<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Exploit Intel — exploit-development</title><link>https://exploit-intel.com/blog/tags/exploit-development/</link><description>EIP research articles tagged exploit-development.</description><language>en-us</language><atom:link href="https://exploit-intel.com/blog/tags/exploit-development/index.xml" rel="self" type="application/rss+xml"/><lastBuildDate>Sun, 17 May 2026 10:48:28 -0400</lastBuildDate><item><title>CVE-2026-41702: Forty-Seven Microseconds in /var/run/vmware/cnx-tmp</title><link>https://exploit-intel.com/blog/posts/cve-2026-41702-vmware-fusion-cnxtmp-symlink-race/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2026-41702-vmware-fusion-cnxtmp-symlink-race/</guid><description>A TOCTOU race in VMware Fusion 25's vmx-apple binary that turns booting a VM into arbitrary chown, then arbitrary chown into a passwordless root shell via PAM injection. World-writable sticky directory, SUID-root callee, bind() and chown() both following symlinks, a 5-15 microsecond window between them. Full LPE chain in 40 seconds, single VM boot. The interesting part is what made it reliable.</description><pubDate>Sun, 17 May 2026 10:31:46 -0400</pubDate></item><item><title>Hermes Agent with EIP Harness: The Vulnerability Research Assistant That Also Runs Your Pipelines</title><link>https://exploit-intel.com/blog/posts/hermes-vulnerability-research-assistant/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/hermes-vulnerability-research-assistant/</guid><description>Hermes Agent with the EIP Harness: a conversational AI vulnerability research assistant that runs full CVE pipelines while you stay in the loop. Built on Nous Research's Hermes. Showcase: a GitLab runner-token leak chained to RCE (CVE-2022-0735), a neatvnc pre-auth stack overflow (CVE-2026-42859), and a KEV-listed Everest Forms PHP Object Injection (CVE-2026-3296), all end to end. Our first public release of EIP CVE pipeline craft, plus win11-forge for Windows kernel and usermode lab orchestration.</description><pubDate>Wed, 13 May 2026 12:00:00 -0400</pubDate></item><item><title>CVE-2025-68670 Part 2: From Crash to RCE - The One That Fought Back (and Lost)</title><link>https://exploit-intel.com/blog/posts/cve-2025-68670-xrdp-from-crash-to-rce-the-one-that-fought-back/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-68670-xrdp-from-crash-to-rce-the-one-that-fought-back/</guid><description>The first post ended with 'not a shell.' This one ends with uid=0(root) - with an asterisk. Ten context windows. A UTF-8 encoding barrier that blocks every libc address. A PLT mapping that lied. A stack alignment problem solved by a NULL pointer and a filename that shouldn't exist. The story of how a pre-auth xrdp overflow became (almost) pure-network RCE - through the most absurd gadget chain we've ever built.</description><pubDate>Wed, 04 Mar 2026 22:00:00 -0400</pubDate></item><item><title>CVE-2025-68670: Pre-Auth xrdp Overflow - The One Where the Protocol Fought Back</title><link>https://exploit-intel.com/blog/posts/cve-2025-68670-xrdp-pre-auth-overflow-the-hard-one/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-68670-xrdp-pre-auth-overflow-the-hard-one/</guid><description>xrdp. Pre-authentication. A full RDP handshake implemented from scratch. UTF-8 encoding constraints that break your ROP chain. A false crash path that wasted hours. And a 3-byte partial overwrite technique that reaches any address in the binary. Stackforge's hardest target yet - and the most honest result.</description><pubDate>Wed, 04 Mar 2026 18:00:00 -0400</pubDate></item><item><title>CVE-2025-62507: Redis Stack Overflow to RCE in 68 Minutes  -  Then We Turned ASLR On</title><link>https://exploit-intel.com/blog/posts/cve-2025-62507-redis-stackforge-from-crash-to-rce-with-aslr/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-62507-redis-stackforge-from-crash-to-rce-with-aslr/</guid><description>The public material available during this CVE-2025-62507 run was a crash PoC. StackForge pursued RCE, then repeated the work with ASLR enabled.</description><pubDate>Tue, 03 Mar 2026 18:00:00 -0400</pubDate></item><item><title>CVE-2025-15467: From OpenSSL Stack Overflow to Three ROP Chains in 64 Minutes  -  Introducing Stackforge</title><link>https://exploit-intel.com/blog/posts/cve-2025-15467-openssl-stackforge-autonomous-binary-exploit/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-15467-openssl-stackforge-autonomous-binary-exploit/</guid><description>We forked Shannon again  -  this time for binary exploit development. Nine AI agents, GDB as an MCP tool, packet capture via SharkMCP, and a pipeline that turned an OpenSSL stack buffer overflow into three independent ROP chains with GDB-verified RCE. Eighty-five minutes. Twenty-five dollars. Here's how Stackforge works.