<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Red plus Blue makes Purple! on Purpleshift</title><link>https://purpleshift.io/</link><description>Recent content in Red plus Blue makes Purple! on Purpleshift</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026</copyright><lastBuildDate>Wed, 12 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://purpleshift.io/index.xml" rel="self" type="application/rss+xml"/><item><title>A key element of protection: how to effectively manage cybersecurity incidents?</title><link>https://purpleshift.io/conf/2025/2025-11-14-vadim-nersesov/</link><pubDate>Fri, 14 Nov 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-11-14-vadim-nersesov/</guid><description/></item><item><title>Inside BlackNevas: gaps, grief, and lessons learned</title><link>https://purpleshift.io/conf/2026/2026-03-14-eduardo-ovalle/</link><pubDate>Sat, 14 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2026/2026-03-14-eduardo-ovalle/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2026/2026-03-14-eduardo-ovalle/featured_HackGDL.jpg"/></item><item><title>C2 by Microsoft: What can go wrong if SCCM ends up in the wrong hands</title><link>https://purpleshift.io/conf/2025/2025-11-14-alexander-rodchenko/</link><pubDate>Fri, 14 Nov 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-11-14-alexander-rodchenko/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2025/2025-11-14-alexander-rodchenko/featured_DefCamp-2025.png"/></item><item><title>Inside the Guts of Ransomware</title><link>https://purpleshift.io/conf/2026/2026-03-14-ashley-munoz/</link><pubDate>Sat, 14 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2026/2026-03-14-ashley-munoz/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2026/2026-03-14-ashley-munoz/featured_HackGDL.jpg"/></item><item><title>How to avoid turning your QA into just a tester</title><link>https://purpleshift.io/conf/2026/2026-03-14-olga-kuznetsova/</link><pubDate>Sat, 14 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2026/2026-03-14-olga-kuznetsova/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2026/2026-03-14-olga-kuznetsova/featured_iSpring.png"/></item><item><title>Cyber Polygon: Career Development</title><link>https://purpleshift.io/conf/2025/2025-09-16-viktor-zvarykin/</link><pubDate>Tue, 16 Sep 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-09-16-viktor-zvarykin/</guid><description/></item><item><title>Buying protection doesn’t mean being protected</title><link>https://purpleshift.io/conf/2025/2025-09-16-grigory-sablin/</link><pubDate>Tue, 16 Sep 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-09-16-grigory-sablin/</guid><description/></item><item><title>Greybox fuzzing of embedded systems made simple: minimizing preparation with Qiling</title><link>https://purpleshift.io/conf/2025/2025-08-22-nikita-proshin/</link><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-08-22-nikita-proshin/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2025/2025-08-22-nikita-proshin/featured_offzone2.jpeg"/></item><item><title>Hack The Air, or How to talk to the air without attracting the attention of the doctors</title><link>https://purpleshift.io/conf/2025/2025-08-22-sergey-andreev/</link><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-08-22-sergey-andreev/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2025/2025-08-22-sergey-andreev/featured_offzone2.jpeg"/></item><item><title>Yet another way to dump LSASS</title><link>https://purpleshift.io/conf/2025/2025-08-22-georgy-kiguradze/</link><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-08-22-georgy-kiguradze/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2025/2025-08-22-georgy-kiguradze/featured_offzone2.jpeg"/></item><item><title>Silent Harvest: extracting Windows secrets under radar</title><link>https://purpleshift.io/conf/2025/2025-08-22-khaydar-kabibo/</link><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-08-22-khaydar-kabibo/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2025/2025-08-22-khaydar-kabibo/featured_offzone2.jpeg"/></item><item><title>A Thousand and One Nights in Search of Indicators of Compromise</title><link>https://purpleshift.io/conf/2025/2025-08-22-victor-sergeev/</link><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-08-22-victor-sergeev/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2025/2025-08-22-victor-sergeev/featured_offzone2.jpeg"/></item><item><title>Detection of ADCS ESC9-15 attacks</title><link>https://purpleshift.io/conf/2025/2025-08-22-dmitry-shchetinin-andrey-skablonsky/</link><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-08-22-dmitry-shchetinin-andrey-skablonsky/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2025/2025-08-22-dmitry-shchetinin-andrey-skablonsky/featured_offzone2.jpeg"/></item><item><title>When the target is one and the attackers are many: competition for the victim</title><link>https://purpleshift.io/conf/2025/2025-08-22-alina-sukhanova/</link><pubDate>Fri, 22 Aug 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-08-22-alina-sukhanova/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2025/2025-08-22-alina-sukhanova/featured_offzone2.jpeg"/></item><item><title>Abusing SSH for fun and profit: Outlaw analysis</title><link>https://purpleshift.io/conf/2025/2025-06-03-cristian-souza/</link><pubDate>Tue, 03 Jun 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-06-03-cristian-souza/</guid><description/></item><item><title>Foremost-NG: An Open-Source Toolkit for Advanced File Carving and Analysis</title><link>https://purpleshift.io/conf/2025/2025-06-03-cristian-souza-foremost-ng/</link><pubDate>Tue, 03 Jun 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-06-03-cristian-souza-foremost-ng/</guid><description/></item><item><title>From entertainment to manipulation: The Dark Side of deepfakes</title><link>https://purpleshift.io/conf/2025/2025-05-23-maxim-shmelev/</link><pubDate>Fri, 23 May 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-05-23-maxim-shmelev/</guid><description/></item><item><title>Standard