The CCleaner affair: the 2017 supply chain attack explained
How a signed CCleaner update installed a backdoor on 2.27 million PCs in 2017. Timeline, technique, attribution and lessons of the supply chain attack.
How a signed CCleaner update installed a backdoor on 2.27 million PCs in 2017. Timeline, technique, attribution and lessons of the supply chain attack.
The complete history of Kali Linux: Whoppix in 2004, WHAX, Auditor, BackTrack, the 2013 Debian rebuild, Kali Purple and local AI. 20 years of pentesting.
The ANTS hack (11.7 million accounts), an IDOR flaw, 284 days to detect intrusions, cyber budgets at 1%: why the French State fails at cybersecurity in 2026.
Claude Mythos, Anthropic's AI kept under lock: 10 trillion parameters, a 27-year-old OpenBSD flaw, 77.8% on SWE-bench Pro and the end of junior hires.
OpenClaw reads your emails and runs code on your machine. ClawHavoc malicious skills, the ClawJacked attack, prompt injection: risks and hardening guide.
The YGG hack of March 2026: an open Sphinx port, 6.6 million accounts exfiltrated, 36 front websites and laundering through Tornado Cash. Autopsy and lessons.
The Friend pendant listens all the time to 'fight loneliness'. Always-on microphone, data processed by Claude and Gemini, acoustic injection, legal risks.
Legal status, cyber liability insurance, bootstrapping, JEI and R&D tax credits, building the offer and sales: the guide to starting a cybersecurity company.
The Amesys affair: the 2007 contract with Libya, the Eagle system and Deep Packet Inspection, Nexa Technologies, Egypt and the complicity in torture case.
Is Temu dangerous? 29 permissions, Pinduoduo malware exploiting an Android zero-day, the Swiss NTC report, dark patterns: a complete security analysis.
Discover the story of the Intel Management Engine, a hidden chip in Intel processors since 2008, capable of operating independently of the operating system.
Kali Linux is probably the most widely used operating system in the offensive security world... but wrongly so! In fact, there are much better alternatives!
How to avoid fines related to GDPR? The most effective solution is to conduct penetration tests. A complete guide is available in the article below.
How to choose the right tools for an intrusion test? Read more in the article below
What is the budget for an intrusion test?r
XZ Utils has a significant backdoor in its latest versions 5.6.0 and 5.6.1. However, its exploitation is not trivial.
WordPress, as one of the most widely used content management systems (CMS) in the world, powers a significant portion of websites, ranging from personal blogs to corporate sites.
A new class of speculative execution vulnerabilities, named GhostRace, has been discovered in March 2024. This attack is particularly dangerous as it can be used to exploit a wide array of software, including web browsers, operating systems, and critical applications.
Canon, a 20 billion euro multinational corporation, is impacted by 2 critical vulnerabilities that, under certain conditions, can compromise the infrastructure hosting the vulnerable application. Trackflaw shares its discovery and responsible disclosure process.
This article details how a simple vulnerability discovered in late January 2024 could allow an attacker to compromise Jenkins instances.
This article details and explains to the reader the different approaches to a penetration test and how to make the right choice.
This article details how GitLab is vulnerable to the CVE-2023-7028 flaw and why it should not be publicly exposed.
Dive into the world of penetration testing with Trackflaw. Find out how to choose the right provider in 2024 with our expert advice. We highlight the importance of criteria such as experience, skills, certifications and methodology. Trackflaw stands out for its expertise, rigorous approach and strict confidentiality policy. Take advantage of our quality services and competitive rates to secure your IT system. Choose reliability and efficiency with Trackflaw.
OwnCloud is an open-source software providing a platform for online file storage, sharing services, and various applications. It is presented as an alternative to Dropbox, which is based on a public cloud. However, like all software, it suffers from vulnerabilities.
Dive into the depths of 'reverse tab nabbing,' an incredibly effective phishing technique. Discover how hackers cleverly exploit your browser tabs to redirect you to malicious sites while making you believe you are safely browsing familiar sites. Through a realistic scenario, we show you step-by-step how this attack unfolds and highlight the exploitable vulnerabilities. Learn essential measures to protect yourself, such as avoiding the use of the target=_blank attribute or incorporating rel=noopener noreferrer. This article is a must-read for strengthening your cybersecurity and thwarting modern phishing traps.
In the article 'Cisco CVE-2023-20198 - Creating a Botnet Network,' published on October 20, 2023, Trackflaw explores a critical privilege escalation flaw in Cisco IOS-XE. Rated 10 on the CVSS scale, this vulnerability allows an unauthenticated attacker to create an account with the highest privileges. Trackflaw details the exploitation steps, from creating an administrator account to installing an implant, restarting the service, and clearing traces. The author also discusses how to locate vulnerable hosts and the protective measures recommended by Cisco in the absence of a patch. The article includes reliable references and an animation summarizing the exploitation.
Discover how to bypass file upload mechanisms by exploiting a file upload vulnerability. I guide you through the sophisticated techniques used to upload a malicious file to a target system, illustrated with the example of the l33t-hoster challenge from the Insomni'hack Teaser 2019 CTF. Learn how to create a polyglot file and bypass anti-PHP protection, while understanding the necessary security measures to counter such attacks. An essential article for cybersecurity enthusiasts looking to deepen their knowledge of file upload security.
Dive into the depths of 'reverse tab nabbing,' an incredibly effective phishing technique. Discover how hackers cleverly exploit your browser tabs to redirect you to malicious sites while making you believe you are safely browsing familiar sites. Through a realistic scenario, we show you step-by-step how this attack unfolds and highlight the exploitable vulnerabilities. Learn essential measures to protect yourself, such as avoiding the use of the target=_blank attribute or incorporating rel=noopener noreferrer. This article is a must-read for strengthening your cybersecurity and thwarting modern phishing traps.