Exploit Development
FreeBSoD: Leveraging Language Models to Find and Exploit Kernel Bugs (Part 1 of 2)
Overview Earlier this year, a team at Praetorian was building Constantine, our automated 0-day discovery engine. I wanted to find techniques worth folding into it, so on the side I started poking ...
What Mythos Tells Us About the Future of Vulnerability Management
Security teams have operated on the same assumption for years: when a vulnerability gets disclosed, there’s time to deal with it. Not much, but enough to assess, prioritize, and patch before anyone ...
Spring Core on JDK9+ is vulnerable to remote code execution
Overview Spring Core on JDK9+ is vulnerable to remote code execution due to a bypass for CVE-2010-1622. At the time of writing, this vulnerability is unpatched in Spring Framework and there is ...
PDF File Format: Basic Structure [updated 2020]
Introduction We all know that there are a number of attacks where an attacker includes some shellcode in a PDF document. This shellcode uses some kind of vulnerability in how the PDF ...

