How an out-of-bounds read in MariaDB's .frm metadata parser can be turned into a forged C++ object with a fake vtable, reaching arbitrary code execution as the mariadbd process (MDEV-40571).
Why random-mutation fuzzers lose coverage on structured protocols, and how to model a PDU with a grammar to systematically traverse field combinations. Covers And/Or combinatorial-explosion control, automatic boundary-value generation, automatic Size-field computation, and Lua-based checksum recomputation.
How to analyze automotive ECU architectures (PPC-VLE, TriCore) that IDA, Ghidra, and Binary Ninja don't support out of the box. The IR-as-common-language structure of RE tools, the formula for implementing an architecture plugin, and how non-standard calling conventions poison data-flow analysis, with the fix.
When started with --reranking, llama.cpp lets a remote attacker trigger a denial of service (std::bad_alloc, HTTP 500) via a negative top_n on POST /rerank (CVE-2026-52132).
A crafted GGUF file with an empty metadata key reaches an assertion in llama.cpp's gguf_reader::read and aborts the process. Affects any binary that loads GGUF files (CVE-2026-52131).
A deeply nested JSON schema exhausts the recursion stack in llama.cpp's grammar converter, crashing the server. Only POST /completions is affected (CVE-2026-52130).
Multiple studies conclude that an LLM agent's completion bias and overconfidence cannot be corrected by prompting. This post lays out the design principles of a vulnerability-checking automation harness that makes "surveyed everything" and "0 vulnerabilities" computed from an HMAC receipt ledger and deterministic hooks rather than from the model's narrative. A "200 OK" without a negative control is not confirmation.
Masked FVE record: a data API with no authentication or authorization returned real-name rosters of residents' association officers, facility staff contacts and employee numbers in bulk.
An anatomy of how Achilles Communications Certification (ACC) tests PLCs, RTUs, and industrial switches. It covers the classification of 31 L1 / 54 L2 test cases, the seven test types (Scans, Storms, Fuzzers, Grammars), control-protocol coverage from the IP stack up to DNP3, Modbus, and IEC 61850, and what the Normal/Warning/Failure monitors actually determine.
A primer map for anyone new to IEC 62443-4-2. Covers why the 62443 series is divided by audience rather than topic, the four faces of SL and the three faces of SL 0, the Component Requirements (CR) of the seven Foundational Requirements (FR1-7), the SAR/EDR/HDR/NDR component types, and the distinctly industrial-security idea of "maintain degraded mode instead of preventing DoS."
When a manufacturer says "we're IEC 62443-4-2 SL2 certified," the sentence alone tells you nothing about what was actually verified. This post dissects the arithmetic behind the three numbers (RA, NAR, TR) printed on a certificate, the decisive difference between N/A and out-of-scope, and why confusing SL-T/SL-C/SL-D/SL-A ruins any reading of the certificate.
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is the world's first law to mandate cybersecurity for physical products with digital elements. This post lays out the incoming timeline (reporting obligations on 2026-09-11, full application on 2027-12-11), how 62443 becomes the basis of CE marking as a harmonised standard, and the 6 CRA-specific requirements 62443 does not cover.
Many legacy industrial control protocols were designed without authentication or integrity guarantees. This wasn't a mistake — it was a rational choice for the 2000s, premised on an air-gapped network, and this post examines how that choice became today's security debt, using open protocols (Modbus, DNP3) as examples.
A defender's retrospective on the attack surface of the MikroTik RB4011 using only public hardware specifications and already-patched CVEs. It organizes router hardening principles centered on the CVE-2023-32154 case from Pwn2Own Toronto 2022.
A breakdown of four open-source agent frameworks (CAI, PentAGI, OpenManus, CRS) grounded in their actual code and papers, plus what DARPA AIxCC revealed about the current state of autonomous vulnerability discovery and patching.
From what an agent is, to sub-agent interaction, to a catalog of multi-agent patterns, to the harness engineering that wraps it all. A single-article summary of the fundamentals of designing AI agent systems.
A single-page summary of four standards in the agent ecosystem. MCP (tool access), A2A (agent-to-agent communication), AGENTS.md (project rules), and SKILL.md (task procedures) — what each standardizes and how they complement one another.
Starting from Naive RAG's 7 limitations, this post compares 8 variants including Graph RAG, RAPTOR, and Agentic RAG, and covers practical design for embedding dimensions, chunking, and hybrid search through the 3 levels of agent memory.
In an era where LLM agents have started solving CTFs automatically, how do you design a challenge that "machines struggle with but a skilled human solves in a reasonable time"? This organizes the anti-LLM design principles that target the structural limits of transformers — state tracking, carry propagation, tokenization, and context loss.
