Blog Posts
Coruna: Analysis of a Chained iOS/macOS Exploit Kit
- Exploit Reversing
- March 11, 2026
- 5 mins
A concise technical review of recovered Coruna artifacts, exploit-chain composition, and the tactics that made old tradecraft effective again.
AirSnitch: Lateral Movement from Guest Wi-Fi to Internal Network
- Research
- February 28, 2026
- 8 mins
How old Wi-Fi attack primitives are being recombined into practical, modern machine-in-the-middle paths.
ClearFake and the Evolution of Browser-Native C2
- Analysis
- January 24, 2026
- 6 mins
How ClearFake turns JavaScript into a browser-resident implant with blockchain-backed indirection.
Abusing Microsoft ClickOnce as an Initial Access Primitive
- Red Team Tactics
- January 15, 2026
- 7 mins
How ClickOnce deployment flows become a low-noise payload delivery channel inside trusted Windows execution paths.