βββββββ βββββββ βββββββ ββββββββββββββββββββ ββββββββββββββ βββ
ββββββββββββββββββββββββββββββββββββββββββββββ ββββββββββββββ βββ
βββββββββββ ββββββ βββ βββ ββββββββββββββββββββββ βββ βββ
βββββββββββ ββββββ βββ βββ ββββββββββββββββββββββ βββ βββ
βββ βββββββββββββββββββββ βββ βββββββββββ βββββββββββββββββββββββββββ
βββ βββ βββββββ βββββββ βββ βββββββββββ βββββββββββββββββββββββββββ
Welcome to RootShell
Hardcore cybersecurity deep dives & breaking security news
HTTP/2 Protocol Overview & Frame Structure - Introductory Guide
Learn the fundamentals of HTTP/2, its connection preface, frame types, multiplexing, flow control, HPACK compression and how it differs from HTTP/1.1 - especially for request smuggling scenarios.
Advanced QUIC Request Smuggling & Multi-Stream Exploitation
Learn how QUICβs multiplexed streams can be abused for request smuggling, the underlying protocol quirks, practical exploitation steps, defensive controls, and hands-on labs.
JSON Injection 101: Understanding the Attack Surface
Learn how JSON data is parsed server-side, discover common injection vectors, and master detection and exploitation techniques-from simple payloads to prototype-pollution RCE. Real-world tools, defenses, and hands-on labs are included.
SharpHound Data Collection: Gathering AD Relationships - Intro Guide
Learn how to run SharpHound with default and custom collection methods, interpret its JSON output, filter noisy data, stay stealthy, and export results for BloodHound ingestion. This guide gives practical examples, mitigation tips, and hands-on exercises.
DLL Search Order Hijacking in Windows Services - PrivEsc Guide
Learn how attackers exploit Windows DLL search order and service misconfigurations to gain SYSTEM privileges. The guide covers theory, discovery, payload creation, registry hijacking, manifest redirection, evasion, and post-exploitation techniques.
Exploiting Unkeyed Header Injection for Cache Poisoning - An Intermediate Guide
Learn how unkeyed (non-vary) HTTP headers can be abused to poison browser, proxy, and CDN caches. The guide covers cache key generation, header discovery, injection techniques, crafting persistent poisoned responses, bypassing defenses, and leveraging CDN edge logic for large-scale impact.
AI-Generated Zero-Day 2FA Bypass Threatens Open-Source Sysadmin Tools
Google uncovered a zero-day 2FA bypass that appears to have been created by an AI system. The flaw targets a widely-used open-source web-based administration platform, prompting a rapid coordinated patch to avert mass exploitation.
Dirty Frag (CVE-2026-43284): Critical Linux Kernel Zero-Day Grants Root With No Patch
A kernel-level bug in the Linux cryptographic API, dubbed Dirtyβ―Frag (CVE-2026-43284), lets unauthenticated attackers gain root privileges. No vendor patch exists yet; only temporary mitigations are available, and active exploitation is imminent.
Ivanti EPMM Zero-Day (CVE-2026-6973) Exploited in Targeted Attacks - What You Need to Know
Ivanti disclosed a high-severity, authenticated input-validation flaw (CVE-2026-6973) in Endpoint Manager Mobile that is already being leveraged in targeted attacks. CISA added the vulnerability to its KEV catalog, demanding remediation by Mayβ―10 for federal agencies.
Palo Alto Networks PAN-OS Zero-Day (CVE-2026-0300) Exploited in the Wild - Critical RCE Threat
A critical buffer-overflow (CVE-2026-0300) in PAN-OS User-ID Authentication (Captive) Portal enables unauthenticated remote code execution with root privileges. State-sponsored actors have been exploiting internet-exposed PA-Series and VM-Series firewalls for almost a month, and patches are slated for Mayβ―13.
Critical MOVEit Automation Auth Bypass (CVE-2026-4670) Threatens Thousands of Deployments
Progress Software disclosed a critical authentication-bypass flaw (CVE-2026-4670) in MOVEit Automation, affecting versions prior to 2025.1.5, 2025.0.9 and 2024.1.8. Over 1,400 internet-exposed instances-incl. U.S. state and local agencies-remain unpatched, prompting urgent upgrades and mitigations.
CISA Flags Critical Linux LPE βCopy Failβ (CVE-2026-31431) as Actively Exploited
The U.S. CISA added CVE-2026-31431, known as βCopy Failβ, to its KEV catalog after confirming active exploitation. The flaw gives any local user a trivial path to root on Linux kernels from 2017 onward, affecting servers, desktops, and containers.
Support RootShell
Help keep this blog growing and maintained
β€οΈ Sponsor MeSupport on GitHub Sponsors
What your sponsorship helps with:
- β‘ Server hosting and maintenance
- β‘ Publishing new security research and CVE analysis
- β‘ Building and maintaining open-source tools
- β‘ Community support and development
Thank you for supporting open-source cybersecurity! π
contact
Feel free to reach out for collaboration, security consulting, or just to say hello.
[email protected]