An explanation of the MFDS medical device cybersecurity approval/review guideline (Guidance No. 0995-05, 2025.01.10) on the basis of IEC 62443-4-2. It organizes, from the perspective of regulatory practitioners and developers, the structure of the 35 requirements across 6 categories, the mapping to the IEC 62443 FR/CR system, the approval submission requirements, and the transition schedule before and after revision.
A defender's explanation of how the three international standards that govern the safety and cybersecurity of medical device software — ISO 14971, IEC 62304, and IEC 62443 — each own a different axis and where they overlap.
Masked FVE record: a null accessToken was accepted and order IDs increased sequentially, so anyone could read other customers' phone numbers, names and payment methods without authentication.
Masked FVE record: a missing authentication-level check let an anonymous session read a victim's resident-number-based linking information (CI) and identity details.
The architecture of a hierarchical multi-agent system that performs autonomous vulnerability assessment, from network reconnaissance to exploit validation. Seven specialists, a five-phase workflow, and the confirmation oracle, execution isolation, and RoE reference monitor that pull the judgment authority out of the model.
How a stack buffer overflow was found in the compression utility dact using AFL and AddressSanitizer. Root-cause analysis of a file_extd_urls array overflow triggered by a crafted DACT header.
Exploiting HackSys Extreme Vulnerable Driver (HEVD) on Windows 7 x86: a kernel stack buffer overflow using token-stealing shellcode, and privilege escalation via a Write-What-Where overwrite of the HalDispatchTable
Static reverse engineering of two 32-bit PE binaries identified as Ryuk ransomware (Hermes variant). Covers the dropper/loader and the encryption payload, including persistence, process injection, and VSS deletion behavior.
A draft design for blackbox fuzzing of the LS Electric PLC system, built on analysis of the XGT protocol. Covers automated mutation strategy, crash triage, and the monitoring infrastructure for discovering vulnerabilities in industrial control systems.
An in-depth analysis of two vulnerabilities found in Netis MEX605 router firmware v2.00.06: OS command injection via the ping diagnostic tool, and DOM-based XSS in the NTP server configuration.
Analysis of HTTP Request Smuggling (HTTP DeSync Attack): how CL.TE and TE.CL deserialization vulnerabilities bypass frontend security controls and poison the backend request queue
A command injection vulnerability found in the WPS PIN handling of the E5600 router — authenticated remote code execution via a crafted WPS PIN parameter
Analysis of an Integer Overflow (SMBGhost) and an uninitialized kernel memory leak (SMBleed) in the SMBv3.1.1 decompression routine, and a Pre-Auth RCE achieved by chaining the two bugs
A step-by-step walkthrough of ARM binary exploitation: reading ARM assembly by hand (hand-ray), stack buffer overflows, ROP gadget chaining, and the ret2zp (return-to-zero-page) technique
A practical guide to using angr for CTF binary analysis: symbolic execution basics, find/avoid strategies, setting up symbolic registers and stack arguments, and solving crackmes automatically
Mounting a crafted btrfs image twice causes an rwsem_down_write_slowpath use-after-free because rwsem_owner_flags returns an already freed task_struct pointer.
A setxattr operation after mounting a crafted ext4 image causes a slab-out-of-bounds write in ext4_xattr_set_entry because a large old_size value is used in a memset call.
__btrfs_free_extent in fs/btrfs/extent-tree.c calls btrfs_print_leaf in a certain ENOENT case, leaking potentially sensitive register values to local users through dmesg.
ext4_empty_dir in fs/ext4/namei.c allows a NULL pointer dereference because ext4_read_dirblock(inode,0,DIRENT_HTREE) can return zero after a crafted ext4 image is mounted.
btrfs_root_node in fs/btrfs/ctree.c allows a NULL pointer dereference because rcu_dereference(root->node) can return zero when a crafted btrfs image is mounted.
A crafted btrfs image triggers a NULL pointer dereference in btrfs_verify_dev_extents because fs_devices->devices is mishandled inside find_device (fs/btrfs/volumes.c) in Linux kernels before 5.1.
An in-depth analysis of checkm8, the BootROM exploit for Apple A5-A11 SoCs: the USB DFU stack use-after-free, heap grooming, and AArch64 shellcode execution.
Writeups for Reversing.kr's Easy series -- Easy CrackMe, Easy ELF, Easy Keygen, Easy Unpack, and Replace -- solved through static and dynamic analysis.
Progressing through the LOB (Lord of Buffer Overflow) wargame: Gate (basic BOF), Iron_golem (partial RELRO bypass), Dark_eyes (NX + ASLR) — tracing the evolution of Linux exploitation techniques.
A shellcode injection writeup for Pwnable.tw's Start challenge, exploiting a stack-based buffer overflow in a minimal 32-bit Linux binary with no NX protection.
Solving DEF CON 22 CTF Qualifier's r0pbaby: leaking the shared library base, finding gadgets via PLT/GOT, and building a 64-bit ROP chain to call system().