6 Jul 2026, 11:49 UTC≈2,510 views27 reactionsread 12 August 2026 Photo
🐘 PHP PDO layer exposed! Aleksey Solovev & Nikita Sveshnikov uncovered 2 flaws: SQL Injection in pdo_firebird (CVE-2025-14179) and DoS in PDO via pdo_pgsql (CVE-2025-14180).
https://swarm.ptsecurity.com/hack-the-elephant-one-bite-at-a-time-nul-byte-sql-injection-in-pdo_firebird-and-null-pointer-dereference-in-pdo-pgsql/
👍25👎2
5 Jun 2026, 11:23 UTC≈4,340 views27 reactionsread 12 August 2026 Photo
👨🏻💻 Did you know that it’s possible to perform RCE in Internet Explorer via clickjacking? Igor Sak-Sakovsky's new article will explain how!
https://swarm.ptsecurity.com/the-click-that-shouldnt-have-worked-rce-via-clickjacking-in-internet-explorer/
👍26👎1
15 May 2026, 09:13 UTC≈5,290 views29 reactionsread 12 August 2026 Photo
🐘 PHP JPEG bugs: how image parsing leads to memory corruption.
Our researcher Nikita Sveshnikov discovered two JPEG-related memory-safety bugs in PHP’s ext/standard: CVE-2025-14177 in getimagesize and a heap buffer overflow in iptcembed.
https://swarm.ptsecurity.com/hack-the-elephant-one-bite-at-a-time-jpeg-related-memory-safety-bugs-in-php/
👍27👎2
30 Apr 2026, 09:05 UTC≈38,000 views45 reactionsread 12 August 2026 Photo
🧑🚒 Our researcher Mikhail Sukhov shares his knowledge and experience in analyzing FreeIPA environments.
He also introduces his new tool, IPAHound 💪
Go ’n see the details ➡️ https://swarm.ptsecurity.com/thinking-in-graphs-with-ipahound/
👍45
15 Apr 2026, 14:35 UTC≈6,000 views21 reactionsread 12 August 2026 Photo
🔥 Read the new article by our researcher Timofey Duditsky.
The write-up dives into the AMD Platform Configuration Blobs mechanism, shows how it works, and reveals the vulnerability CVE-2025-54502.
https://swarm.ptsecurity.com/slowburn-looking-through-amd-platform-configuration-blobs-infrastructure/
👍21
23 Mar 2026, 13:46 UTC≈6,430 views27 reactionsread 12 August 2026 Two bugs. One chain. Full RCE.
New research by Aleksandr Zhurnakov on Dell Wyse Management Suite shows how business logic flaws can be chained into complete system compromise.
Read the full writeup!
https://swarm.ptsecurity.com/business-logic-and-chains-unauthenticated-rce-in-dell-wyse-management-suite/
👍27
10 Mar 2026, 14:03 UTC≈6,300 views21 reactionsread 12 August 2026 🐘 Attack arithmetic: how an integer overflow in PostgreSQL libpq leads to denial of service.
Our researcher Aleksey Solovev discovered the vulnerability CVE-2025-12818, which may cause a product using the libpq PostgreSQL library to crash.
https://swarm.ptsecurity.com/attack-arithmetic-how-an-integer-overflow-in-postgresql-libpq-leads-to-denial-of-service/
👍20👎1
2 Mar 2026, 13:45 UTC≈6,210 views40 reactionsread 12 August 2026 Video
🚨 Our researcher Alexander Zhurnakov identified two vulnerabilities in Dell Wyse Management Suite prior to version 5.5.
In certain configurations, they can be chained to achieve unauthenticated remote code execution.
Upgrade now → https://www.dell.com/support/kbdoc/en-us/000429141/dsa-2026-103
👍40
21 Jan 2026, 11:39 UTC≈7,000 views52 reactionsread 12 August 2026 🏆 Two of our research articles are nominated for PortSwigger's Top 10 Web Hacking Techniques of 2025!
1️⃣ Impossible XXE in PHP
2️⃣ Blind trust: what is hidden behind the process of creating your PDF file?
Last day to vote if you found them useful!
https://portswigger.net/polls/top-10-web-hacking-techniques-2025
👍51👎1
19 Jan 2026, 13:04 UTC≈6,700 views56 reactionsread 12 August 2026 Video
📞 Microsoft fixed an authenticated RCE in Windows Telephony Service (CVE-2026-20931), discovered by our researcher Sergey Bliznyuk.
Read the write-up: https://swarm.ptsecurity.com/whos-on-the-line-exploiting-rce-in-windows-telephony-service/
👍55👎1
29 Dec 2025, 12:17 UTC≈9,340 views30 reactionsread 12 August 2026 📑 A new article from our researchers Aleksey Solovev, Nikita Sveshnikov and Vladimir Razov — "Blind trust: what is hidden behind the process of creating your PDF file?".
https://swarm.ptsecurity.com/blind-trust-what-is-hidden-behind-the-process-of-creating-your-pdf-file/
👍28👎2
14 Nov 2025, 14:15 UTC≈7,530 views26 reactionsread 12 August 2026 📱 New article by our researcher Artem Kulakov: Injection for an athlete.
Read about a vulnerability discovered in the Garmin Connect mobile application:
https://swarm.ptsecurity.com/injection-for-an-athlete/
👍25👎1
Showing the 12 most recent of 20 posts we hold for @ptswarm. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.