Latest posts

PT SWARM
15 Sept, 08:23
🍏 Fresh LPE in macOS: Repair Permissions - Get Root!CVE-2026-43783 found by our researcher Ilya Andr has been recently fixed by Apple. A single XPC request to DesktopServicesHelper lets you chown any path on disk - straight to root.https://ptswarm.com/blog/cve-2026-43783-repair-permissions-get-root-lpe-via-desktopserviceshelper-in-macos-26-5/


PT SWARM
24 Aug, 13:45
⚡️ IPAHound has received an important update!Now we support BloodHound CE. You can use the -O collector flag to output in OpenGraph format.We have prepared neo4j queries directly in the object descriptions for easy analysis of the FreeIPA graph.https://github.com/IPAHound/IPAHound


PT SWARM
6 Jul, 11:49
🐘 PHP PDO layer exposed! Aleksey Solovev & Nikita Sveshnikov uncovered 2 flaws: SQL Injection in pdo_firebird (CVE-2025-14179) and DoS in PDO via pdo_pgsql (CVE-2025-14180).https://swarm.ptsecurity.com/hack-the-elephant-one-bite-at-a-time-nul-byte-sql-injection-in-pdo_firebird-and-null-pointer-dereference-in-pdo-pgsql/


PT SWARM
5 Jun, 11:23
👨🏻💻 Did you know that it’s possible to perform RCE in Internet Explorer via clickjacking? Igor Sak-Sakovsky's new article will explain how!https://swarm.ptsecurity.com/the-click-that-shouldnt-have-worked-rce-via-clickjacking-in-internet-explorer/


PT SWARM
15 May, 09:13
🐘 PHP JPEG bugs: how image parsing leads to memory corruption.Our researcher Nikita Sveshnikov discovered two JPEG-related memory-safety bugs in PHP’s ext/standard: CVE-2025-14177 in getimagesize and a heap buffer overflow in iptcembed.https://swarm.ptsecurity.com/hack-the-elephant-one-bite-at-a-time-jpeg-related-memory-safety-bugs-in-php/


PT SWARM
30 Apr, 09:05
🧑🚒 Our researcher Mikhail Sukhov shares his knowledge and experience in analyzing FreeIPA environments.He also introduces his new tool, IPAHound 💪Go ’n see the details ➡️ https://swarm.ptsecurity.com/thinking-in-graphs-with-ipahound/


PT SWARM
15 Apr, 14:35
🔥 Read the new article by our researcher Timofey Duditsky.The write-up dives into the AMD Platform Configuration Blobs mechanism, shows how it works, and reveals the vulnerability CVE-2025-54502.https://swarm.ptsecurity.com/slowburn-looking-through-amd-platform-configuration-blobs-infrastructure/


PT SWARM
23 Mar, 13:46
Two bugs. One chain. Full RCE.New research by Aleksandr Zhurnakov on Dell Wyse Management Suite shows how business logic flaws can be chained into complete system compromise.Read the full writeup!https://swarm.ptsecurity.com/business-logic-and-chains-unauthenticated-rce-in-dell-wyse-management-suite/
PT SWARM
10 Mar, 14:03
🐘 Attack arithmetic: how an integer overflow in PostgreSQL libpq leads to denial of service.Our researcher Aleksey Solovev discovered the vulnerability CVE-2025-12818, which may cause a product using the libpq PostgreSQL library to crash.https://swarm.ptsecurity.com/attack-arithmetic-how-an-integer-overflow-in-postgresql-libpq-leads-to-denial-of-service/
PT SWARM
2 Mar, 13:45
🚨 Our researcher Alexander Zhurnakov identified two vulnerabilities in Dell Wyse Management Suite prior to version 5.5.In certain configurations, they can be chained to achieve unauthenticated remote code execution.Upgrade now → https://www.dell.com/support/kbdoc/en-us/000429141/dsa-2026-103
PT SWARM
21 Jan, 11:39
🏆 Two of our research articles are nominated for PortSwigger's Top 10 Web Hacking Techniques of 2025!1️⃣ Impossible XXE in PHP 2️⃣ Blind trust: what is hidden behind the process of creating your PDF file?Last day to vote if you found them useful!https://portswigger.net/polls/top-10-web-hacking-techniques-2025portswigger.netTop 10 web hacking techniques of 2025Welcome to the community vote for the Top 10 Web Hacking Techniques of 2025.
PT SWARM
19 Jan, 13:04
📞 Microsoft fixed an authenticated RCE in Windows Telephony Service (CVE-2026-20931), discovered by our researcher Sergey Bliznyuk.Read the write-up: https://swarm.ptsecurity.com/whos-on-the-line-exploiting-rce-in-windows-telephony-service/
PT SWARM
29 Dec 2025, 12:17
📑 A new article from our researchers Aleksey Solovev, Nikita Sveshnikov and Vladimir Razov — "Blind trust: what is hidden behind the process of creating your PDF file?".https://swarm.ptsecurity.com/blind-trust-what-is-hidden-behind-the-process-of-creating-your-pdf-file/
PT SWARM
14 Nov 2025, 14:15
📱 New article by our researcher Artem Kulakov: Injection for an athlete.Read about a vulnerability discovered in the Garmin Connect mobile application:https://swarm.ptsecurity.com/injection-for-an-athlete/
PT SWARM
24 Jul 2025, 16:31
🚨 We've launched dbugs.ptsecurity.com, a new home for vulnerabilities. More than CVEs. More than MITRE.✅ Trends & Insights ✅ AI-generated, multi-source vulnerability descriptions ✅ Researcher creditsExplore now: https://dbugs.ptsecurity.com


PT SWARM
22 Jul 2025, 13:39
👑 Our researcher has discovered LPE in VMWare Tools (CVE-2025-22230 & CVE-2025-22247) via VGAuth!Write-up by the one who broke it: Sergey Bliznyukhttps://swarm.ptsecurity.com/the-guest-who-could-exploiting-lpe-in-vmware-tools/


PT SWARM
17 Jul 2025, 15:15
😈 Read the new article "Daemon Ex Plist: LPE via MacOS Daemons" by our researcher Egor Filatov.This research reveals a vulnerability affecting popular apps like Mozilla VPN, Tunnelblick & more.https://swarm.ptsecurity.com/daemon-ex-plist-lpe-via-macos-daemons/
PT SWARM
9 Jul 2025, 14:08
🧠 Our researcher Sergey Tarasov discovered a vulnerability (CVE-2025-49689) in NTFS on MS Windows.The article dives into the exploitation path, file system internals, VHD format, and more.🔗 Read the article: https://swarm.ptsecurity.com/buried-in-the-log-exploiting-a-20-years-old-ntfs-vulnerability/


PT SWARM
27 Jun 2025, 13:40
🦊 Mozilla Foundation fixed CVE-2025-6430, discovered by our researcher Daniil Satyaev!This vulnerability allows the Content-Disposition: attachment header to be ignored if the page is opened using <embed> or <object>, resulting in files being displayed instead of downloaded.


PT SWARM
3 Jun 2025, 16:46
⚠️ We've reproduced CVE-2025-49113 in Roundcube.This vulnerability allows authenticated users to execute arbitrary commands via PHP object deserialization.If you're running Roundcube — update immediately!
Related Channels
Other channels in the same section of the catalogue.