rules for non-standard sources</title><link>https://purpleshift.io/conf/2025/2025-05-23-nikolay-sovetkin/</link><pubDate>Fri, 23 May 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-05-23-nikolay-sovetkin/</guid><description/></item><item><title>SOC architecture practices in the digital flood era</title><link>https://purpleshift.io/conf/2025/2025-05-23-alexey-peshik/</link><pubDate>Fri, 23 May 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-05-23-alexey-peshik/</guid><description/></item><item><title>Adventures of Red Team in SBC security</title><link>https://purpleshift.io/conf/2025/2025-05-22-alexander-makovsky/</link><pubDate>Thu, 22 May 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-05-22-alexander-makovsky/</guid><description/></item><item><title>Flashy doesn't mean effective</title><link>https://purpleshift.io/conf/2025/2025-05-22-olga-zinenko/</link><pubDate>Thu, 22 May 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-05-22-olga-zinenko/</guid><description/></item><item><title>bind_tcp_agent: a Mythic P2P bridge for TCP-based C2</title><link>https://purpleshift.io/articles/2026-08-14-bindtcpagent/</link><pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2026-08-14-bindtcpagent/</guid><description>How to bridge Mythic&amp;rsquo;s egress network with TCP-based P2P agents through an outbound connection</description></item><item><title>Certighost: a new vulnerability in Windows Server</title><link>https://purpleshift.io/purple/2026-08-11-mfjy/</link><pubDate>Tue, 11 Aug 2026 06:05:15 +0000</pubDate><guid>https://purpleshift.io/purple/2026-08-11-mfjy/</guid><description>How to find out if your servers have been attacked</description></item><item><title>Hacker group Labooboo developed its own backdoor</title><link>https://purpleshift.io/purple/2026-08-05-fnpg/</link><pubDate>Wed, 05 Aug 2026 09:13:01 +0000</pubDate><guid>https://purpleshift.io/purple/2026-08-05-fnpg/</guid><description>New malware uses MQTT and Matrix protocols to talk to C2</description></item><item><title>Detecting Certighost attack</title><link>https://purpleshift.io/articles/2026-08-07-certighost/</link><pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2026-08-07-certighost/</guid><description>A user with minimal privileges can gain control over the domain</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/articles/2026-08-07-certighost/featured_certighost4.png"/></item><item><title>Attacks on Education</title><link>https://purpleshift.io/purple/2026-08-03-ozxe/</link><pubDate>Mon, 03 Aug 2026 18:00:42 +0000</pubDate><guid>https://purpleshift.io/purple/2026-08-03-ozxe/</guid><description>Schools and universities are hacked through stolen accounts and outdated software</description></item><item><title>Turning a TURN server into an evil proxy</title><link>https://purpleshift.io/purple/2026-07-29-xfzo/</link><pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/purple/2026-07-29-xfzo/</guid><description>A video conferencing relay host can redirect traffic to C2</description></item><item><title>Our Incident Response talks at DEFCON</title><link>https://purpleshift.io/purple/2026-07-30-lexa/</link><pubDate>Thu, 30 Jul 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/purple/2026-07-30-lexa/</guid><description>Guts of ransomware, Bitlocker abuse, and a workshop on investigative skills</description></item><item><title>Privilege escalation through trusts in AD</title><link>https://purpleshift.io/purple/2026-07-10-dqoo/</link><pubDate>Tue, 28 Jul 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/purple/2026-07-10-dqoo/</guid><description>Trust relationships between domains facilitate various attacks</description></item><item><title>Active Directory Trust Relationship Attacks</title><link>https://purpleshift.io/articles/2026-07-09-trusts/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2026-07-09-trusts/</guid><description>Our lab environment examples show how to get info about domains and elevate privileges</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/articles/2026-07-09-trusts/featured_trusts.png"/></item><item><title>HeartlessSoul APT uses blockchain to hide C2</title><link>https://purpleshift.io/purple/2026-07-24-offj/</link><pubDate>Fri, 24 Jul 2026 05:47:11 +0000</pubDate><guid>https://purpleshift.io/purple/2026-07-24-offj/</guid><description>Command &amp;amp; control addresses are transmitted in BNB Smart Chain and Solana transactions</description></item><item><title>How BitLocker becomes ransomware</title><link>https://purpleshift.io/purple/2026-07-21-olgs/</link><pubDate>Tue, 21 Jul 2026 13:23:01 +0000</pubDate><guid>https://purpleshift.io/purple/2026-07-21-olgs/</guid><description>Incidents in Latin America show how secure configuration could prevent encryption</description></item><item><title>Extracting secrets from Octopus Deploy</title><link>https://purpleshift.io/purple/2026-07-16-gelw/</link><pubDate>Thu, 16 Jul 2026 03:51:24 +0000</pubDate><guid>https://purpleshift.io/purple/2026-07-16-gelw/</guid><description>Attackers can get valuable data even if they don&amp;rsquo;t have access to the web version of the tool</description></item><item><title>Leaks through Claude Code and other missed incidents</title><link>https://purpleshift.io/purple/2026-07-02-rbcn/</link><pubDate>Thu, 02 Jul 2026 09:05:02 +0000</pubDate><guid>https://purpleshift.io/purple/2026-07-02-rbcn/</guid><description>Our Compromise Assessment service report features such a hidden threat as generative AI</description></item><item><title>Large-scale attack via stealthy ScreenConnect installation</title><link>https://purpleshift.io/purple/2026-07-01-elbb/</link><pubDate>Wed, 01 Jul 2026 10:03:44 +0000</pubDate><guid>https://purpleshift.io/purple/2026-07-01-elbb/</guid><description>Users receive attackers&amp;rsquo; remote access tool along with popular freeware</description></item><item><title>Ghost in the RAM: weaponizing memfd_create() for fileless