Firmware reverse engineering done in public, with the disassembly and the dead ends left in. Some of this found a buyer. Most of it did not.
Four offline WordPress vulnerability scanners compared on what they detect, how they source advisory data, and whether they tell you when their database has no coverage of a plugin.
Read →HiSilicon ARM32 surveillance firmware across 28,006 internet-facing units. A hardcoded AES key, an unsigned root upgrade chain, and a two-character blocklist bypass, with the disassembly for each.
Read →Independent research into supply-chain and CMS vulnerabilities, with full technical analysis. Where an issue is unpatched upstream we publish the analysis and reproduction steps, not a turnkey weapon.
| Advisory | Severity | Class | Target & impact |
|---|---|---|---|
| decompress CWE-59 | High | CWE-59 | Symlink escape and hardlink write bypass in decompress@4.2.1, a package with millions of weekly npm downloads. Patch analysis published; reproduction steps documented. |
| CVE-2026-52824 GHSA-jr9p-4h4j-6c58 |
High | CWE-287 | Default APP_SECRET enabling cryptographic session forgery in Kimai ≤ 2.57.0, resulting in administrative session hijack. |
| Tianwen ERP | Critical | CWE-434 | Unauthenticated arbitrary file upload in Tianwen Property Management ERP. Vendor notified; reproduction steps documented in the advisory. |
| braces DoS | Medium | CWE-400 | Patch analysis of CVE-2024-4068: comma-separated brace expansion strings remain unmitigated in braces@3.0.3. |
Reporting a vulnerability in your own product? Responsible disclosure is handled directly, no middleman. Email the details and we will confirm receipt and coordinate a fix timeline with you.