Custody You Didn't Ask For: The White-Hat Rescue Fund Problem

Sweeping weak-entropy wallets "for safekeeping" is a one-way door. This is an operational risk assessment of a thing that looks, from the outside, like a weekend project.

Read More
Full Disclosure: Coldcard v5.6.0 Post-Hotfix Analysis and 39 Unpatched Findings

On July 31, 2026, Coinkite released Coldcard firmware v5.6.0 as an urgent hotfix for a "limited entropy bug" that produced roughly $90M in user losses. This post presents a technical analysis of what that hotfix actually addresses, what it does not, and additional security findings that users need to know about when deciding how to proceed.

Read More
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools

Unit 42 reveals how AD CS template misconfigs and shadow credentials are driving privilege escalation in modern enterprises.

Read More
Disrupting Hell's Gate, Caro Kann, and GuLoader with DJB2 Hash Collisions

Shellcode Disruption Revisited with DJB2 Hash Collisions

Read More
Nuking Weak Shellcode Hacker Hashes For Fun And Profit

Shellcode disruption is just ONE thing Karma-X has scaled to protect it's customers.

Read More
HappyCamper: Doubling Down On Naming Space Location Randomization (NSLR)

Enter HappyCamper, a formal demonstration of the concept of "Naming Space Location Randomization - NSLR" for cyber defense.

Read More
💬 Ask our AI Assistant Kali