attacks</title><link>https://purpleshift.io/purple/2026-06-29-onsd/</link><pubDate>Mon, 29 Jun 2026 04:55:19 +0000</pubDate><guid>https://purpleshift.io/purple/2026-06-29-onsd/</guid><description>How to detect malware that runs on Linux systems without writing on disk</description></item><item><title>Web shells in backups: natural persistence</title><link>https://purpleshift.io/purple/2026-06-25-ppmu/</link><pubDate>Thu, 25 Jun 2026 09:52:43 +0000</pubDate><guid>https://purpleshift.io/purple/2026-06-25-ppmu/</guid><description>Some stats on threats found in backups during compromise assessment</description></item><item><title>NTLM Reflection attack: when it works</title><link>https://purpleshift.io/purple/2026-06-23-qjdo/</link><pubDate>Tue, 23 Jun 2026 05:41:05 +0000</pubDate><guid>https://purpleshift.io/purple/2026-06-23-qjdo/</guid><description>Under what conditions can a non-domain Windows host be compromised</description></item><item><title>Hacker group VasyGrek expands its arsenal</title><link>https://purpleshift.io/purple/2026-06-17-rjjv/</link><pubDate>Wed, 17 Jun 2026 06:19:48 +0000</pubDate><guid>https://purpleshift.io/purple/2026-06-17-rjjv/</guid><description>New attacks use .vbs droppers, .com droppers, and .com stealer written in Rust</description></item><item><title>Malicious Network Provider DLL allows stealing credentials</title><link>https://purpleshift.io/purple/2026-06-15-ckcn/</link><pubDate>Mon, 15 Jun 2026 04:59:33 +0000</pubDate><guid>https://purpleshift.io/purple/2026-06-15-ckcn/</guid><description>Registration of a malicious provider can be detected in ProviderOrder and ProviderPath parameters</description></item><item><title>Vulnerable PackageKit gives attacker root access</title><link>https://purpleshift.io/purple/2026-06-09-rsgr/</link><pubDate>Tue, 09 Jun 2026 05:00:12 +0000</pubDate><guid>https://purpleshift.io/purple/2026-06-09-rsgr/</guid><description>Detecting privilege escalation in Linux through TOCTOU vulnerability</description></item><item><title>Extending IDA Pro: а guide for reverse engineers</title><link>https://purpleshift.io/purple/2026-03-03-lgyh/</link><pubDate>Fri, 05 Jun 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/purple/2026-03-03-lgyh/</guid><description>What if your decompiler doesn&amp;rsquo;t support some RISC-V instructions</description></item><item><title>MiniPlasma: detecting a dangerous exploit from Nightmare Eclipse</title><link>https://purpleshift.io/purple/2026-06-03-hojr/</link><pubDate>Wed, 03 Jun 2026 08:40:12 +0000</pubDate><guid>https://purpleshift.io/purple/2026-06-03-hojr/</guid><description>A 2020 vulnerability still allows a local user to elevate privileges to SYSTEM</description></item><item><title>Teaching IDA Pro to understand the RISC-V P Extension</title><link>https://purpleshift.io/articles/2026-06-02-risc_v/</link><pubDate>Tue, 02 Jun 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2026-06-02-risc_v/</guid><description>How we make IDA Pro decode, interpret, and lift previously unsupported CPU instructions</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/articles/2026-06-02-risc_v/featured_riscv.jpg"/></item><item><title>CVE-2026-26980 | Ghost CMS | SQL</title><link>https://purpleshift.io/avl/2026/cve-2026-26980-_-ghost-cms-_-sql/</link><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-26980-_-ghost-cms-_-sql/</guid><description/></item><item><title>CVE-2026-32202 | Windows | Protection Mechanism Failure</title><link>https://purpleshift.io/avl/2026/cve-2026-32202-_-windows-_-protection-mechanism-failure/</link><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-32202-_-windows-_-protection-mechanism-failure/</guid><description/></item><item><title>CVE-2026-34926 | Trend Micro Apex One | PT</title><link>https://purpleshift.io/avl/2026/cve-2026-34926-_-trend-micro-apex-one-_-pt/</link><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-34926-_-trend-micro-apex-one-_-pt/</guid><description/></item><item><title>CVE-2026-41091 | Microsoft Defender | EoP</title><link>https://purpleshift.io/avl/2026/cve-2026-41091_-microsoft-defender_-eop/</link><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-41091_-microsoft-defender_-eop/</guid><description/></item><item><title>CVE-2026-42897 | Exchange | XSS</title><link>https://purpleshift.io/avl/2026/cve-2026-42897-_-exchange-_-xss/</link><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-42897-_-exchange-_-xss/</guid><description/></item><item><title>CVE-2026-44277 | FortiAuthenticator | RCE</title><link>https://purpleshift.io/avl/2026/cve-2026-44277_-fortiauthenticator_-rce/</link><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-44277_-fortiauthenticator_-rce/</guid><description/></item><item><title>Privilege escalation on SCCM undetected by antiviruses</title><link>https://purpleshift.io/purple/2026-05-26-kklj/</link><pubDate>Tue, 26 May 2026 06:10:17 +0000</pubDate><guid>https://purpleshift.io/purple/2026-05-26-kklj/</guid><description>Vulnerability CVE-2025-47179 allows for full control over SCCM</description></item><item><title>From RCE on a controller to domain admin</title><link>https://purpleshift.io/purple/2026-05-21-hyci/</link><pubDate>Thu, 21 May 2026 04:17:22 +0000</pubDate><guid>https://purpleshift.io/purple/2026-05-21-hyci/</guid><description>An interesting experience in solving a pentesting task</description></item><item><title>Role-playing games: when SCCM turns into C2</title><link>https://purpleshift.io/articles/2026-05-22-sccm/</link><pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2026-05-22-sccm/</guid><description>Catching exploitation of a vulnerability that antiviruses don&amp;rsquo;t see</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/articles/2026-05-22-sccm/featured_SCCM.png"/></item><item><title>NetNTLM hashes leak through Snipping Tool</title><link>https://purpleshift.io/purple/2026-05-18-nkdw/</link><pubDate>Mon, 18 May 2026 04:50:21 +0000</pubDate><guid>https://purpleshift.io/purple/2026-05-18-nkdw/</guid><description>How to prevent exploitation of a vulnerability