βββββββ βββββββ βββββββ ββββββββββββββββββββ ββββββββββββββ βββ
ββββββββββββββββββββββββββββββββββββββββββββββ ββββββββββββββ βββ
βββββββββββ ββββββ βββ βββ ββββββββββββββββββββββ βββ βββ
βββββββββββ ββββββ βββ βββ ββββββββββββββββββββββ βββ βββ
βββ βββββββββββββββββββββ βββ βββββββββββ βββββββββββββββββββββββββββ
βββ βββ βββββββ βββββββ βββ βββββββββββ βββββββββββββββββββββββββββ
Welcome to RootShell
Hardcore cybersecurity deep dives & breaking security news
Pass-the-Hash Fundamentals: Theory, Tools, and Defensive Strategies
Learn the inner workings of NTLM hashes, why Pass-the-Hash works, common tooling, attack scenarios, and how to detect and mitigate PTHT in Windows environments.
DNS Tunneling 101: Fundamentals, Tools, and Threat Landscape
Learn the core concepts behind DNS tunneling, explore popular tools like Iodine, DNSCat2, and DNS2TCP, and discover real-world attack techniques and defensive controls.
AWS S3 Bucket Enumeration 101: Fundamentals & Tools
Learn how to discover, enumerate, and assess Amazon S3 buckets using built-in CLI commands and popular open-source scanners, understand region resolution, and safely list objects. This guide gives hands-on examples and defensive recommendations.
Exploiting runc (CVE-2021-3493): From Detection to Host Root Shell
A step-by-step walkthrough of identifying vulnerable runc binaries, crafting a malicious container, bypassing seccomp/AppArmor, and gaining a host root shell. Includes mitigation guidance for security teams.
Abusing HTTP/2 Stream Multiplexing for Tunneling & Exfiltration
Learn how attackers exploit HTTP/2 multiplexing to hide reverse shells, exfiltrate data, and bypass validation. The guide covers stream lifecycle, crafting parallel streams, server-push abuse, and practical lab exercises.
Mastering SSRF Exploitation with the Gopher Protocol
Learn how to craft gopher URLs, embed HTTP requests, bypass sanitizers, target internal services, chain protocols, and defend against these powerful SSRF techniques.
CISA Flags Critical Langflow, Tomcat, and N-central Flaws in KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added three high-severity vulnerabilities-IBMβ―Langflow, Apacheβ―Tomcat, and N-ableβ―N-central-to its Known Exploited Vulnerabilities (KeV) catalog. Federal agencies must remediate by Augβ―7β―2026, and the advisory warns all enterprises using these products to act immediately.
Adobe Campaign Classic Hit by Three Critical Unauthenticated RCE Flaws
Adobe disclosed three CVSSβ―10.0 vulnerabilities (CVE-2026-48331, CVE-2026-48323, CVE-2026-48330) that allow unauthenticated attackers to execute arbitrary code on Campaign Classic servers. Immediate upgrade to buildβ―9399 is mandatory for all internet-facing deployments.
Critical N-able N-central Auth Bypass (CVE-2026-18556/18577) Exploited in the Wild
In early August 2026 attackers leveraged two critical authentication-bypass flaws in N-able's N-central RMM platform to obtain full admin rights and pivot into client environments. An incomplete hot-fix left a secondary attack path open, prompting urgent remediation for all MSPs.
Critical VMware Flaws Expose Auth Bypass, Code Exec, and VM Escape
Three newly disclosed VMware vulnerabilities-CVE-2026-47876, CVE-2026-41703, and CVE-2026-41709-enable authentication bypass, host code execution, VM escape, and stealthy admin actions. Broadcomβs patches for ESXi, vSphere, Workstation, Fusion and Cloud Foundation are now available.
Critical Cisco FMC Static Credentials Flaw (CVE-2026-20316) Under Active Exploitation
Cisco Secure Firewall Management Center (FMC) contains hard-coded low-privilege credentials (CVE-2026-20316) that attackers are using to gain unauthenticated access. The vulnerability is listed in CISAβs KEV catalog, with active exploitation confirmed across multiple sectors.
Apache Syncope Flaws Enable Privilege Escalation and Remote Code Execution
Multiple CVEs in Apache Syncope (3.0.0-M0 through 4.1.1) allow low-privileged users to self-escalate to admin, perform SSRF, SQL injection, and chain to full remote code execution. Patches released in 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7.
Support RootShell
Help keep this blog growing and maintained
β€οΈ Sponsor MeSupport on GitHub Sponsors
What your sponsorship helps with:
- β‘ Server hosting and maintenance
- β‘ Publishing new security research and CVE analysis
- β‘ Building and maintaining open-source tools
- β‘ Community support and development
Thank you for supporting open-source cybersecurity! π
contact
Feel free to reach out for collaboration, security consulting, or just to say hello.
[email protected]