Note: at the time of publishing this article (2026-06-03), the vulnerability is still a zero-day. On 2026-06-07, it was assigned as CVE-2026-49494 but is still yet to be patched. I’ve submitted a full ...
Recently, as part of my day job doing CTI at Expel Security, I came across this unique ClickFix / FileFix style phishing page. It merges FileFix and Cache Smuggling to avoid having its first stage ...
Since the latest Windows patch dropped on the 13th of August I’ve been deep in the weeds of tcpip.sys (the kernel driver responsible for handling TCP/IP packets). A vulnerability with a 9.8 CVSS score ...
Previously, I wrote an article detailing how system calls can be utilized to bypass user mode EDR hooks. Now, I want to introduce an alternative technique, “EDR-Preloading”, which involves running ...
Recently I was testing some EDR’s abilities to detect indirect syscalls, and I had an idea for a quirky bypass. If you’re not already familiar with direct and indirect syscalls, I recommend reading ...
Recently I got back into malware research and was going through some of my old notes for an article I’m writing. While cross-referencing notes against old blog posts, I realized that I never actually ...
In the wake of the MGM news, I thought it a good time to discuss phishing awareness. It’s rumored that the attacker(s) were able to impersonate an internal MGM employee and social engineer the help ...
This is one of the claims that seems to be everywhere. I can’t even scroll down three posts on LinkedIn without someone talking about AI malware. The first problem with this claim is that ChatGPT is ...
An introduction to Use-After-Free exploitation and walking through one of my old challenges. Challenge Info: https://www.malwaretech.com/challenges/windows ...
Up until recently, I’d never tried the bug hunting part of vulnerability research. I’ve been reverse engineering Windows malware for over a decade, and I’d done the occasional patch analysis, but I ...