AmberWolf Research
  • Home
  • Blog
  • Disclosure Policy
  • Main Site
to navigate to select ESC to close
  • Richard Warren Richard Warren
  • 27 Aug, 2026
    • Vulnerability
    • Disclosure
    • SonicWall
    • RCE

SonicWall GMS - Unauthenticated RCE and Encrypted Password Hash Extraction (CVE-2026-66145)

SonicWall patched our bugs. We checked. They didn’t.

Read Article
  • Richard Warren Richard Warren
  • 21 Aug, 2026
    • Vulnerability
    • Disclosure
    • Google
    • Chrome

Tag, You're Managed - Executing Code via Google's Own Signed Installer

Code execution via a Google-signed Chrome MSI.

Read Article
  • David Cash David Cash
  • 18 Aug, 2026
    • Vulnerability
    • Disclosure
    • Microsoft

NachoMDM - Weaponising Windows MDM for UAC Bypass and SYSTEM Execution via Malicious Enrollment

Summary In modern enterprise environments, Mobile Device Management (MDM) allows organisations to enforce policies, deploy software, and maintain …

Read Article
  • Darren McDonald Darren McDonald
  • 08 Aug, 2026
    • Vulnerability
    • Dell
    • TPM
    • Encryption
    • Defcon

Dell ThinOS 10.x: the worst use of a TPM possible

A SPI Flash would have at least been cheaper.

Read Article
  • Darren McDonald Darren McDonald
  • 08 Aug, 2026
    • Vulnerability
    • HP
    • TPM
    • Encryption
    • Defcon

HP ThinPro: TPM-Sealed Disk Encryption that only measured half the boot chain

Measuring only half the boot chain doesn’t help.

Read Article
  • Darren McDonald Darren McDonald
  • 08 Aug, 2026
    • Vulnerability
    • Dell
    • HP
    • IGEL
    • TPM
    • Encryption
    • Defcon

Thin Client? Thin Crypto: An overview.

Bypassing Disk Encryption on Every Major Thin Client Without Breaking a Cipher

Read Article
  • 1
  • 2
  • 3
  • 4
  • 5
  • Main Site
  • Privacy

Copyright AmberWolf 2024-2026