Technical insights from Blaze Labs
Blaze Labs ist die Forschungs- und Entwicklungsgruppe von Blaze Information Security.

LLM pentest: Leveraging agent integration for RCE
This post describes a case study of a recent LLM pentest engagement that allowed to exploit the LLM agent for remote code execution.
Alle Artikel

Security advisory: Signal IDN homograph attack
Advisory information Title: Signal IDN homograph attacks Advisory reference: BLAZE-01-2019 (CVE-2019-9970) Product: Signal Disclosure mode: Coordinated disclosure Product Description The signal is an encrypted communications

Homographs Attack: What you see is not what you get
Introduction Since the introduction of Unicode in domain names (known as Internationalized Domain Names, or simply IDN) by ICANN over two decades ago, a series

Love letters from the red team: from e-mail to NTLM hashes with Microsoft Outlook
Introduction A few months ago Will Dormann of CERT/CC published a blog post [1] describing a technique where an adversary could abuse Microsoft Outlook

Jury.Online smart contract security audit
Introduction This blog post presents the results of a security audit of a smart contract performed by Blaze Information Security, and made public on behalf

ANNI tokens smart contract security audit
Introduction This blog post presents the results of a security audit of a smart contract performed by Blaze Information Security and made public on behalf

Leveraging web application vulnerabilities to steal NTLM hashes
Introduction NTLM authentication is the de-facto standard in corporate networks running Windows. There are a plethora of well-understood local attacks that take advantage of the
