to Hunt for GRAYRABBIT
ACTION BRIEF • WINDOWS ENDPOINTS If your organization uses Sogou Input Method for Windows, verify its version and investigate suspicious activity from before it was patched. A malicious link can exploit a vulnerable installation to deliver GRAYRABBIT, a backdoor that gives an attacker access in the signed-in user’s context. Your first three actions: identify affected devices, update the software, and check whether attackers used it before the update. Patching closes the repor
7 min read


JFrog Artifactory: How Tokens Become Admin and How to Hunt the Abuse
A software repository sits between the people who build software and the systems that run it. When that repository is compromised, the investigation needs to answer more than whether someone accessed a server. It needs to establish whether the company can still trust the identities, credentials, and artifacts passing through it. Recent Artifactory exploitation illustrates why. Two vulnerabilities allow an attacker to obtain a token and escalate its authority. A separate vulne
8 min read


Hunt the commits POST that reads the GitLab box
Hunt GitLab CVE-2026-85706: unauth commits API path traversal. POST /repository/commits with file.path. watchTowr ITW Sep 11. CISA KEV due Sep 14.
7 min read


Hunt the Chrome-to-curl BlueMoon chain
The process tree still sitting on the box is not a closed Chrome patch ticket. It is chrome.exe (or msedge.exe / brave.exe) spawning cmd.exe, which spawns curl.exe, which writes %TEMP%\msgbox.exe or %TEMP%\ChromeUpdate.exe and runs it. Proofpoint tracks that default BlueMoon breakout, and the follow-on loaders are what operators actually keep. A hot stable build does not rewrite a curl stub that already ran from the broker. This hunt shop is not a second CVSS recap, and it is
8 min read


Hunt the FMC shell that opens AD for Qilin
The traces still on the management plane are not a closed patch ticket. They are a Tomcat JSP named home.jsp that Base64-decodes F6C1F0E7, a package_info.pl line that runs /var/tmp/license.tmp --lsm as root, and a Python socks5.py reverse-SSH tunnel that forwards LDAP, Kerberos, SMB, and WinRM out of Secure Firewall Management Center into Active Directory. Cisco Secure Firewall Management Center centrally manages your Secure Firewall estate. CVE-2026-20079 is a critical authe
4 min read


Hunt the ScreenConnect Guest that runs your scripts: 1.vbs through 4.vbs
The alert is wscript.exe, four short script names, and a Run key that looks like a Windows service helper. ScreenConnect is already on the box. Someone says helpdesk has a session. There is no ransomware family on the page, and the brand name on the client is the same one your techs use every day. That is when this chain wants you to call it a rogue RMM install and move on. Here is the plain version before the product jargon. A modified ScreenConnect client on one host watche
7 min read


Hunt the MP4 that never plays: NetSupport in an ISO-BMFF uuid box
You know the ticket. Someone downloaded a video. The ticket says media. The player refuses to open it. Antivirus already shrugged and called it an MP4. There is no ransomware family name on the alert, and the user swears they never watched anything. That unfair case is when this chain wants you to close it and move on. Here is the plain version before the box jargon. The file is a fake video shell. It is stuffed with a script. It is not a clip you failed to open. It is a carr
7 min read


Spring Ring: hunt the Teams helpdesk that never hits email
Unit 42 published Spring Ring today, 31 August 2026. The activity in the report is from January through April. This is leftover tradecraft, not a weekend outbreak. If you are hunting it because the write-up is new, you are hunting a gap that has been sitting in Teams since winter. The gap is Chat with anyone plus a voice call that never hits the mail gateway. They are not phish-mailing IT. A throwaway .onmicrosoft.com tenant named like a helpdesk opens a Teams chat. Then a 10
5 min read


PaperCut CVE-2026-81578: hunt the emergency patch that did not stay a patch
You have seen this ticket. Print is still working. Someone applied the first emergency PaperCut patch when it dropped, the queue came back, and they closed it. The Application Server web UI is still on the internet because print admins do not like taking that box down twice in one week. That is the hunt. Not the CVE number. The hunt is the emergency patch that did not stay a patch. CISA put CVE-2026-81578 and CVE-2026-82078 on KEV on 31 August 2026. If you only ran Patch 1, y
5 min read


NetScaler CVE-2026-8452 KEV: hunt the nsppe crash that did not stay a crash
Citrix NetScaler Gateway after a quiet nsppe crash. Hunt PHP under /var/vpn/theme. You have seen this ticket. VPN died, VPN came back, someone closed it as a blip. Citrix sold CVE-2026-8452 as a crash. CISA put it on KEV Monday. The federal clock is Saturday, 29 August. Builds with a fix: 13.1-63.21 or later, 14.1-73.32 or later. 12.1 and 13.0 have no fix. Patch is not the hunt. A patched box that already had a quiet respawn still needs the directory check. The hunt is not th
4 min read


SynkLoader: the lock screen plus the tunnel
PhishLocker is a fake Windows lock screen. The password plus the tunnel is the prize. On 18 August, Expel caught SynkLoader off a scheduled-task EDR hit that started in Microsoft Teams and ended in a fake lock screen. The EDR alert was the first clean look at a loader nobody had published yet. File times and compile stamps ran back to about 28 July. They named it SynkLoader. No crew name came with it. How SynkLoader arrives in Microsoft Teams The user had already been talked
3 min read
bottom of page
