DOSSIER: LZ-994 CLEARANCE: LEVEL-4 // TOP SECRET UTC: --:--:--
SHORTCUT: [T] THEME / [/] SEARCH
COMMAND // OFFENSIVE SECURITY RESEARCH KERNEL DISPATCH NODE LZ-994

DISPATCHES FROM THE RESEARCH KERNEL.

⚡ SUBSYSTEM: CMS ZERO-DAYS // VARIANT HUNTING // RED TEAM // LZ-994 CLASSIFIED REPO

"Source-driven exploit research, CVE variant analysis, and red team tradecraft. Diffed vendor patches, chained primitives, and the coordinated disclosure trail behind each one. Pull the source apart. Diff the patch. Chain the primitive. Ship the PoC."

15+ CVE DISCLOSURES
10.0 MAX CVSS CRITICAL
100% CLEANROOM REPRO
5x ACTIVE DISPATCHES
CATEGORY:
/

▶ RESEARCH LOG & PREPRINTS

[5 RECORDS FOUND]
MEMO #008 DATE: 2026-01-01
EST. TIME: ~10 MIN

Pay a Penny, Run Code: CVE-2026-67363 and CVE-2026-67364 in Balbooa Forms

While variant-hunting the pre-auth upload RCEs in Balbooa Forms, a line-by-line read of the shortcode engine and the payment tasks surfaced two separate flaws. The custom-PHP handler eval()s an unescaped query parameter behind a CSRF token that anyone can mint, and both payment endpoints charge the attacker-supplied total straight to Stripe and Authorize.net. This memo walks both code paths line by line, the MITM wire capture, and the disclosure to JSST.

READ DISPATCH →
MEMO #007 DATE: 2026-01-01
EST. TIME: ~10 MIN

The Test Connection That Executes Code: CVE-2026-41042 in Apache Gravitino

While hunting an incomplete-fix pattern across Apache Gravitino's catalog REST surface, an unauthenticated testConnection endpoint surfaced that hands attacker-controlled jdbc-url strings to the connection factory with zero validation. This memo walks the patch diff, the variant sweep, and the first working PoC for CVE-2026-41042.

READ DISPATCH →
MEMO #006 DATE: 2026-01-01
EST. TIME: ~10 MIN

DropoutJeep: The Phishing Simulator That Refuses to Drop Out

DropoutJeep is a phishing-simulation and red-team platform with 80-plus utility modules spanning OSINT, pretext generation, payload crafting, C2, exfiltration, evasion, persistence, and deliverability. This memo covers why it exists, why it keeps growing, and why its authors now read Gmail spam-filter documentation for fun.

READ DISPATCH →
MEMO #005 DATE: 2026-01-01
EST. TIME: ~10 MIN

The String the Fix Stopped Watching: CVE-2026-75948 in iCagenda

A stored XSS in iCagenda 4.0.8 through 4.0.12, found while I was rebuilding the extension's KEV-listed upload bug during an incident response. The event submission form stores the image and file fields as raw strings, and the event page prints them straight into an img src and an a href. This memo walks the code line by line, the lab repro, and the retest of the vendor candidate build.

READ DISPATCH →
MEMO #004 DATE: 2026-01-01
EST. TIME: ~10 MIN

GrandScream: From One Desk Phone to a Root PBX

One unauthenticated request against a Grandstream desk phone is enough to locate the PBX, fingerprint its firmware, and eventually own it, root shell included. This memo is the narrative of that chain: the leaks that pointed the way, the blind SQLi that gave up the password, and the credential reuse that collapsed three devices into one.

READ DISPATCH →

[NO MATCHING RESEARCH DISPATCHES FOUND]

Try clearing your search query or switching the category filter.