KERNEL: LZ-SYS v2.6.4 SYS_ARCH: X86_64 // NEURAL_INTERP
LATENCY: 0.8ms KEYS: [T] THEME / [/] SEARCH
CMS EXPLOIT RESEARCH // RED TEAM // CVE HUNTING

DISPATCHES FROM THE RESEARCH KERNEL.

Source-driven exploit research, CVE variant analysis, and red team tradecraft. Diffed patches, chained primitives, and the disclosure trail behind each one.

CATEGORY:
/

RESEARCH LOG & PREPRINTS

[5 RECORDS FOUND]
MEMO #008 DATE: 2026-08-30
EST. TIME: ~12 MIN

Pay a Penny, Run Code: CVE-2026-67363 and CVE-2026-67364 in Balbooa Forms

While variant-hunting the pre-auth upload RCEs in Balbooa Forms, a line-by-line read of the shortcode engine and the payment tasks surfaced two separate flaws. The custom-PHP handler eval()s an unescaped query parameter behind a CSRF token that anyone can mint, and both payment endpoints charge the attacker-supplied total straight to Stripe and Authorize.net. This memo walks both code paths line by line, the MITM wire capture, and the disclosure to JSST.

READ DISPATCH →
MEMO #007 DATE: 2026-08-17
EST. TIME: ~10 MIN

The Test Connection That Executes Code: CVE-2026-41042 in Apache Gravitino

While hunting an incomplete-fix pattern across Apache Gravitino's catalog REST surface, an unauthenticated testConnection endpoint surfaced that hands attacker-controlled jdbc-url strings to the connection factory with zero validation. This memo walks the patch diff, the variant sweep, and the first working PoC for CVE-2026-41042.

READ DISPATCH →
MEMO #006 DATE: 2026-08-15
EST. TIME: ~12 MIN

DropoutJeep: The Phishing Simulator That Refuses to Drop Out

DropoutJeep is a phishing-simulation and red-team platform with 80-plus utility modules spanning OSINT, pretext generation, payload crafting, C2, exfiltration, evasion, persistence, and deliverability. This memo covers why it exists, why it keeps growing, and why its authors now read Gmail spam-filter documentation for fun.

READ DISPATCH →
MEMO #005 DATE: TBD
EST. TIME: ~8 MIN

Stored XSS in a Widely Deployed CMS Plugin

An unauthenticated stored XSS in a popular CMS extension, found while diffing an unrelated patch. Vendor and plugin name withheld pending coordinated disclosure. Full writeup, PoC, and CVE reference land here the day the fix ships.

READ DISPATCH →
MEMO #004 DATE: 2026-08-15
EST. TIME: ~15 MIN

GrandScream: From One Desk Phone to a Root PBX

One unauthenticated request against a Grandstream desk phone is enough to locate the PBX, fingerprint its firmware, and eventually own it, root shell included. This memo is the narrative of that chain: the leaks that pointed the way, the blind SQLi that gave up the password, and the credential reuse that collapsed three devices into one.

READ DISPATCH →

[NO MATCHING RESEARCH DISPATCHES FOUND]

Try clearing your search query or switching the category filter.