Tagged articles

PoC

6 articles · Page 1 of 1
Black & White Path
Black & White Path
Jul 26, 2026 · Information Security

CVE‑2026 PoC Collection: All 12 Exploit Codes in One Repository

A GitHub repository named cve-2026-poc-collection, maintained by researcher XZ1r0, aggregates twelve high‑severity CVE‑2026 proof‑of‑concept exploits across web, Linux, Windows and other categories, detailing their impact, implementation languages, and offering a search script to help security professionals quickly locate and analyze the code.

CVE-2026KubernetesPoC
0 likes · 9 min read
CVE‑2026 PoC Collection: All 12 Exploit Codes in One Repository
Black & White Path
Black & White Path
Jul 13, 2026 · Information Security

Deep Dive into CVE‑2026‑47291: Windows HTTP.sys RCE and Public PoC

Security researcher Omair released a PoC for CVE‑2026‑47291, a critical integer‑overflow flaw in Windows HTTP.sys that enables unauthenticated remote code execution with SYSTEM privileges across a fourteen‑year span of Windows client and server versions, prompting urgent patching and mitigation guidance.

CVE-2026-47291HTTP.sysPoC
0 likes · 10 min read
Deep Dive into CVE‑2026‑47291: Windows HTTP.sys RCE and Public PoC
Black & White Path
Black & White Path
Jun 3, 2026 · Information Security

Stealing GitHub Tokens via a One‑Click VSCode WebView Exploit

The article details how a VSCode WebView vulnerability lets an attacker capture the OAuth token issued to github.dev, use keyboard‑event relay to install a malicious extension, and ultimately gain read‑write access to all of a victim’s private GitHub repositories, while also providing a PoC and mitigation steps.

GitHub tokenOAuthPoC
0 likes · 12 min read
Stealing GitHub Tokens via a One‑Click VSCode WebView Exploit
Black & White Path
Black & White Path
May 18, 2026 · Information Security

Windows Kernel LPE (CVE‑2026‑40369) PoC: Privilege Escalation from Chrome Sandbox

CVE‑2026‑40369 is an arbitrary kernel‑address write bug in ntoskrnl.exe that lets a low‑privilege attacker invoke NtQuerySystemInformation from the Chrome sandbox to gain SYSTEM rights on vulnerable Windows 11 and Server 2025 builds, with a fully functional PoC released on GitHub.

CVE-2026-40369Chrome sandboxNtQuerySystemInformation
0 likes · 10 min read
Windows Kernel LPE (CVE‑2026‑40369) PoC: Privilege Escalation from Chrome Sandbox