Recent Insights

Detecting the nftables Catchall Use-After-Free (CVE-2026–23111) by thinking outside the box
The thesis there was simple: you don’t catch a kernel LPE by chasing the root shell at the end of it — you catch it by recognizing the one abnormal pattern the exploit cannot avoid producing, and you do it with high confidence and near-zero false positives.


