KERNEL: LZ-SYS v2.6.4 SYS_ARCH: X86_64 // NEURAL_INTERP
LATENCY: 0.8ms KEYS: [T] THEME / [/] SEARCH
CMS EXPLOIT RESEARCH // RED TEAM // CVE HUNTING

DISPATCHES FROM THE RESEARCH KERNEL.

Source-driven exploit research, CVE variant analysis, and red team tradecraft. Diffed patches, chained primitives, and the disclosure trail behind each one.

CATEGORY:
/

RESEARCH LOG & PREPRINTS

[2 RECORDS FOUND]
MEMO #006 DATE: 2026-08-15
EST. TIME: ~12 MIN

DropoutJeep: The Phishing Simulator That Refuses to Drop Out

DropoutJeep is a phishing-simulation and red-team platform with 80-plus utility modules spanning OSINT, pretext generation, payload crafting, C2, exfiltration, evasion, persistence, and deliverability. This memo covers why it exists, why it keeps growing, and why its authors now read Gmail spam-filter documentation for fun.

READ DISPATCH ->
MEMO #005 DATE: TBD
EST. TIME: ~8 MIN

Stored XSS in a Widely Deployed CMS Plugin

An unauthenticated stored XSS in a popular CMS extension, found while diffing an unrelated patch. Vendor and plugin name withheld pending coordinated disclosure. Full writeup, PoC, and CVE reference land here the day the fix ships.

READ DISPATCH →
MEMO #004 DATE: 2026-08-15
EST. TIME: ~15 MIN

GrandScream: From One Desk Phone to a Root PBX

Recon methodology and chain automation: one unauthenticated request against a Grandstream GXP phone becomes a root shell on the UCM PBX. Blind-oracle SQLi, credential reuse graphs, and the stdlib-only Python script that compresses the whole chain into thirty seconds.

READ DISPATCH →

[NO MATCHING RESEARCH DISPATCHES FOUND]

Try clearing your search query or switching the category filter.