RCE in Strix Agent: A practical guide to prompt injections with impact
How we discovered an RCE in the AI Pentester Strix (sandbox) and how to find prompt injections with impact.
We dedicate extensive time to research through activities such as zero-day vulnerability research and tool development. Our research collection is built upon the accomplishments of our dedicated Baldur team members careers. This is done to stay ahead of the industry and keep our customers secure.
Baldur is devoted to responsible disclosure, to ensure the vulnerabilities are patched and customers are protected. Read our responsible disclosure policy here
How we discovered an RCE in the AI Pentester Strix (sandbox) and how to find prompt injections with impact.
Fortinet EMS Remote Code Execution. How one tiny img tag was all we needed to escalate our access to a full remote code execution.
Vibecoding is fast, but is it secure? We tested today's leading LLMs on a common security task: the MFA in your login flow.
How to achieve a working remote code execution exploit in an embedded phone without any previous access.
Showcasing why automated scanners might miss some very obvious bugs and how to deal with that.
Danish National Cybercrime Center held their annual hacking competition. We participated and solved some challenges
How to turn an RCE vulnerability into a working Metasploit module that spawns any payload, using CVE-2023-32781 as the example.
How we could exploit a vulnerability in WithSecure Elements EDR to shut down a company network through malicious isolation.
This post details the process of exploiting CVE-2023-32782 in PRTG to gain remote code execution.
Improper authentication in the FortiPAM privileged-access Chrome extension lets a malicious website hijack the browser proxy and record open tabs.
Authenticated remote code execution vulnerability in Umbraco CMS
Spoofing vulnerability in Google Chrome Media Component affecting all Chromium-based browsers
Unauthenticated remote code execution as root in Mitel 6800/6900-series IP phones (advisory 24-0006).
Authentication bypass in Mitel 6800/6900-series IP phones (advisory 24-0007).
One of the chained vulnerabilities behind unauthenticated RCE in Mitel IP phones (advisory 24-0008).
Part of the Mitel IP phone vulnerability chain disclosed by Baldur (advisory 24-0009).
Mitel IP phone security issue from Baldur's disclosure chain (advisory 24-0010).
CSRF allowing the leakage of cleartext windows credentials over the network.
Utilize regex feature for leaking sensitive configuration files
Path traversal vulnerability was discovered in the HL7 sensor of PRTG
Authentication bypass via weak tokens and salts in Nagios.
Unauthenticated memory corruption in the WithSecure fsicapd ICAP component.
Unauthenticated arbitrary filewrite as SYSTEM
Multiple Cross-Site (XSS) Scripting vulnerabilities
Unauthenticated memory-corruption DoS in the F-Secure Policy Manager fsicapd component.
XSS which leads to a leaked private key, allowing wallet control
Global CSRF bypass due to RFC incompliance in HTTP header
Heap Based buffer overflow leads to Remote Code Execution
Remote Code Execution in F-secure Server Security
Fortinet IPC permission leads to local privilege escalation as SYSTEM