All Posts

CVE-2026-65400: macOS Screen Sharing Authentication Bypass Can Lead to Root-Level Remote Access
CVE-2026-65400 affects macOS Screen Sharing. Learn how the authentication flaw works, affected versions, exploitation research, detection etc.

Proton VPN Pricing A/B Test: How One HTML Tag Correlates With a €12 Difference in What Customers Pay
An investigation into Proton VPN's pricing page found an A/B-test tag linked to two VPN Plus prices: €2.99 and €3.49 per month

Why IRCTC Keeps Crashing During Tatkal Booking: A Technical Deep Dive into India’s Biggest Ticketing Bottleneck
Why does IRCTC crash during Tatkal? An in-depth technical analysis of traffic spikes, database contention, retries, CAPTCHA, payments and more

Beginner’s Guide to Conquering DanglingTree on Hack the Box
Conquer DanglingTree on Hack The Box like a pro with the beginner's HTB writeup. Dominate this challenge and level up your cybersecurity skills

New WordPress Pre-Authentication XSS Could Lead to PHP Code Execution, Patch Immediately
Learn how CVE-2026-64638 affects WordPress, why the pre-authentication XSS is dangerous, how researchers chained it to PHP code execution using XSS2Shell

Metabase Confirms Active Exploitation of Critical SQL Injection Flaw, Urges Immediate Upgrades for Self-Hosted Deployments
Metabase has disclosed a critical SQL injection vulnerability that is actively exploited in the wild. Learn how the attack works, affected versions, IoCs and more

Zapscape: A Technical Deep-dive of the CVE-2026-64561 KVM Guest-to-Host Escape
Discover how Zapscape (CVE-2026-64561) exploits Linux KVM's Shadow MMU to achieve guest-to-host escape, including root cause, exploitation and more

New Interrupt Injection Attack Bypasses Spectre v2 Defenses on Intel and AMD CPUs
MIT CSAIL researchers discovered Interrupt Injection, a new speculative execution attack that bypasses Spectre v2 mitigations on Intel and AMD CPUs

Apple WebKit Flaws Can Leak Real IP Addresses Despite iCloud Private Relay and Proxy Browsers
Researchers discovered three WebKit behaviors that bypass Apple Private Relay and proxy browsers, exposing users' real IP addresses and DNS requests on iOS and macOS

OVSwrap (CVE-2026-64531): How a 13-Year-Old Open vSwitch Bug Became a Reliable Linux Root Exploit
OVSwrap (CVE-2026-64531) is a Linux kernel privilege escalation flaw affecting Open vSwitch. Explore the vulnerability, exploit chain and more





