AmberWolf Research
  • Home
  • Blog
  • Disclosure Policy
  • Main Site
to navigate to select ESC to close
  • Darren McDonald Darren McDonald
  • 10 Jul, 2026
    • Vulnerability
    • Dell
    • BIOS
    • UEFI

Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)

A password cipher that leaks it’s own key.

Read Article
  • Adam Boylan Adam Boylan
  • David Cash David Cash
  • 23 Jun, 2026
    • Disclosure
    • Vulnerability
    • Bypass

Microsoft Graph API - Hidden Exclusions with Overly Scoped Permissions

Hidden exclusions in Entra ID Conditional Access policies let attackers bypass MFA and use an overly scoped Graph token to enumerate tenant data.

Read Article
  • Richard Warren Richard Warren
  • 09 Apr, 2026
    • Vulnerability
    • Disclosure
    • Zscaler
    • ZTNA

Next, Next, SYSTEM: Exploiting NSIS installer bugs to escalate privileges in Zscaler Client Connector

Exploiting NSIS installer bugs to escalate privileges in Zscaler Client Connector

Read Article
  • Richard Warren Richard Warren
  • 24 Mar, 2026
    • Vulnerability
    • Bypass
    • Netskope

Patch Bypass: Netskope Client for Windows - Local Privilege Escalation via Rogue Server

A bypass of the CVE-2025-0309 fix allowed enrolment to a rogue server via unauthenticated Netskope reverse-proxy routes.

Read Article
  • David Cash David Cash
  • Richard Warren Richard Warren
  • 27 Feb, 2026
    • Vulnerability
    • Disclosure
    • Delinea

Delinea Protocol Handler - Return of the MSI: RCE via Custom Launcher

Summary Ok, so there’s no MSI this time but our last Delinea post was titled ‘MSI Strikes Back’ so we thought we’d stay on …

Read Article
  • David Cash David Cash
  • Richard Warren Richard Warren
  • 21 Jan, 2026
    • Vulnerability
    • Disclosure

Advisory - Check Point Harmony Local Privilege Escalation (CVE-2025-9142)

Check Point Harmony Local Privilege Escalation (CVE-2025-9142)

Read Article
  • Iain Smart Iain Smart
  • 01 Sep, 2025
    • Kubernetes

Breaking Boundaries - Kubernetes Namespaces and multi-tenancy

Footguns and privilege escalations making multi-tenancy difficult in Kubernetes clusters.

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 29 Aug, 2025
    • Vulnerability
    • ZTNA
    • DEFCON
    • Netskope

Advisory - Netskope Client for Windows - Local Privilege Escalation via Rogue Server (CVE-2025-0309)

Never Trust, Always Verify - except when you have to trust the server isn’t malicious .. and install this CA certificate and MSI while …

Read Article
  • David Cash David Cash
  • 20 Aug, 2025
    • PAM
    • Vulnerability
    • Disclosure
    • Delinea

Delinea Protocol Handler - MSI Strikes Back

Introduction Delinea’s custom URL handler allows the software’s update process to be triggered, downloading and running an MSI from an …

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 15 Aug, 2025
    • Vulnerability
    • ZTNA
    • DEFCON
    • Netskope

Advisory - Netskope Cross-tenant Authentication Bypass

Advisory - Netskope Cross-tenant Authentication Bypass

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 09 Aug, 2025
    • Vulnerability
    • Zscaler
    • ZTNA
    • DEFCON

Advisory - Zscaler SAML Authentication Bypass (CVE-2025-54982)

Advisory - Zscaler SAML Authentication Bypass (CVE-2025-549820)

Read Article
  • Gavin Holt Gavin Holt
  • 09 Aug, 2025
    • Vulnerability
    • NachoVPN
    • ZTNA
    • DEFCON

Breaking Into Your Network? Zer0 Effort. - DEF CON 33 Overview

Uncovering critical flaws in ZTNA solutions, allowing attackers to escalate privileges on end user devices and to completely bypass authentication, …

Read Article
  • Richard Warren Richard Warren
  • 04 Aug, 2025
    • Vulnerability
    • NachoVPN
    • GlobalProtect
    • Palo Alto

NachoVPN: Now With More VPN (And SYSTEM Shells) - Part 2 - Palo Alto GlobalProtect

Thought CVE-2024-5921 was fixed? Nacho problem! NachoVPN brings downgrade attacks to GlobalProtect.

Read Article
  • Richard Warren Richard Warren
  • 29 Jul, 2025
    • Vulnerability
    • NachoVPN
    • Ivanti

NachoVPN: Now With More VPN (And SYSTEM Shells) - Part 1 - Ivanti Connect Secure

What’s better than logon scripts? SYSTEM shells. NachoVPN now abuses Ivanti remediation logic to load rogue DLLs over SMB and hijack Wow64 …

Read Article
  • Darren McDonald Darren McDonald
  • 04 Jun, 2025
    • Vulnerability
    • Dell
    • ThinOS

ThinOS - Unencrypted Memory Dumps (CVE-2025-32752)

Full disk encryption that wasn’t.

