New Windows privilege-escalation primitive just dropped.
GreenPlasma is a minimal PoC that forces creation of an arbitrary section object inside any directory writable by SYSTEM via CTFMON’s named-object cache.
Let me break it down for you:
The second vulnerability (CVE-2026-21510) bypasses security features such as the Microsoft Defender SmartScreen and executes attacker-controlled code, which is stored on the attacker's remote server.
An incomplete patch for CVE-2026-21510 (an #APT28 exploit) created a new zero-click vulnerability: CVE-2026-32202.
https://t.co/zkA6AXs2Uo
Kaspersky uncovers PhantomRPC, a Windows architectural flaw allowing unauthenticated SYSTEM-level access via RPC spoofing. Microsoft has no plans to patch.
https://t.co/9guIibT4sE
Theori leads #kernelCTF again! 🏆
✅ LTS 6.6.69/COS 109 0-day
✅ LTS 6.6.75/COS 105 1-day
✅ LTS 6.6.77/COS 109/Mitigation 0-day
Theori locked in the first valid flag for LTS 6.6.77 at @Google's CTF. Also, last year our researchers @v4bel & @_qwerty_po made history as the first to exploit VSock, pushing kernelCTF’s attack surface even further! 🥳
#Theori #LinuxKernel #VulnerabilityResearch #zeroday
🎩 Theori at Black Hat Europe 2024
Our researchers @bbbig12 and Gwangun Jung will be presenting their VMware full chain exploit at @BlackHatEvents Europe 2024 this December! They’ll cover key vulnerabilities like information leakage, arbitrary code execution, and a Windows Kernel Elevation of Privilege exploit, originally showcased at Pwn2Own 2024. Catch their session in the Exploit Development & Vulnerability Discovery track!
Will we see you there? Comment below or retweet to let us know!
Utilizing Cross-CPU Allocation to Exploit Preempt-Disabled Linux Kernel (Hexagon 2024 slides)
https://t.co/xUyE50y20r
Credits Mingi Cho and Wongi Lee
#Linux#infosec
Administrator Protection, introduced in the latest Windows Insider Canary build, is a solid security enhancement... uhh.. really?? can be bypassed with @splinter_code's clever SspiUacBypass tool. Check it out here: https://t.co/e1WWHi2Rnk
The kernel bug, CVE-2024-30088 was reported through the ZDI program. Our colleagues at @TrendMicroRSRCH have details on how APT34 is using the bug in the wild. Read all about it at https://t.co/QS0LYhCmBD
Following up on my earlier tweet (https://t.co/hTBzbcXcxD) regarding Kerberos relay with SMB server, I've uploaded my quick & dirty version. It's far from perfect, so feel free to improve it! https://t.co/Pi0sfpTbc7
I always wanted to have IDA's graph-overview for source-code.
So I created a small VS-Code extension to do that for me.
https://t.co/zTgooSrUtq
It currently supports only Go code, but adding more languages should be relatively straightforward.
We've updated our blog on abusing file deletes to escalate privileges. We've also released PoC to demonstrate this. The exploit offers a high degree of reliability and eliminates all race conditions. It has been tested on the latest Windows 11 Enterprise. https://t.co/9D5Npp20rf