logo

SensePost Blog

ID: d18f9307-5e85-50d7-bf63-aaabcef8ebeb

STIX ID: identity--d18f9307-5e85-50d7-bf63-aaabcef8ebeb

Feed Type: rss

Earliest post: 2007-05-30

Latest post: 2026-04-01

Technical security research, penetration-testing insights, and offensive/defensive analysis from the Orange Cyberdefense team — covering exploit techniques, threat research, tooling, and real-world security lessons.

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
Noooooooooo Touch!2025-11-19TrueTrue
pwning asus driverhub, msi center, acer control centre and razer synapse 42025-07-24TrueTrue
Depscanner: Find orphaned packages before the bad guys do2025-06-03TrueTrue
Investigating an in-the-wild campaign using RCE in CraftCMS2025-04-18TrueTrue
Is TLS more secure? The WinRMS case.2025-04-14TrueTrue
Browser Cache Smuggling: the return of the dropper2025-03-24TrueTrue
Leakymetry: Circumventing GLPI Authentication2025-03-21TrueTrue
Getting rid of pre- and post-conditions in NoSQL injections2025-03-11TrueTrue
From a GLPI patch bypass to RCE2024-06-20TrueTrue
Targeting an industrial protocol gateway2024-05-30TrueTrue
From Discovery to Disclosure: ReCrystallize Server Vulnerabilities2024-03-22TrueTrue
Dress Code – The Talk2023-08-23TrueTrue
Filter-Mute Operation: Investigating EDR Internal Communication2023-07-28TrueTrue
Browsers’ cache smuggling2023-07-10TrueTrue
an offensive look at docker desktop extensions2023-05-30TrueTrue
Investigating the Wink Hub 22023-05-26TrueTrue
Protected Users: you thought you were safe uh?2023-03-31TrueTrue
me vs request smugglingPOST2022-07-19TrueTrue
Sail away, sail away, sail away2022-05-31TrueTrue
SIM Hijacking2022-02-07TrueTrue
From 500 to Account Takeover2021-03-02TrueTrue
Duo Two-factor Authentication Bypass2021-01-28TrueTrue
Pass-the-hash WiFi2020-10-02TrueTrue
Let me store that for you2020-09-11TrueTrue
DirectAccess and Kerberos Resource-based Constrained Delegation2020-08-19TrueTrue
Routopsy – Hacking Routing with Routers2020-08-03TrueTrue
Seeing (Sig)Red2020-07-20TrueTrue
Clash of the (Spam)Titan2020-07-14TrueTrue
Resurrecting an old AMSI Bypass2020-06-24TrueTrue
The hunt for Chromium issue 10721712020-05-29TrueTrue
Being Stubborn Pays Off pt. 2 – Tale of two 0days on PRTG Network Monitor2020-05-22TrueTrue
Hack-From-Home Challenge Walk Through2020-04-24TrueTrue
Masquerading Windows processes like a DoubleAgent.2020-04-23TrueTrue

1–33 of 33