Articles
OpenSSL CVE-2026-75806: One-Datagram DTLS 1.2 Association Teardown
A single unauthenticated UDP datagram destroys an established OpenSSL DTLS 1.2 AEAD association instead of being silently discarded per RFC 6347. Discovered from a two-year-old TLS conformance bug report; root cause, reproducer, impact and fix, reported and fixed by Mounir IDRASSI.
FEILIAN: Hash Specification and Implementation Review
Version 1.0.2: hardware length-binding findings, conflicting definitions and a complete SubColumn linear-structure classification. Published report, reproduction code and recorded verification.
Octarine: Independent Signature Security Review
Message-hash security bounds, polynomial solutions of relaxed SIS estimates, and a challenge-expansion mismatch. Includes the v1.0.1 report and reproducible evidence, with a 48-bit signature-transfer model and explicit limits on attacks against the submitted parameters.
CHAMP: Independent Hash Security Review
Twelve reduced-parameter collisions, failures of naive keyed constructions, and specification and implementation findings. Includes the technical report, reproducible evidence and GitHub repository, with clear limits on full-size attack projections.
Fancy Entropy, Missing Caller: Anti-Analysis Collector Review
An evidence-led reading of a public Windows anti-analysis collector: what its XOR fold visibly does, which caller-side mechanisms remain unproven, and how to investigate the missing consumer.
usbliter8: Apple SecureROM BootROM USB DMA Exploit Analysis
A USB-controller DMA buffer underflow in Apple SecureROM is permanently unpatchable and extends the checkm8 family of boot-chain compromise to A12, A13 and S4/S5-class devices.
RoguePlanet: Windows Defender LPE Exploit Analysis
A TOCTOU race condition in Windows Defender threat remediation yielding Standard → SYSTEM privilege escalation. Analysis of the 7th exploit by Nightmare-Eclipse, released shortly after Microsoft's June 2026 Patch Tuesday.