Technical
A privilege escalation vulnerability hid behind a broken endpoint and a misleading error message. Here's how RAID's agentic system decompiled the frontend JavaScript to find the real API path, the real field name, and a critical access control flaw that let a standard user grant themselves admin rights.
When the API Lies – How RAID Discovered a Critical Privilege Escalation by Reading JavaScript
A privilege escalation vulnerability hid behind a broken endpoint and a misleading error message. Here's how RAID's agentic system decompiled…
How RAID found unauthenticated customer data in a retail GraphQL API
CovertSwarm's web testing agent identified a critical broken access control vulnerability in a retail subscription platform's GraphQL middleware. The platform…
When “Just Logging In” Isn’t Just Logging In: A Lookat xrdp and CVE-2026-33145
A quiet finding with real-world impact. CVE-2026-33145 shows how xrdp's AlternateShell feature, enabled by default, passes client-supplied input directly into…
CVE-2026-33727 – When “Low Privilege” Isn’t Low Enough: A Pi-hole LPE Story
Pi-hole's pihole user is low-privileged. It's configured with nologin. It looks contained. It isn't. Here's how a writable file and…
Why So Syscalls? BOF Edition
Ibai Castells explains how moving from high level Windows APIs to lower level syscall usage alters what EDRs observe. It…
Cobalt Strike External C2 Passthrough Guide
Cobalt Strike’s passthrough mode reshapes how red teams use External C2. By taking control of shellcode staging and custom channels,…