codewhitesec.bsky.social @codewhitesec.bsky.social · 05/02/2026Highly recommend the writeup from our @fl0mb.bsky.social and congrats on this well-deserved achievement! 043
codewhitesec.bsky.social @codewhitesec.bsky.social · 23/01/2026You like technical deep dives into binary exploitation and crazy heap wizardry? Then you'll like our blog post about unauth'ed RCE in NetSupport Manager aka CVE-2025-34164 & CVE-2025-34165 code-white.com/blog/2026-01...code-white.comCODE WHITE | Unauthenticated RCE in NetSupport Manager - A Technical Deep DiveNetSupport Manager is a remote control and support software that we find surprisingly often utilized in sensitive *Operational Technology (OT)* environments, such as production plant networks. Besides... 068
codewhitesec.bsky.social @codewhitesec.bsky.social · 05/12/2025Our 2024 applicants challenge is officially #roasted: the full BeanBeat × Maultaschenfabrikle walkthrough is now online. Unwrap the write-up at apply-if-you-can.com/walkthrough/... and revisit the hacks that escalated from cold brew to full breach.apply-if-you-can.comCODE WHITE - Applicants ChallengeApplicants Challenge! Face real-world vulns, earn trophies, First Bloods & epic swag! 066
codewhitesec.bsky.social @codewhitesec.bsky.social · 29/10/2025Latest ≠ Greatest? A Retrospective Analysis of CVE-2025-59287 in Microsoft WSUS from our very own @mwulftange.bsky.social who loves converting n-days to 0-days code-white.com/blog/wsus-cv...code-white.comCODE WHITE | A Retrospective Analysis of CVE-2025-59287 in Microsoft WSUSHow the n-day research for a suspected vulnerability in Microsoft WSUS (CVE-2025-59287) led to the surprising discovery of a new `SoapFormatter` vulnerability added by the Patch Tuesday updates of Oct... 086
codewhitesec.bsky.social @codewhitesec.bsky.social · 15/09/2025CODE WHITE proudly presents #ULMageddon which is our newest applicants challenge at apply-if-you-can.com packaged as a metal festival. Have fun 🤘 and #applyIfYouCan 067
codewhitesec.bsky.social @codewhitesec.bsky.social · 28/08/2025We always love a good challenge. That’s why we’re sponsoring the 10th FAUST CTF. Game on at 2025.faustctf.net2025.faustctf.net FAUST CTF 2025 | FAUST CTF 2025FAUST CTF 2025 is an online attack-defense CTF competition run by FAUST, the CTF team of Friedrich-Alexander University Erlangen-Nürnberg 076
codewhitesec.bsky.social @codewhitesec.bsky.social · 05/08/2025We've added a new demo to NewRemotingTricks that makes deploying a MarshalByRefObject (e.g., WebClient) even easier: System.Lazy<T> creates an instance of T on serialization, which is probably more likely to be allowed than a XAML gadget getting through. github.com/codewhitesec...github.comGitHub - codewhitesec/NewRemotingTricks: New exploitation tricks for hardened .NET Remoting serversNew exploitation tricks for hardened .NET Remoting servers - codewhitesec/NewRemotingTricks 044
codewhitesec.bsky.social @codewhitesec.bsky.social · 14/07/2025We have reproduced "ToolShell", the unauthenticated exploit chain for CVE-2025-49706 + CVE-2025-49704 used by @_l0gg (on X) to pop SharePoint at #Pwn2Own Berlin 2025, it's really just one request! Kudos to @mwulftange.bsky.social 145
codewhitesec.bsky.social @codewhitesec.bsky.social · 13/05/2025Yes, we're beating a dead horse. But that horse still runs in corporate networks - and quietly gives attackers the keys to the kingdom. We're publishing what’s long been exploitable. Time to talk about it. #DSM #Ivanti code-white.com/blog/ivanti-...code-white.comCODE WHITE | Analyzing the Attack Surface of Ivanti's DSMIvanti's Desktop & Server Management (DSM) product is an old acquaintance that we have encountered in numerous red team and internal assessments. The main purpose of the product is the centralized dis... 088
Reposted by codewhitesec.bsky.socialFlomb @fl0mb.bsky.social · 31/03/2025blog.flomb.net/posts/ingres...blog.flomb.netExploiting IngressNightmare: A Deep DiveWiz recently discovered an unauthenticated remote code execution (RCE) vulnerability in the Ingress NGINX admission controller. I found the exploit chain particularly intriguing and decided to recreat... 043
codewhitesec.bsky.social @codewhitesec.bsky.social · 28/03/2025Our crew members @mwulftange.bsky.social & @frycos.bsky.social discovered & responsibly disclosed several new RCE gadgets that bypass #Veeam 's blacklist for CVE-2024-40711 & CVE-2025-23120 + further entry points after @sinsinology.bsky.social & @chudypb.bsky.social 's blog. Replace BinaryFormatter! 096
codewhitesec.bsky.social @codewhitesec.bsky.social · 21/02/2025Ever wondered how Kurts Maultaschenfabrikle got hacked in 2023? The full story, all technical details, out now ;-) apply-if-you-can.com/walkthrough/...apply-if-you-can.comWalkthrough 2023 0710