in a popular image editing tool</description></item><item><title>CVE-2026-42945 | NGINX | HO</title><link>https://purpleshift.io/avl/2026/cve-2026-42945-_-nginx-_-ho/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-42945-_-nginx-_-ho/</guid><description/></item><item><title>Accessing Bitbucket through a test K8s cluster</title><link>https://purpleshift.io/purple/2026-05-13-lfym/</link><pubDate>Wed, 13 May 2026 08:10:53 +0000</pubDate><guid>https://purpleshift.io/purple/2026-05-13-lfym/</guid><description>Kubernetes API can reveal many secrets without authentication</description></item><item><title>New NTLM audit events help to detect coercing attacks</title><link>https://purpleshift.io/purple/2026-05-08-biat/</link><pubDate>Fri, 08 May 2026 09:48:48 +0000</pubDate><guid>https://purpleshift.io/purple/2026-05-08-biat/</guid><description>A chain of events 4023 and 4021 from the same IP address means an attack</description></item><item><title>LLM for pentesting: speed isn't everything</title><link>https://purpleshift.io/purple/2026-05-05-ugbv/</link><pubDate>Tue, 05 May 2026 06:11:28 +0000</pubDate><guid>https://purpleshift.io/purple/2026-05-05-ugbv/</guid><description>We found out which local LLMs are better at finding vulnerabilities</description></item><item><title>Pentesting by AI: Local LLMs Benchmark</title><link>https://purpleshift.io/articles/2026-05-05-llm-pentesting/</link><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2026-05-05-llm-pentesting/</guid><description>Comparative analysis of multiple LLMs in their ability to uncover vulnerabilities</description></item><item><title>CopyFail: Decade-old kernel flaw in all Linux distributions</title><link>https://purpleshift.io/purple/2026-04-30-vtqo/</link><pubDate>Thu, 30 Apr 2026 13:44:42 +0000</pubDate><guid>https://purpleshift.io/purple/2026-04-30-vtqo/</guid><description>Severe vulnerability allows an unprivileged user to gain root</description></item><item><title>PhantomRPC: A new method for privilege escalation</title><link>https://purpleshift.io/purple/2026-04-24-juwr/</link><pubDate>Fri, 24 Apr 2026 08:46:16 +0000</pubDate><guid>https://purpleshift.io/purple/2026-04-24-juwr/</guid><description>Fake RPC server can impersonate the security context of the calling client, up to SYSTEM</description></item><item><title>How to make OpenClaw execute malicious commands</title><link>https://purpleshift.io/purple/2026-04-22-vizw/</link><pubDate>Wed, 22 Apr 2026 04:47:30 +0000</pubDate><guid>https://purpleshift.io/purple/2026-04-22-vizw/</guid><description>We found a vulnerabilty in a popular LLM agent</description></item><item><title>Attacks via OpenClaw: when your LLM can make RCE</title><link>https://purpleshift.io/articles/2026-04-21-openclaw/</link><pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2026-04-21-openclaw/</guid><description>Following a special link, the AI agent itself will execute shell commands</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/articles/2026-04-21-openclaw/featured_openclaw.png"/></item><item><title>Privilege escalation on SCCM with WebClient</title><link>https://purpleshift.io/purple/2026-04-14-irtw/</link><pubDate>Tue, 14 Apr 2026 08:10:24 +0000</pubDate><guid>https://purpleshift.io/purple/2026-04-14-irtw/</guid><description>An attacker can take over the domain if automatic client push installation is enabled on the server</description></item><item><title>Who are the SOC and why do IS professionals need a tester?</title><link>https://purpleshift.io/conf/2026/2026-04-10-olga-kuznetsova/</link><pubDate>Fri, 10 Apr 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2026/2026-04-10-olga-kuznetsova/</guid><description/></item><item><title>Bruteforcing WPA 802.11r: a new module for HashCat</title><link>https://purpleshift.io/purple/2026-04-09-deve/</link><pubDate>Thu, 09 Apr 2026 07:19:17 +0000</pubDate><guid>https://purpleshift.io/purple/2026-04-09-deve/</guid><description>Previously, pentesting tools did not work with 802.11r hashes</description></item><item><title>CVE-2026-21509 | MS Office | SFB</title><link>https://purpleshift.io/avl/2026/cve-2026-21509-_-ms-office-_-sfb/</link><pubDate>Thu, 09 Apr 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-21509-_-ms-office-_-sfb/</guid><description/></item><item><title>CVE-2026-25676 | HP installer | dll hijack</title><link>https://purpleshift.io/avl/2026/cve-2026-25676-_-hp-installer-_-dll-hijack/</link><pubDate>Thu, 09 Apr 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-25676-_-hp-installer-_-dll-hijack/</guid><description/></item><item><title>CVE-2026-25747 | Apache Camel | RCE</title><link>https://purpleshift.io/avl/2026/cve-2026-25747-_-apache-camel-_-rce/</link><pubDate>Thu, 09 Apr 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-25747-_-apache-camel-_-rce/</guid><description/></item><item><title>Invisible attacks with bind mount</title><link>https://purpleshift.io/purple/2026-04-06-oqqa/</link><pubDate>Mon, 06 Apr 2026 07:12:39 +0000</pubDate><guid>https://purpleshift.io/purple/2026-04-06-oqqa/</guid><description>A technique much simpler than rootkit can make a malicious process invisible</description></item><item><title>Incidents 2025: MDR and IR Report</title><link>https://purpleshift.io/purple/2026-03-31-fusf/</link><pubDate>Tue, 31 Mar 2026 10:51:13 +0000</pubDate><guid>https://purpleshift.io/purple/2026-03-31-fusf/</guid><description>Combining MDR and IR statistics provides a better understanding of current and emerging threats</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/purple/2026-03-31-fusf/MDR-report-2026-cover.png"/></item><item><title>CVE-2026-20127 | Cisco | AB</title><link>https://purpleshift.io/avl/2026/cve-2026-20127--cisco--ab/</link><pubDate>Thu, 26 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-20127--cisco--ab/</guid><description/></item><item><title>CVE-2026-25769 | Wazuh | RCE</title><link>https://purpleshift.io/avl/2026/cve-2026-25769--wazuh--rce/</link><pubDate>Thu, 26 