The Patch Priority Calculus Is Changing: What Security Leaders Must Prepare For
The New Reality of Enterprise Patch Prioritization I have been in enough patch review meetings to know the rhythm by heart: Patch Tuesday drops, the team…
Original discoveries. Exploit development. Shellcode engineering. Patch intelligence.
This archive documents vulnerabilities I have identified, responsibly disclosed and independently analysed—alongside public exploit development, shellcode engineering, payload research and Windows patch intelligence.
The objective is not simply to list CVEs. It is to preserve the full technical record: what failed, how exploitation primitives were built, how payloads work internally, what changed in the patch, and what defenders can learn from the evidence.
More than 10 zero-day discoveries, public CVE research, responsible vendor disclosure and technical work referenced across industry and security-training ecosystems.
Zero-day discoveries
Original vulnerabilities identified through hands-on product and attack-surface research.
Public research record
Technical references across NVD, Exploit-DB, Rapid7 and vendor advisories.
Shellcode and payload research
Assembly-level payload analysis, custom encoding, crypters, polymorphism and exploit-development education.
Patch intelligence
Binary comparison, root-cause reasoning, reachability analysis and defensive guidance.
A disciplined workflow that connects technical evidence to real exploitability and defensive action.
Map attack surfaces, identify trust boundaries, inspect parsers and protocol handlers, and isolate unsafe code paths or behavioural inconsistencies.
Reproduce the condition safely, establish reachability, identify prerequisites, assess impact, and separate theoretical weakness from demonstrable risk.
Document root cause, affected versions, patch behaviour, detection opportunities and practical remediation without publishing unnecessary weaponisation detail.
Representative work spanning remote code execution, local exploitation, browser security and operating-system patch research.
Remote SEH buffer overflow
A remotely reachable memory-corruption vulnerability affecting the embedded web-server component across multiple enterprise file-management products. The research demonstrated arbitrary-code-execution potential through a crafted HTTP request.
The vulnerability later became a teaching case within offensive-security training, extending its impact beyond the original disclosure.
Opera DLL search-order hijacking
A search-order weakness allowed a malicious DLL placed beside extracted HTML content to be loaded when the browser opened the page. The issue was responsibly disclosed and subsequently corrected by the vendor.
AIDA64 local SEH buffer overflow
A local memory-corruption vulnerability in AIDA64 Engineer 6.00.5100 involving unsafe processing of attacker-controlled input. The research documents the crash condition, SEH overwrite and code-execution implications.
From diff to defense in tcpip.sys
A Windows TCP/IP patch-analysis investigation focused on ESP outbound initialisation. Binary comparison exposed a security-relevant shift from raw pointers to safer offsets, providing evidence of a TOCTOU hardening change in kernel code.
The public research record extends beyond CVEs into exploit construction, payload internals, assembly-level reasoning and evasion-aware shellcode design.
The Art of Shellcoding is a restored nine-part Linux x86 research series spanning bind and reverse shell construction, payload-size optimisation, egghunting, custom encoding, Metasploit payload internals, polymorphism and AES-based encryption. Selected articles include:
Assembly-level analysis explained how established Metasploit payloads operate rather than treating generated shellcode as a black box.
Exploit and shellcode work has been published, mirrored or referenced through established offensive-security archives and technical publishing platforms.
Long-form technical writing across penetration testing, exploit development, wireless forensics, mobile forensics and web-application security.
These articles connected attack techniques with evidence reconstruction, packet analysis and defensible forensic methodology.
This editorial work predates and complements the book portfolio, showing a sustained history of translating hands-on offensive-security research into material for practitioners and learners.
Responsible disclosures and technical write-ups covering vulnerabilities discovered through independent research.
The New Reality of Enterprise Patch Prioritization I have been in enough patch review meetings to know the rhythm by heart: Patch Tuesday drops, the team…
A significant security vulnerability CVE-2020-19513 has been identified in version 6.00.5100 of FinalWire Ltd’s AIDA64 Engineer software. This vulnerability, classified as a buffer overflow issue, presents a serious risk, allowing ...
The CVE-2017-13708 is a critical buffer overflow vulnerability has been identified in the web server service component of VX Search Enterprise version 10.0.14. This particular security flaw poses a significant ...
The CVE-2017-13696 is a buffer overflow vulnerability has been identified in the web server component of several software applications: Dup Scout Enterprise version 9.9.14, Disk Savvy Enterprise version 9.9.14, Sync ...
The CVE-2018-18913 states that Before version 57.0.3098.106, the Opera web browser had a security problem called DLL Search Order Hijacking. This issue happens when an attacker creates a ZIP file ...
Patch-diff research that examines changed code, probable root cause, reachability, exploitability and defensive significance.
The New Reality of Enterprise Patch Prioritization I have been in enough patch review meetings to know the rhythm by heart: Patch Tuesday drops, the team…
CVE-2025-54093: Windows TCP/IP hardens ESP outbound init, replacing raw pointers with safe offsets to eliminate a TOCTOU race in kernel.
Authoritative public records and third-party repositories containing vulnerability, exploit and acknowledgement references.
Responsible-disclosure and security-research contributions have been acknowledged by organisations including Apple, AT&T, Facebook, Microsoft, BlackBerry, Rapid7 and Offensive Security.
Vendors are given a reasonable opportunity to investigate and remediate before sensitive technical details are published.
Claims are grounded in reproducible behaviour, patch evidence, code-level observations or authoritative public records.
Public content prioritises root cause, detection, remediation and learning while avoiding unnecessary operational weaponisation.
Available for selected research conversations, conference sessions, media commentary and community collaboration.