At the end of last year we compiled a TOP-10 of our channel’s posts that received the most likes in 2025. Back then, our content was Russian only.
This year, we started the PurpleShift blog in English, so we are going to publish English digests now and then. And here is the first one: let’s look back at the 10 most popular posts of the first half of 2026. If you were on vacation this spring, you might have missed them!
(1) Pentest practice by Irina Belyaeva — how to gain access to Bitbucket via a test Kubernetes cluster:
https://purpleshift.io/purple/2026-05-13-lfym/
(2) Taha Hakeem compiled cognitive biases that hinder SOC analysts in their work, and proposed several methods to identify such mindset mistakes:
https://purpleshift.io/purple/2026-01-19-akaq/
(3) Attackers don’t necessarily need rootkits to make malicious files invisible. Alexander Golovin explains a technique for hiding processes in Linux via bind mount:
https://purpleshift.io/purple/2026-04-06-oqqa/
(4) Khaydar Kabibo studied the internal Windows RPC protocol and discovered a new local privilege escalation vector, named PhantomRPC:
https://purpleshift.io/purple/2026-04-24-juwr/
(5) Another pentest case from Irina Belyaeva — various techniques to go from RCE on a domain controller to the domain admin:
https://purpleshift.io/purple/2026-05-21-hyci/
(6) Sergey Bobrov, Vladas Bulavas and Vitaly Salnikov proved that an overly autonomous LLM-agent OpenClaw can execute malicious commands on your computer:
https://purpleshift.io/purple/2026-04-22-vizw/
(7) Alexander Golovin shows the method for disabling Windows Defender without additional software, just via a symbolic link (symlink):
https://purpleshift.io/purple/2026-01-12-bmka/
(8) MiniPlasma is the most troublesome exploit from anonymous hacker Nightmare Eclipse. This post by Sofya Figurnaya details how to detect this attack:
https://purpleshift.io/purple/2026-06-03-hojr/
(9) For several months, attackers had access to the Notepad++ update center and distributed custom malware to targeted victims. Alexander Rodchenko’s recommendations for SOC analysts regarding this threat:
https://purpleshift.io/purple/2026-02-05-kmwb/
(10) What can a firmware researcher do when he encounters a little-known microcontroller or a fresh CPU architecture? See how our reverse engineers tought IDA Pro to understand the RISC-V P Extension:
https://purpleshift.io/purple/2026-03-03-lgyh/
PS. If you were on vacation this summer (not spring), stay tuned for the next (summer) digest!