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2026/cve-2026-25769--wazuh--rce/</guid><description/></item><item><title>Yes, we can RCE via your AI agent OpenClaw</title><link>https://purpleshift.io/purple/2026-03-24-rkdd/</link><pubDate>Tue, 24 Mar 2026 07:59:44 +0000</pubDate><guid>https://purpleshift.io/purple/2026-03-24-rkdd/</guid><description>Overly autonomous LLM executes commands not requested by the user</description></item><item><title>How we patched PEAS and ensured Provisioning</title><link>https://purpleshift.io/purple/2026-03-23-dcul/</link><pubDate>Mon, 23 Mar 2026 06:45:27 +0000</pubDate><guid>https://purpleshift.io/purple/2026-03-23-dcul/</guid><description>If Exchange ActiveSync requires security policy agreement, PEAS still works</description></item><item><title>Attribution by Slang: Exposing Horabot</title><link>https://purpleshift.io/purple/2026-03-18-nffa/</link><pubDate>Wed, 18 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/purple/2026-03-18-nffa/</guid><description>How our MDR team investigated a Brazilian hacker attack on Mexico</description></item><item><title>The moment of controls, services, and management in cybersecurity strategies</title><link>https://purpleshift.io/conf/2026/2026-03-17-eduardo-ovalle/</link><pubDate>Tue, 17 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2026/2026-03-17-eduardo-ovalle/</guid><description/></item><item><title>Accessing services through Kubernetes</title><link>https://purpleshift.io/purple/2026-03-11-cqoo/</link><pubDate>Wed, 11 Mar 2026 06:04:04 +0000</pubDate><guid>https://purpleshift.io/purple/2026-03-11-cqoo/</guid><description>K8s clusters can be an interesting target during a pentest</description></item><item><title>Incidents 2020-2025: Industry Statistics</title><link>https://purpleshift.io/purple/2026-03-02-etxv/</link><pubDate>Tue, 03 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/purple/2026-03-02-etxv/</guid><description>What types of attacks are leading in different sectors in different years?</description></item><item><title>History of Critical Incidents</title><link>https://purpleshift.io/articles/2026-03-02-critical-incidents/</link><pubDate>Mon, 02 Mar 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2026-03-02-critical-incidents/</guid><description>How critical incidents of different types were distributed across industries in 2020-2025</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/articles/2026-03-02-critical-incidents/featured_fishing.png"/></item><item><title>Hidden Tunnel: Proxying through WebSocket Secure</title><link>https://purpleshift.io/purple/2026-02-24-qjtc/</link><pubDate>Tue, 24 Feb 2026 05:35:02 +0000</pubDate><guid>https://purpleshift.io/purple/2026-02-24-qjtc/</guid><description>Another story of non-standard remote access</description></item><item><title>Attack with Four Remote Access Channels</title><link>https://purpleshift.io/purple/2026-02-19-tvxz/</link><pubDate>Thu, 19 Feb 2026 04:30:32 +0000</pubDate><guid>https://purpleshift.io/purple/2026-02-19-tvxz/</guid><description>Attackers used Velociraptor, VS Code Tunnel, Cloudflare Tunnel, and Zoho Assist</description></item><item><title>Scan2hive helps upload data to Hive</title><link>https://purpleshift.io/purple/2026-02-10-zoyf/</link><pubDate>Tue, 10 Feb 2026 06:56:04 +0000</pubDate><guid>https://purpleshift.io/purple/2026-02-10-zoyf/</guid><description>How we improved our work with Hexway Pentest Suite</description></item><item><title>How to detect Notepad++ attack</title><link>https://purpleshift.io/purple/2026-02-05-kmwb/</link><pubDate>Thu, 05 Feb 2026 06:56:04 +0000</pubDate><guid>https://purpleshift.io/purple/2026-02-05-kmwb/</guid><description>Attackers were distributing malware from Notepad++ update center</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/purple/2026-02-05-kmwb/featured_Notepad_hack.png"/></item><item><title>Bypassing authentication in Fortinet products via SSO</title><link>https://purpleshift.io/purple/2026-02-04-gjgx/</link><pubDate>Wed, 04 Feb 2026 08:21:47 +0000</pubDate><guid>https://purpleshift.io/purple/2026-02-04-gjgx/</guid><description>An attacker with a FortiCloud account can log in to other users&amp;rsquo; FortiOS</description></item><item><title>Implementation of TCP transport for the Mythic agent</title><link>https://purpleshift.io/purple/2026-01-30-saqk/</link><pubDate>Fri, 30 Jan 2026 11:41:55 +0000</pubDate><guid>https://purpleshift.io/purple/2026-01-30-saqk/</guid><description>If Mythic agents communicate over HTTP(S), they are easy to detect</description></item><item><title>Cognitive Biases in SOC Analysts' Work</title><link>https://purpleshift.io/purple/2026-01-19-akaq/</link><pubDate>Mon, 19 Jan 2026 10:52:55 +0000</pubDate><guid>https://purpleshift.io/purple/2026-01-19-akaq/</guid><description>Anchoring effect, reasoning by analogy, and other logical errors</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/purple/2026-01-19-akaq/featured_Suspicious_Service.png"/></item><item><title>Human factor in cyber defense: when the enemy is our own mindset</title><link>https://purpleshift.io/articles/2026-01-16-mindset/</link><pubDate>Fri, 16 Jan 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2026-01-16-mindset/</guid><description>The most common biases that occur in SOC and how to avoid them</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/articles/2026-01-16-mindset/featured_Confirmation_Bias.png"/></item><item><title>Disabling Windows Defender via symlink</title><link>https://purpleshift.io/purple/2026-01-12-bmka/</link><pubDate>Mon, 12 Jan 2026 00:00:00 +0000</pubDate><guid>https://purpleshift.io/purple/2026-01-12-bmka/</guid><description>Built-in antivirus could be switched off without any third-party software</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/purple/2026-01-12-bmka/featured_Defender.png"/></item><item><title>Top-10 posts of PurpleShift in 2025</title><link>https://purpleshift.io/purple/2025-12-26-ikap/</link><pubDate>Fri, 26 Dec 2025 09:47:52 +0000</pubDate><guid>https://purpleshift.io/purple/2025-12-26-ikap/</guid><description>We