Read Article
  • Iain Smart Iain Smart
  • 17 Jan, 2025
    • Vulnerability
    • Kubernetes

Reproducing CVE-2024-9042: Command Injection in Windows Kubernetes Nodes

Recreating a vulnerability in log streaming via the Kubelet on Windows nodes

Read Article
  • David Cash David Cash
  • Richard Warren Richard Warren
  • 26 Dec, 2024
    • Vulnerability
    • Disclosure
    • PAM

Delinea Protocol Handler - Remote Code Execution via Update Process (CVE-2024-12908)

The Delinea Protocol Handler suffers from a Remote Code Execution vulnerability in the sslauncher URL handler. This could be exploited by a malicious …

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 26 Nov, 2024
    • Vulnerability
    • Disclosure

Introducing NachoVPN: One VPN Server to Pwn Them All

Is Your Corporate VPN Client Providing Access to More Than Just Your Employees?

Read Article
  • David Cash David Cash
  • Richard Warren Richard Warren
  • 26 Nov, 2024
    • Vulnerability Disclosure
    • Palo Alto
    • NachoVPN
    • GlobalProtect
    • VPN

Palo Alto GlobalProtect - RCE and Privilege Escalation via Malicious VPN Server (CVE-2024-5921)

Palo Alto GlobalProtect - RCE and Privilege Escalation via Malicious VPN Server (CVE-2024-5921)

Read Article
  • David Cash David Cash
  • Richard Warren Richard Warren
  • 26 Nov, 2024
    • Vulnerability Disclosure

SonicWall NetExtender for Windows - RCE as SYSTEM via EPC Client Update (CVE-2024-29014)

SonicWall NetExtender for Windows - RCE as SYSTEM via EPC Client Update (CVE-2024-29014)

Read Article
  • Richard Warren Richard Warren
  • 08 Oct, 2024
    • Vulnerability
    • Disclosure

Ivanti Connect Secure - Authenticated RCE via OpenSSL CRLF Injection (CVE-2024-37404)

Today, we are releasing the details of CVE-2024-37404, a zero-day vulnerability in the Ivanti Connect Secure product. This vulnerability allows an …

Read Article
  • David Cash David Cash
  • Richard Warren Richard Warren
  • 17 Sep, 2024
    • Vulnerability
    • Disclosure

Skeleton Cookie: Breaking into Safeguard with CVE-2024-45488

Join us as we reveal how CVE-2024-45488 can let attackers gain access to your corporate password vault and uncover hidden secrets of Microsoft DPAPI.

Read Article
  • David Cash David Cash
  • Richard Warren Richard Warren
  • 04 Sep, 2024
    • Vulnerability
    • Disclosure

One Identity SafeGuard for Privileged Passwords - Authentication Bypass (CVE-2024-45488)

SafeGuard for Privileged Passwords (SPP) virtual appliance images contain a hard-coded cryptographic key (CWE-321). An attacker can exploit this key …

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 31 Jul, 2024
    • Cato
    • VPN
    • Vulnerability Disclosure

AmberWolf Uncovers Critical Vulnerabilities in Cato Client

As part of a recent client engagement, we conducted a product assessment of the Cato Client. During this assessment, we discovered significant …

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 31 Jul, 2024
    • Cato
    • VPN
    • Vulnerability Disclosure

Cato Client - Account Takeover Via Sensitive Log Data (CVE-2024-6977)

The Cato Client was found to store authentication data within the trace logs generated by the desktop client during SSO authentication.

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 31 Jul, 2024
    • Cato
    • VPN
    • Vulnerability
    • Disclosure

Cato Client - Local Privilege Escalation via OpenSSL Configuration File (CVE-2024-6975)

The OpenSSL implementation in the winvpnclient.cli.exe service executable is configured to load an openssl.cnf file from a location that does not …

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 31 Jul, 2024
    • Cato
    • VPN
    • Vulnerability
    • Disclosure

Cato Client - Local Privilege Escalation via Self-Upgrade (CVE-2024-6974)

The Cato Client was found to use an insecure temporary folder for downloading and processing updates.

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 31 Jul, 2024
    • Cato
    • VPN
    • Vulnerability Disclosure

Cato SSO - Open Redirect Leading to Config Theft

The web service used during the Cato SSO authentication flow was found to contain an Open Redirect issue, which could allow a remote attacker to …

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 31 Jul, 2024
    • Cato
    • VPN
    • Vulnerability Disclosure

Remote Code Execution via Crafted URLs (CVE-2024-6973)

The Cato Client suffers from a Remote Code Execution vulnerability which could be triggered via a URL handler, or via requests to the local webserver.

Read Article
  • Richard Warren Richard Warren
  • David Cash David Cash
  • 31 Jul, 2024
    • Cato
    • VPN
    • Vulnerability
    • Disclosure

Cato Client - Local Root Certificate Install as Low Privileged User (CVE-2024-6978)

The Cato Client allows a low-privileged, local user to install arbitrary Root CA Certificates in the computer’s certificate store.

Read Article
  • Main Site
  • Privacy

Copyright AmberWolf 2024-2026