Blog posts
Deep dives into vulnerabilities we discover, offensive security techniques we develop, and insights from the front lines of enterprise security research.

Case Study: Analyzing macOS IONVMeFamily Driver Denial of Service Issue
Explore a detailed case study on detecting vulnerabilities in macOS drivers. Learn how to analyze IOKit, reverse engineer kernel extensions, and debug system crashes using real-world techniques. This guide walks through the discovery of a Denial of Service (DoS) condition in the NS_01 driver within Apple’s IONVMeFamily, offering insights into fuzzing, integer overflow detection, and crash analysis.
Apple
Karol Mazurek
February 12, 2026
10
min read
•
Feb 12, 2025

JTAG & Flipper Zero: To repair the Proxmark3
Bricked your Proxmark3? No problem! This guide shows you how to revive it using Flipper Zero as a JTAG adapter, from setup to flashing recovery firmware. Plus, we’ll explore how JTAG can be used in hardware security and penetration testing.
Internet of things
Hardware
Marcin Węgłowski
February 12, 2026
12
min read
•
Feb 19, 2025

Microsoft 365 Phishing: Bypassing Outlook Spam Filters
Discover how attackers bypass Microsoft 365 spam filters using URL obfuscation to distribute malicious files. This vulnerability, reported to Microsoft but left unpatched, demonstrates why email security requires multiple layers of defense beyond built-in filters.
Red teaming
Social engineering
Web
Karol Mazurek
February 12, 2026
3
min read
•
Feb 24, 2025

TOCTOU Vulnerabilities in C# Applications: Mitigation
In this article, we explore TOCTOU vulnerabilities, subtle yet dangerous race conditions that occur when security checks and resource usage are not tightly coupled. In C# development on Windows, where file operations and dynamic code loading are common, understanding and mitigating these risks is essential for building secure and resilient applications.
Secure coding
Windows
Sławomir Zakrzewski
February 12, 2026
13
min read
•
Mar 5, 2025

Prompt Injection Mitigation: 7 Defense Strategies for LLMs
A practical guide to prompt injection mitigation strategies for LLM applications. Explores 7 defense methods including guardrails, design patterns, and input preprocessing - plus why no solution offers 100% protection.
AI
LLM
Mateusz Wojciechowski
February 12, 2026
6
min read
•
Mar 7, 2025

NULL Pointer Dereference on macOS: Exploitation History
Technical analysis of NULL Pointer Dereference bugs, mitigations, and exploit development challenges on Apple Silicon macOS.
MacOS
Vulnerability research
Apple
Karol Mazurek
February 12, 2026
15
min read
•
Mar 10, 2025

PostgreSQL Injection in NetIQ: CVE-2024-10864 & CVE-2024-10865
NetIQ Advanced Authentication reflected XSS vulnerability (CVE-2024-10865) discovered during PostgreSQL injection testing
Web
Maksymilian Kubiak
April 3, 2026
5
min read
•
Jul 15, 2025

Credential Harvesting via Check Point SmartConsole CVE-2024-24915
CVE-2024-24915 is an insecure credential storage flaw in Check Point SmartConsole (R81.20) that leaves user credentials in plaintext memory.
Red teaming
Vulnerability research
Windows
Karol Mazurek
February 12, 2026
3
min read
•
Aug 4, 2025

Java RMI for pentesters: structure, recon and communication (non-JMX Registries).
Welcome to the comprehensive guide on Java Remote Method Invocation (RMI) tailored for penetration testers. This article aims to demystify RMI interfaces encountered during infrastructure penetration testing. Due to the depth of this topic, we’ve divided it into two parts. In this initial section, we’ll provide a concise overview of RMI interfaces, demonstrate how to create one for testing purposes, and guide you through the manual construction of an RMI Client to invoke remote methods.
Web
Infrastructure
AFINE
February 12, 2026
13
min read
•
Sep 27, 2020
.webp)
SQL Injection in the Age of ORM: Risks, Mitigations, and Best Practices
This article explains how SQL injection vulnerabilities can still occur in applications using modern ORM frameworks. It describes how to identify insecure patterns and write safer code, providing practical examples to illustrate common pitfalls and secure practices.
Secure coding
Web
Sławomir Zakrzewski
April 7, 2026
10
min read
•
Apr 28, 2025
Sort by Categories
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Monthly Security Report
Subscribe to our Enterprise Security Report. Every month, we share what we're discovering in enterprise software, what vulnerabilities you should watch for, and the security trends we're seeing from our offensive security work.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Cookie Settings
We use cookies to provide you with the best possible experience. They also allow us to analyze user behavior in order to constantly improve the website for you.
See our Privacy PolicyThank you! Your submission has been received!
Oops! Something went wrong while submitting the form.