selected posts that got the most likes</description></item><item><title>Overview of Industrial Cyber Threats and How to Counter Them</title><link>https://purpleshift.io/conf/2025/2025-11-26-sergey-sidorov/</link><pubDate>Wed, 26 Nov 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-11-26-sergey-sidorov/</guid><description/></item><item><title>Entry Points to the Cloud</title><link>https://purpleshift.io/conf/2025/2025-11-13-sergey-bobrov/</link><pubDate>Thu, 13 Nov 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-11-13-sergey-bobrov/</guid><description/></item><item><title>CVE-2025-7771: Antivirus Evasion Through Legitimate Driver Abuse</title><link>https://purpleshift.io/conf/2025/2025-11-10-ashley-munoz/</link><pubDate>Mon, 10 Nov 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-11-10-ashley-munoz/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2025/2025-11-10-ashley-munoz/featured_ekoparty2.webp"/></item><item><title>Attacks on Automotive Manufacturing</title><link>https://purpleshift.io/conf/2025/2025-10-18-sergey-sidorov/</link><pubDate>Sat, 18 Oct 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-10-18-sergey-sidorov/</guid><description/></item><item><title>Creating a QA process from scratch</title><link>https://purpleshift.io/conf/2025/2025-10-17-olga-kuznetsova/</link><pubDate>Fri, 17 Oct 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-10-17-olga-kuznetsova/</guid><description/></item><item><title>Offensive Security: how to turn Pentesting and RedTeaming into a strategy</title><link>https://purpleshift.io/conf/2025/2025-10-15-vyacheslav-vasin/</link><pubDate>Wed, 15 Oct 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-10-15-vyacheslav-vasin/</guid><description/></item><item><title>Ransomware attacks: Risks, Impacts, and Prevention</title><link>https://purpleshift.io/conf/2025/2025-10-10-cristian-souza/</link><pubDate>Fri, 10 Oct 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-10-10-cristian-souza/</guid><description/></item><item><title>How do we know if we are prepared to respond to current cyberattacks?</title><link>https://purpleshift.io/conf/2025/2025-09-25-ashley-munoz/</link><pubDate>Thu, 25 Sep 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-09-25-ashley-munoz/</guid><description/></item><item><title>Attacks on warehouse infrastructure: where robots meet humans</title><link>https://purpleshift.io/conf/2025/2025-09-24-sergey-sidorov/</link><pubDate>Wed, 24 Sep 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-09-24-sergey-sidorov/</guid><description/></item><item><title>Turn me off, Turn me on</title><link>https://purpleshift.io/conf/2025/2025-09-17-khaydar-kabibo/</link><pubDate>Wed, 17 Sep 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-09-17-khaydar-kabibo/</guid><description/></item><item><title>Collect the shadows of compromised systems</title><link>https://purpleshift.io/conf/2025/2025-09-07-areg-baghinyan/</link><pubDate>Sun, 07 Sep 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-09-07-areg-baghinyan/</guid><description/></item><item><title>Lessons Learned from the ShrinkLocker Ransomware: From Response to Detection</title><link>https://purpleshift.io/conf/2025/2025-07-02-cristian-souza/</link><pubDate>Wed, 02 Jul 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-07-02-cristian-souza/</guid><description/></item><item><title>Hybrid SOC 2025: How AI, Automation, and Humans Defeat Cyber Threats Together</title><link>https://purpleshift.io/conf/2025/2025-06-26-alexey-peshik/</link><pubDate>Thu, 26 Jun 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-06-26-alexey-peshik/</guid><description/></item><item><title>Find the shadow, hunting advanced malware</title><link>https://purpleshift.io/conf/2025/2025-06-14-areg-baghinyan/</link><pubDate>Sat, 14 Jun 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-06-14-areg-baghinyan/</guid><description/></item><item><title>Revealing LockBit's secrets: From technical analysis to tactical perspective</title><link>https://purpleshift.io/conf/2025/2025-06-13-eduardo-ovalle/</link><pubDate>Fri, 13 Jun 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-06-13-eduardo-ovalle/</guid><description/></item><item><title>Cyber security aspects of digital trade</title><link>https://purpleshift.io/conf/2025/2025-06-06-cristian-souza/</link><pubDate>Fri, 06 Jun 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-06-06-cristian-souza/</guid><description/></item><item><title>AI-Enhanced Forensics Analysis of Web Application Attacks</title><link>https://purpleshift.io/conf/2025/2025-05-28-ahmad-zaidi-said/</link><pubDate>Wed, 28 May 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-05-28-ahmad-zaidi-said/</guid><description/></item><item><title>Agentic AI Security: Managing Autonomous AI Systems in Cybersecurity</title><link>https://purpleshift.io/conf/2025/2025-05-27-ayman-shaaban/</link><pubDate>Tue, 27 May 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-05-27-ayman-shaaban/</guid><description/></item><item><title>Are we ready for the threats related to AI?</title><link>https://purpleshift.io/conf/2025/2025-05-21-eduardo-ovalle/</link><pubDate>Wed, 21 May 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-05-21-eduardo-ovalle/</guid><description/></item><item><title>The Art of Finding Hidden threats</title><link>https://purpleshift.io/conf/2025/2025-05-16-ahmed-khlief/</link><pubDate>Fri, 16 May 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-05-16-ahmed-khlief/</guid><description/></item><item><title>Targeted Attacks: Be Ready, Respond Smart, Recover Fast</title><link>https://purpleshift.io/conf/2025/2025-04-28-ayman-shaaban/</link><pubDate>Mon, 28 Apr 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-04-28-ayman-shaaban/</guid><description/></item><item><title>New Ransomware Ymir &amp; Fortinet FortiClientEMS (CVE-2023-48788)</title><link>https://purpleshift.io/conf/2025/2025-03-01-ashley-munoz/</link><pubDate>Sat, 01 Mar 