XENOPS
Blog Tags
Blog Tags
XENOPS Research
Author

XENOPS Research

Research Team

Focusing on proactive security research, we aim to help organizations stay ahead of emerging threats and vulnerabilities.

One Byte Is Plenty: Reversing IceWarp CVE-2025-14500
Aug 08, 2026
XENOPS Research

One Byte Is Plenty: Reversing IceWarp CVE-2025-14500

IceWarp's X-File-Operation RCE (CVE-2025-14500) is really a missing null-byte check in the FastCGI parameter builder. One null byte in a request is enough for unauthenticated code execution as root.

  • Reverse Engineering
  • PHP
  • Penetration Testing
We’re Inviting Guests to Admin Groups Now? Broad Dynamic Membership Rules & Guest Accounts
May 16, 2026
XENOPS Research

We’re Inviting Guests to Admin Groups Now? Broad Dynamic Membership Rules & Guest Accounts

We have seen broad membership rules in multiple penetration tests and red team engagements; let's take a look at one case we encountered recently and how to (ab)use it should you come across it

  • Cloud
  • Active Directory
  • Red Team
Breaking the Cube: Under the Hood of ionCube Loader
Mar 06, 2026
XENOPS Research

Breaking the Cube: Under the Hood of ionCube Loader

Reverse engineering ionCube's Zend VM hooks and the opcode dispatch it drives.

  • Reverse Engineering
  • PHP
  • ionCube
XENOPS © 2026 XENOPS. All rights reserved. RSS Sitemap