Independent research0-day · n-day · malware

AbraxasLabs_

analyzereversedisclose

> Independent analysis of 0-days, n-days, and malware — written for operators and the people who write the advisories.

Coveragelive
Published notes
53
Focus
Windows · identity · malware
Disclosure
Coordinated when it matters
Author
abraxas
00Latest work

Recent analysis.

The three newest published write-ups. The rest live in the archive.

Open archive→
00N-dayCVE-2026-103956CriticalPublic

CVE-2026-103956: Loom for AWS unauthenticated super-admin

Loom for AWS before 1.6.1 grants every request t-admin / g-admins-super when Cognito is unset and no external IdP is active, including requests with no Authorization header. A fresh deploy is an open admin panel. Labbed on v1.6.0 against v1.6.1. Unauthenticated GET /api/auth/me returns local-dev. Unauthenticated MCP register plus export returns the planted OAuth secret.

03 Oct 2026AWS Labs
Read analysis→
010-dayHighPublic

Vaultwarden, default X-Real-IP trusted-local bypasses login rate limits

Vaultwarden 1.37.3 defaults IP_HEADER to X-Real-IP and IP_HEADER_TRUSTED_PROXIES to local. Any non-global TCP peer is treated as a reverse proxy, so a client X-Real-IP becomes the login rate-limit key. Stock Docker published-port NAT is RFC1918. Unique headers never share a burst. 2FA after a correct password still runs. No CVE yet.

02 Oct 2026Vaultwarden
Read analysis→
020-dayHighPublic

Bitwarden, EF cipher create skips collection ACL

Bitwarden Server 2026.9.2 lite on MariaDB/Postgres/SQLite nulls the caller UserId before attaching a new org cipher to collections. A confirmed member can plant a decryptable vault item into a collection they cannot write. Members sync it as a shared login. MSSQL/Dapper keeps the caller id. No CVE yet.

02 Oct 2026Bitwarden
Read analysis→

03 of 53Showing the newest 3. 50 more published notes are in the archive.

Open archive→
01Open Source

Code next to the notes.

Repos that came out of the write-ups. Open GitHub from here if that is what you came for.

Open the tree→
00GitHubRust

Veneficus Mini

Spicy malware. Full kill-chain implant: exploit, escalate, pivot, poison, C2. Windows 10/11 x64 Rust source, released as-is and slightly broken on purpose.

0-daymalwareimplantrust
01GitHubPython

GateX

Late-90s IRC TUI that re-keys the Fortinet Hunter Nuitka gate. Static unpack, XOR unmask, Docker cage. The ELF never runs on the host.

nuitkaargon2tuipython

02 of 04Showing the newest 2. 2 more repos are in the tree.

Open the tree→
02Reading Room

The pile on the desk.

PDFs I actually reopen. Shelf notes in my voice, then the book.

Open the room→
01PDF2019No Starch Press

Rootkits and Bootkits

Alex Matrosov, Eugene Rodionov, and Sergey Bratus

The book I hand people when they ask why the kernel still believes the firmware. Boot path, UEFI, and the malware that lives underneath the OS you thought you were analyzing.

rootkitsbootkitsuefiwindows

02 of 03Showing the newest 2. 1 more shelf note is in the room.

Open the room→
03Practice

Built for people who still read the advisory.

Four lanes. Same standard: enough technical depth to be useful, without turning the site into a drop.

0-day

Unpatched issues

Fresh findings, coordinated when they need to be, written when they are ready.

N-day

Reachability after the patch

What the advisory left out — leftover packages, composition, and still-live primitives.

Malware

Reverse-engineering notes

Loaders, C2, host fitness, persistence. Behavioral tells a SOC can actually use.

Notes

Everything else

Composition, vendor logic, and the ugly leftovers that do not fit a tidy label.