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-03-01-ashley-munoz/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2025/2025-03-01-ashley-munoz/featured_HackGDL.jpg"/></item><item><title>AI-Driven Incident Response</title><link>https://purpleshift.io/conf/2025/2025-02-27-ahmad-zaidi-said/</link><pubDate>Thu, 27 Feb 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-02-27-ahmad-zaidi-said/</guid><description/></item><item><title>Technologies and products for equipping the SOC</title><link>https://purpleshift.io/conf/2025/2025-02-13-sergey-soldatov/</link><pubDate>Thu, 13 Feb 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-02-13-sergey-soldatov/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/conf/2025/2025-02-13-sergey-soldatov/featured_amlife.jpg"/></item><item><title>Dangers of AI: disinformation using ChatGPT</title><link>https://purpleshift.io/conf/2025/2025-01-28-eduardo-ovalle/</link><pubDate>Tue, 28 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/conf/2025/2025-01-28-eduardo-ovalle/</guid><description/></item><item><title>About us</title><link>https://purpleshift.io/about/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/about/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/about/featured_1.jpg"/></item><item><title>CVE-2025-0282 | Ivanti | RCE</title><link>https://purpleshift.io/avl/2025/cve-2025-0282--ivanti--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-0282--ivanti--rce/</guid><description/></item><item><title>CVE-2025-0411 | 7-Zip | PMF</title><link>https://purpleshift.io/avl/2025/cve-2025-0411--7-zip--pmf/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-0411--7-zip--pmf/</guid><description/></item><item><title>CVE-2025-22225 | VMware | AW</title><link>https://purpleshift.io/avl/2025/cve-2025-22225--vmware--aw/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-22225--vmware--aw/</guid><description/></item><item><title>CVE-2025-24071 | Windows File Explorer | spoofing</title><link>https://purpleshift.io/avl/2025/cve-2025-24071---windows-file-explorer--spoofing/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-24071---windows-file-explorer--spoofing/</guid><description/></item><item><title>CVE-2025-24813 | Tomcat | RCE</title><link>https://purpleshift.io/avl/2025/cve-2025-24813--tomcat--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-24813--tomcat--rce/</guid><description/></item><item><title>CVE-2025-29824 | Windows | LPE</title><link>https://purpleshift.io/avl/2025/cve-2025-29824--windows--lpe/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-29824--windows--lpe/</guid><description/></item><item><title>CVE-2025-29927 | NextJs | AB</title><link>https://purpleshift.io/avl/2025/cve-2025-29927--nextjs--ab/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-29927--nextjs--ab/</guid><description/></item><item><title>CVE-2025-31644 | Big-IP | RCE</title><link>https://purpleshift.io/avl/2025/cve-2025-31644--big-ip--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-31644--big-ip--rce/</guid><description/></item><item><title>CVE-2025-32433 | SSH | RCE</title><link>https://purpleshift.io/avl/2025/cve-2025-32433--ssh--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-32433--ssh--rce/</guid><description/></item><item><title>CVE-2025-32463 | sudo | LPE</title><link>https://purpleshift.io/avl/2025/cve-2025-32463--sudo--lpe/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-32463--sudo--lpe/</guid><description/></item><item><title>CVE-2025-33053 | WEBDAV | RCE</title><link>https://purpleshift.io/avl/2025/cve-2025-33053--webdav--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-33053--webdav--rce/</guid><description/></item><item><title>CVE-2025-33073 | MS | PE</title><link>https://purpleshift.io/avl/2025/cve-2025-33073--ms--pe/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-33073--ms--pe/</guid><description/></item><item><title>CVE-2025-34291 | Langflow | AT</title><link>https://purpleshift.io/avl/2025/cve-2025-34291--langflow--at/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-34291--langflow--at/</guid><description/></item><item><title>CVE-2025-34291 | Langflow | AT</title><link>https://purpleshift.io/avl/2025/cve-2025-49113--roundcube--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-49113--roundcube--rce/</guid><description/></item><item><title>CVE-2025-61882 | Oracle | RCE</title><link>https://purpleshift.io/avl/2025/cve-2025-61882--oracle--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-61882--oracle--rce/</guid><description/></item><item><title>CVE-2025-61884 | Oracle | ID</title><link>https://purpleshift.io/avl/2025/cve-2025-61884--oracle--id/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-61884--oracle--id/</guid><description/></item><item><title>CVE-2025-64446 | Fortiweb | PT</title><link>https://purpleshift.io/avl/2025/cve-2025-64446--fortiweb--pt/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-64446--fortiweb--pt/</guid><description/></item><item><title>CVE-2025-65964 | n8n | RCE</title><link>https://purpleshift.io/avl/2025/cve-2025-65964--n8n--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-65964--n8n--rce/</guid><description/></item><item><title>CVE-2025-8088 | WinRar | PT</title><link>https://purpleshift.io/avl/2025/cve-2025-8088--winrar--pt/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-2025-8088--winrar--pt/</guid><description/></item><item><title>CVE-2025–55182 | RSC | RCE</title><link>https://purpleshift.io/avl/2025/cve-202555182--rsc--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve-202555182--rsc--rce/</guid><description/></item><item><title>CVE‑2025‑31324 | SAP | RCE</title><link>https://purpleshift.io/avl/2025/cve202531324--sap--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve202531324--sap--rce/</guid><description/></item><item><title>CVE‑2025‑42999 | SAP | RCE</title><link>https://purpleshift.io/avl/2025/cve202542999--sap--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve202542999--sap--rce/</guid><description/></item><item><title>CVE‑2025‑47827 | IGEL | SBB</title><link>https://purpleshift.io/avl/2025/cve202547827--igel--sbb/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve202547827--igel--sbb/</guid><description/></item><item><title>CVE‑2025‑53770 | SharePoint | RCE</title><link>https://purpleshift.io/avl/2025/cve202553770--sharepoint--rce/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2025/cve202553770--sharepoint--rce/</guid><description/></item><item><title>Disclaimer</title><link>https://purpleshift.io/disclaimer/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/disclaimer/</guid><description/></item><item><title>Tools</title><link>https://purpleshift.io/tools/</link><pubDate>Wed, 01 Jan 2025 00:00:00 +0000</pubDate><guid>https://purpleshift.io/tools/</guid><description/><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/tools/featured.jpg"/></item><item><title>Attacking Security Researchers via Visual Studio</title><link>https://purpleshift.io/articles/2025-05-01-attacking-security-researchers-via-visual-studio/</link><pubDate>Fri, 05 Jul 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/articles/2025-05-01-attacking-security-researchers-via-visual-studio/</guid><description>A new technique to exploit VS IDE using SUO files</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://purpleshift.io/articles/2025-05-01-attacking-security-researchers-via-visual-studio/featured-payload.png"/></item><item><title>CVE-2024-1086 | Linux-kernel | LPE</title><link>https://purpleshift.io/avl/2024/cve-2024-1086--linux-kernel--lpe/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-1086--linux-kernel--lpe/</guid><description/></item><item><title>CVE-2024-1512 | WordPress | SQL</title><link>https://purpleshift.io/avl/2024/cve-2024-1512--wordpress--sql/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-1512--wordpress--sql/</guid><description/></item><item><title>CVE-2024-21412 | SmartScreen</title><link>https://purpleshift.io/avl/2024/cve-2024-21412--smartscreen/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-21412--smartscreen/</guid><description/></item><item><title>CVE-2024-21413 | Outlook | RCE</title><link>https://purpleshift.io/avl/2024/cve-2024-21413--outlook--rce/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-21413--outlook--rce/</guid><description/></item><item><title>CVE-2024-23113 CVE-2024-47575 | Fortinet | LPE-RCE</title><link>https://purpleshift.io/avl/2024/cve-2024-23113-cve-2024-47575--fortinet--lpe-rce/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-23113-cve-2024-47575--fortinet--lpe-rce/</guid><description/></item><item><title>CVE-2024-24919 | Check Point SVN | AFR</title><link>https://purpleshift.io/avl/2024/cve-2024-24919--check-point-svn--afr/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-24919--check-point-svn--afr/</guid><description/></item><item><title>CVE-2024-25600 | WordPress | RCE</title><link>https://purpleshift.io/avl/2024/cve-2024-25600--wordpress--rce/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-25600--wordpress--rce/</guid><description/></item><item><title>CVE-2024-30088 | Windows kernel | AMW</title><link>https://purpleshift.io/avl/2024/cve-2024-30088--windows-kernel--amw/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-30088--windows-kernel--amw/</guid><description/></item><item><title>CVE-2024-32002 | Git | RCE</title><link>https://purpleshift.io/avl/2024/cve-2024-32002--git--rce/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-32002--git--rce/</guid><description/></item><item><title>CVE-2024-37404 | Ivanti | RCE</title><link>https://purpleshift.io/avl/2024/cve-2024-37404--ivanti--rce/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-37404--ivanti--rce/</guid><description/></item><item><title>CVE-2024-38063 | Windows | RCE</title><link>https://purpleshift.io/avl/2024/cve-2024-38063--windows--rce/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-38063--windows--rce/</guid><description/></item><item><title>CVE-2024-38112| MSHTML | RCE</title><link>https://purpleshift.io/avl/2024/cve-2024-38112-mshtml--rce/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-38112-mshtml--rce/</guid><description/></item><item><title>CVE-2024-38200| Windows | LPE</title><link>https://purpleshift.io/avl/2024/cve-2024-38200-windows--lpe/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-38200-windows--lpe/</guid><description/></item><item><title>CVE-2024-45409 | Gitlab | UA</title><link>https://purpleshift.io/avl/2024/cve-2024-45409---gitlab--ua/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-45409---gitlab--ua/</guid><description/></item><item><title>CVE-2024-4577 | PHP | RCE</title><link>https://purpleshift.io/avl/2024/cve-2024-4577--php--rce/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-4577--php--rce/</guid><description/></item><item><title>CVE-2024-4985 | Github | UA</title><link>https://purpleshift.io/avl/2024/cve-2024-4985--github--ua/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-4985--github--ua/</guid><description/></item><item><title>CVE-2024-50379 | Tomcat | RCE</title><link>https://purpleshift.io/avl/2024/cve-2024-50379--tomcat--rce/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-50379--tomcat--rce/</guid><description/></item><item><title>CVE-2024-6387 | OpenSSH | RCE</title><link>https://purpleshift.io/avl/2024/cve-2024-6387--openssh--rce/</link><pubDate>Mon, 01 Jan 2024 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2024/cve-2024-6387--openssh--rce/</guid><description/></item><item><title>CVE-2023-35359 | Windows | LPE</title><link>https://purpleshift.io/avl/2023/cve-2023-35359--windows--lpe/</link><pubDate>Sun, 01 Jan 2023 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2023/cve-2023-35359--windows--lpe/</guid><description/></item><item><title>CVE-2023-48788 | FortinetClientEMS | RCE</title><link>https://purpleshift.io/avl/2023/cve-2023-48788--fortinetclientems--rce/</link><pubDate>Sun, 01 Jan 2023 00:00:00 +0000</pubDate><guid>https://purpleshift.io/avl/2023/cve-2023-48788--fortinetclientems--rce/</guid><description/></item></channel></rss>