Writeups, including the ones that went nowhere.

Firmware reverse engineering done in public, with the disassembly and the dead ends left in. Some of this found a buyer. Most of it did not.

Offline WordPress Scanners: What They Find and What They Don't

Four offline WordPress vulnerability scanners compared on what they detect, how they source advisory data, and whether they tell you when their database has no coverage of a plugin.

Read →

80 Days on an IoT DVR: Three Real Bugs, No Bounty

HiSilicon ARM32 surveillance firmware across 28,006 internet-facing units. A hardcoded AES key, an unsigned root upgrade chain, and a two-character blocklist bypass, with the disassembly for each.

Read →

Published advisories and patch analysis.

Independent research into supply-chain and CMS vulnerabilities, with full technical analysis. Where an issue is unpatched upstream we publish the analysis and reproduction steps, not a turnkey weapon.

Advisory Severity Class Target & impact
decompress CWE-59 High CWE-59 Symlink escape and hardlink write bypass in decompress@4.2.1, a package with millions of weekly npm downloads. Patch analysis published; reproduction steps documented.
CVE-2026-52824
GHSA-jr9p-4h4j-6c58
High CWE-287 Default APP_SECRET enabling cryptographic session forgery in Kimai ≤ 2.57.0, resulting in administrative session hijack.
Tianwen ERP Critical CWE-434 Unauthenticated arbitrary file upload in Tianwen Property Management ERP. Vendor notified; reproduction steps documented in the advisory.
braces DoS Medium CWE-400 Patch analysis of CVE-2024-4068: comma-separated brace expansion strings remain unmitigated in braces@3.0.3.

Reporting a vulnerability in your own product? Responsible disclosure is handled directly, no middleman. Email the details and we will confirm receipt and coordinate a fix timeline with you.