Research
- Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours
MikroTrick, an unauthenticated MikroTik RouterOS takeover chain, was exploited in the wild before the advisory shipped. We rebuilt the full exploit from the public advisory and patch diff in approximately three hours.
- Anatomy of a Malicious Package: The Install-Time Playbook
A field guide to the techniques attackers hide inside npm, PyPI, and Crates packages, and the benign look-alikes that make them hard to catch.