<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vulnerability-Research on grit8086</title><link>https://grit8086.github.io/tags/vulnerability-research/</link><description>Recent content in Vulnerability-Research on grit8086</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 05 Dec 2025 00:00:00 +0800</lastBuildDate><atom:link href="https://grit8086.github.io/tags/vulnerability-research/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-10767</title><link>https://grit8086.github.io/posts/cve-2025-10767/</link><pubDate>Fri, 05 Dec 2025 00:00:00 +0800</pubDate><guid>https://grit8086.github.io/posts/cve-2025-10767/</guid><description>&lt;h1 id="whats-up"&gt;What&amp;rsquo;s up?&lt;/h1&gt;
&lt;p&gt;Lately I’ve been digging into vulnerability research - reading writeups and watching videos about adversarial toolkits that turned out to be vulnerable themselves. Shout-out to my friend Chebuya for the insights on this topic.&lt;/p&gt;
&lt;h1 id="what-made-me-delve-into-this-topic"&gt;What made me delve into this topic?&lt;/h1&gt;
&lt;p&gt;Most vulnerability researchers, hackers, and threat actors look for bugs in enterprise software, apps, and the like. But what if we look for vulnerabilities in the tools researchers use? IDA, BloodHound, Havoc, Sliver, Cobalt Strike - it’s ironic, but these tools can also contain exploitable mistakes.&lt;/p&gt;</description></item></channel></rss>