Skip to content

Security

12 articles, newest first.

Vulnerability research, exploit development, and the CVE writeups we publish once a patch has shipped and the risk is understood.

A dark Egnworks security banner representing malicious style data crossing into Magento template execution.

Security

CVE-2026-75650 StyleSmuggler Magento RCE

A technical analysis of CVE-2026-75650, the actively exploited Magento template injection that gives unauthenticated attackers remote code execution.

Jacob Strix

A laptop displays source code during an investigation into compromised npm packages.

Security

ChainDrop Poisoned the npm Supply Chain

ChainDrop turned trusted npm releases into a self-propagating credential stealer across Keyv, Cacheable, and hundreds of downstream packages.

Jacob Strix

wp2shell CVE-2026-63030 Unauthenticated RCE in WordPress Core

Security

wp2shell CVE-2026-63030 Unauthenticated RCE in WordPress Core

How wp2shell chains two WordPress core bugs into unauthenticated RCE with a full exploit walkthrough SIEM detection and the patch for CVE-2026-63030 and CVE-2026-60137.

Jacob Strix

Pickle Deserialization RCE How a Malicious AI Model Runs Code the Moment You Load It

Security

Pickle Deserialization RCE How a Malicious AI Model Runs Code the Moment You Load It

How a malicious AI model runs code on load through pickle deserialization. Real CVEs a working PoC SIEM detection and the safetensors fix.

Jacob Strix

CVE-2025-55182 React2Shell Unauthenticated RCE in React

Security

CVE-2025-55182 React2Shell Unauthenticated RCE in React

How CVE-2025-55182 React2Shell turns a React Server Components request into unauthenticated RCE and how to patch it fast.

Jacob Strix

Hunting LOLBins in Your SIEM With Sysmon and Sigma

Security

Hunting LOLBins in Your SIEM With Sysmon and Sigma

A hands on build for detecting living off the land binaries. Sysmon visibility a Sigma rule for certutil and Atomic Red Team validation with real configs.

Jacob Strix