Technical insights from Blaze Labs
Blaze Labs is the R&D group of Blaze Information Security.

LLM pentest: Leveraging agent integration for RCE
This post describes a case study of a recent LLM pentest engagement that allowed to exploit the LLM agent for remote code execution.
All Articles

Dissecting Ragnar Locker: The Case Of EDP
Introduction On April 13th 2020, news broke out in Portuguese media [1] that Energias de Portugal (EDP), the Portuguese multinational energy giant and one of

Security advisory: Mattermost Mobile for iOS v1.31.0 Authentication Token Leakage and Account Takeover
Advisory information Title: Mattermost Mobile for iOS Authentication Token Leakage and Account Takeover Advisory reference: BLAZE-05-2020 Product: Mattermost Mobile Client for iOS v1.31.0 (Build 293)

Security advisory: Mullvad VPN client for Windows 2020.3 local privilege escalation
Advisory information Title: Mullvad VPN client for Windows 2020.3 local privilege escalation Advisory reference: BLAZE-03-2020 Product: Mullvad 2020.3 for Windows CVE reference: CVE-2020-14197 Disclosure mode:

Security advisory: i2p for Windows local privilege escalation
Advisory information Title: i2p for Windows local privilege escalation Advisory reference: BLAZE-02-2020 Product: i2p 0.7.5 to 0.9.45 for Windows CVE reference: CVE-2020-13431 Disclosure mode: Coordinated

The never ending problems of local ASLR holes in Linux
Introduction Address Space Layout Randomization, or simply ASLR, is a probabilistic security defense that was released by the PaX Team in 2001 and introduced into

Security advisory: Telegram instant messenger IDN homograph attack
Advisory information Title: Telegram instant messenger IDN homograph attacks Advisory reference: BLAZE-02-2019 (CVE-2019-10044) Product: Telegram Disclosure mode: Coordinated disclosure Product Description Telegram is a messaging
