P
Proxy Bar
21.07.2026 15:11 · 👁 889
[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India)
Original text: “[QuickNote] SolidPDFCreator – Mustang Panda Stage-1 Backdoor (Target India)” — AI, 0day in {REA_TEAM} (July 13, 2026). Code blocks, tables, diagrams, and technical artefacts are reproduced verbatim with attribution captions.
Executive Summary
SolidPDFCreator.dll is a sophisticated stage-1 backdoor loader disguised as a legitimate SolidPDF product, attributed to Mustang Panda and targeting India. The…
https://core-jmp.org/2026/07/solidpdfcreator-mustang-panda-stage-1-backdoor-india/
P
Proxy Bar
21.07.2026 14:35 · 👁 1.3K
CVE-2026-58629: A Double-Free in dxgkrnl’s CreateAllocation Rollback
Original text: “July 2026 Patch Tuesday [CVE-2026-58629] Freeing the Wrong Allocation: a double-free in dxgkrnl’s CreateAllocation rollback” — gengstah, gengstah (personal blog), July 14, 2026. Disassembly, crash dumps and code below are reproduced verbatim with attribution captions.
Executive Summary
CVE-2026-58629 is a local elevation-of-privilege bug in dxgkrnl, the Windows Display Driver Model (WDDM) kernel component…
https://core-jmp.org/2026/07/cve-2026-58629-dxgkrnl-createallocation-double-free/
P
Proxy Bar
18.07.2026 01:12 · 👁 4.5K
CVE-2026-63030 WordPress
*
wp2shell
P
Proxy Bar
17.07.2026 21:08 · 👁 4.1K
CVE-2026-58532: An Integer Overflow in Windows tcpip.sys
Original text: “How I found an integer overflow in tcpip.sys (CVE-2026-58532)” — April Ivy (aprilpet), April Ivy’s Writing (aprl.pet), 17 July 2026. The prose below is a paraphrase; the call stack, code snippets and proof-of-concept are reproduced verbatim with attribution.
Executive Summary
Security researcher April Ivy discovered an unsigned 64-bit integer overflow in tcpip.sys, the…
https://core-jmp.org/2026/07/cve-2026-58532-tcpip-sys-integer-overflow/
P
Proxy Bar
17.07.2026 18:26 · 👁 3.7K
Верное мнение из СССР
#onlyGNU
P
Proxy Bar
17.07.2026 13:43 · 👁 3.4K
CVE-2026-58613: Use-After-Free in the Windows Cloud Files Mini Filter Driver (cldflt.sys)
Original text: “Microsoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteRequest use-after-free vulnerability” — Marcin ‘Icewall’ Noga, Cisco Talos (July 17, 2026). Register dumps, decompiled listings and crash logs below are reproduced verbatim with attribution.
Executive Summary
Cisco Talos researcher Marcin ‘Icewall’ Noga disclosed CVE-2026-58613, a kernel-mode use-after-free in cldflt.sys — the Windows Cloud Files Mini…
https://core-jmp.org/2026/07/cve-2026-58613-cldflt-cloud-files-use-after-free/
P
Proxy Bar
17.07.2026 10:04 · 👁 3.2K
Direct $MFT Parsing: Reading NTFS Below the Monitored API Layer
Original text: “Direct $MFT Parsing” — S12 — 0x12Dark Development, on Medium. This article summarises the technique in our own words for readers of core-jmp.org; the ASCII pipeline diagram and the short C++ excerpts below are reproduced with attribution to illustrate the discussion. For the complete C++17 header, main runner, and YARA rule, follow the…
https://core-jmp.org/2026/07/direct-mft-parsing-ntfs-raw-enumeration/
P
Proxy Bar
17.07.2026 08:43 · 👁 3.4K
CVE-2026-58635: How the Windows Narrator Braille Bug Escalates a Standard User to SYSTEM
Original text: "CVE-2026-58635: Windows Narrator Braille Local Privilege Escalation" (proof-of-concept) — DavidCarliez, GitHub (July 2026), released under the MIT License. Source code, scripts, tables and terminal output below are reproduced verbatim with attribution.
Executive Summary
CVE-2026-58635 is a local privilege-escalation vulnerability in an unlikely place: the Braille accessibility component that ships with Windows Narrator. Microsoft…
https://core-jmp.org/2026/07/cve-2026-58635-windows-narrator-braille-privilege-escalation/
P
Proxy Bar
17.07.2026 08:26 · 👁 3.2K
Reverse Engineering CVE-2026-2796: How Claude Built a Firefox WebAssembly Exploit
Original text: "Reverse engineering Claude’s CVE-2026-2796 exploit" — Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, and Daniel Freeman, Anthropic Frontier Red Team (6 March 2026). The prose below is an independent technical summary; the code listings are reproduced verbatim from the source with attribution.
Executive Summary
In March 2026 Anthropic’s Frontier Red Team…
https://core-jmp.org/2026/07/cve-2026-2796-claude-firefox-webassembly-exploit/
P
Proxy Bar
16.07.2026 19:26 · 👁 3.4K
CVE-2026-50343
InstallService StaticPluginMap EoP (Standard User to SYSTEM)
*
Exploit + WriteUP