</description><pubDate>Tue, 03 Mar 2026 12:00:00 -0400</pubDate></item><item><title>CVE-2025-26866: From Undocumented Binary Protocol to Root Shell - AI Agent Meets Java Deserialization</title><link>https://exploit-intel.com/blog/posts/cve-2025-26866-hugegraph-hessian-deserialization-autonomous-exploit/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cve-2025-26866-hugegraph-hessian-deserialization-autonomous-exploit/</guid><description>CVE-2025-26866 is a Hessian deserialization RCE in Apache HugeGraph PD. Our autonomous exploit pipeline CVEForge - which had completed 56 consecutive CVEs - hit a wall: an undocumented binary protocol, a non-standard serialization format, and a class blacklist blocking every known gadget chain. The agent spent $49 and four hours reverse-engineering SOFABolt, mapping sofa-hessian byte by byte, and finding a JDK-only gadget chain to bypass the blacklist. Then we took over to turn file creation into a proper root shell - navigating JNDI hardening, CC library defenses, and a gadget chain that silently dies on modern JDK. The result: a full Metasploit module.</description><pubDate>Sun, 01 Mar 2026 18:00:00 -0400</pubDate></item><item><title>72 Hours, 24 CVE Proof of Concept Exploits, and 8 Disclosure Submissions: The CVEForge Stress Test</title><link>https://exploit-intel.com/blog/posts/72-hours-24-cves-the-cveforge-stress-test/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/72-hours-24-cves-the-cveforge-stress-test/</guid><description>We left CVEForge running for three days. Twenty-four CVEs went in. All twenty-four produced working PoCs. Ten incomplete fixes triggered eight responsible disclosure submissions - six GitHub issues, one MITRE report, one HackerOne 0-day. Here's the full accounting.</description><pubDate>Sat, 28 Feb 2026 18:00:00 -0400</pubDate></item><item><title>Foreman Command Injection and Telnetd Privilege Escalation - A Dropdown, a Blacklist, and Two Very Different Fixes</title><link>https://exploit-intel.com/blog/posts/two-cves-two-outcomes-foreman-command-injection-telnetd-privilege-escalation/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/two-cves-two-outcomes-foreman-command-injection-telnetd-privilege-escalation/</guid><description>Foreman command injection via the REST API (CVE-2025-10622) and telnetd privilege escalation through environment variable injection (CVE-2026-28372) - CVEForge analyzes both end-to-end. One fix is a proper server-side whitelist. The other is a single unsetenv() call on a blacklist from 1995. Both produced working PoCs. Only one produced a fix we'd trust.</description><pubDate>Fri, 27 Feb 2026 18:00:00 -0400</pubDate></item><item><title>CVE-2025-60355 (OneBlog): CVEForge Finds 3 Bypass/Incomplete Fixes in 5 CVE Runs</title><link>https://exploit-intel.com/blog/posts/five-cves-three-bypasses-java-case-study/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/five-cves-three-bypasses-java-case-study/</guid><description>In this CVEForge patch-validation run, we analyze CVE-2025-60355 in OneBlog (Java/FreeMarker) and compare outcomes across five CVEs. Three of five runs ended in confirmed bypass or incomplete-fix results.</description><pubDate>Fri, 27 Feb 2026 12:00:00 -0400</pubDate></item><item><title>Zero to RCE: Autonomous Exploit Development Across Three Vulnerability Classes</title><link>https://exploit-intel.com/blog/posts/zero-to-rce-autonomous-exploit-development/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/zero-to-rce-autonomous-exploit-development/</guid><description>After CVEForge's first successful run, we needed to know if it was luck or a pattern. Two more CVEs, zero hand-holding, and an AI agent that found a fix bypass the developers missed.</description><pubDate>Thu, 26 Feb 2026 12:00:00 -0400</pubDate></item><item><title>CVE-2025-53833: Autonomous PoC Generation with CVEForge - From CVE Number to Root Shell in 32 Minutes</title><link>https://exploit-intel.com/blog/posts/cveforge-from-shannon-to-autonomous-poc/</link><guid isPermaLink="true">https://exploit-intel.com/blog/posts/cveforge-from-shannon-to-autonomous-poc/</guid><description>We forked Shannon - the open-source AI pentesting framework - and wired it to the EIP MCP server. Six AI agents, one CVE number, 32 minutes: a working RCE PoC for a CVSS 10.0 vulnerability with zero existing public exploits. Here's how it happened.</description><pubDate>Wed, 25 Feb 2026 12:00:00 -0400</pubDate></item></channel></rss>
