FreeBSD 14.x kernel local privilege escalation via setcred(2)
fatgid.io
#infosec
DirtyFree: Linux kernel Data-Oriented Programming ()DOP exploitation via the arbitrary free primitive (paper)
leeyoochan.github.io/assets/pdf/D...
#Linux #infosec
Exploiting a page Use-After-Free in Qualcomm's AI Accelerator Linux Kernel Driver (qaic)
lukasmaar.github.io/posts/qaic-p...
Credits Lukas Maar
#infosec
Reverse engineering and exploiting TP-LINK TAPO security cameras
labs.taszk.io/articles/pos...
#infosec
Single-stepping attack on TrustZone-M via interrupt-latency leakage (Usenix paper)
www.usenix.org/system/files...
#infosec
Static Devirtualization of Themida
back.engineering/blog/09/05/2...
#infosec
HDD firmware hacking: dumping/analyzing/modifying the drive firmware and debugging via JTAG
icode4.coffee?p=1465
Credits Ryan Miceli
#infosec
Cisco Catalyst SD-WAN Controller auth bypass in vdaemon DTLS via spoofed vHub device type (CVE-2026-20182)
www.rapid7.com/blog/post/ve...
#infosec
This article demonstrates devirtualization of CodeVirtualizer/Themida protected code, however the techniques described here apply to pretty much every virtual machine based obfuscator. Only requiring ...