Discover expert insights on the latest exploits, penetration testing tactics, and real-world vulnerabilities to strengthen your cybersecurity defenses.
The Exploit: Penetration Testing Insights From The Frontlines
Articles Categorized as Exploits
wp2shell: Critical WordPress Unauthenticated to Remote Code Execution Vulnerability
It’s rare for WordPress itself to have CVEs. CVE-2026-63030 and CVE-2026-60137 combine to create the critical unauthenticated to RCE vulnerability wp2shell.
RoguePlanet: The Defender Zero-day that Survived Microsoft’s June Patch
The new critical Microsoft Defender exploit, RoguePlanet (CVE-2026-50656), is confirmed active in the wild. Learn what it is and how to protect your network.
Building Security Tools from Source to Bypass Endpoint Security
Endpoint security detects many malicious files created with pentest tools, but pentesters can sometimes bypass this by rebuilding source code. Learn how here.
BloodHound’s Community Edition has everything a penetration tester needs to enumerate relationships in a domain in order to gain more access, even Domain Admin.
CVE-2026-36748: XSS in Rock RMS Leads to Privilege Escalation
Raxis Lead Pentester Jason Taylor recently discovered CVE-2026-36748, a high-risk XSS vulnerability in Rock RMS that allows privilege escalation to admin.