PurpleSec
Where offense meets defense — a living archive of real-world attack paths, Hack The Box pwns, and threat research, built to make defenders think like attackers.
PurpleSec — Cybersecurity Research & Enterprise Defense
Latest Drop
Featured Intel
Freshly published from the research desk.
Latest Post
CVE-2026-68820: Lazarus Group's Windows Zero-Day Exploitation in Operation Dream Job
A comprehensive technical analysis of CVE-2026-68820 — the Windows AFD.sys use-after-free vulnerability weaponized by North Korea's Lazarus Group to deploy the FudModule rootkit against defense and aerospace organizations worldwide.
Read full analysis →
From the blog
Recent Posts
Writeups and research notes, newest first.
Aug 17, 2026CVE-2026-68820: Lazarus Group's Windows Zero-Day Exploitation in Operation Dream JobJul 31, 2026The Great Korean AI Crash: Inside the $2 Trillion Meltdown That Shattered the KOSPIJul 23, 2026When AI Hacks AI: How OpenAI's Models Escaped Containment and Breached Hugging FaceJul 22, 2026LegacyHive: The Windows Zero-Day That Loads Another User's Registry HiveJul 11, 2026Your Passkey Is Now Theirs: How Hackers Are Hijacking Microsoft Entra Passkey Enrollment to Own Microsoft 365 AccountsJul 04, 2026JADEPUFFER: The First Fully Autonomous AI-Agent Ransomware — A Complete Technical AnalysisJul 02, 202681 Million Login Attempts in 14 Days: Inside the Massive Azure CLI Password Spray Campaign
Ethos
Words to Hack By
Let's talk security.
Building something, breaking something, or hardening something? I'm always up for a sharp conversation on offensive tradecraft, detection engineering, or where the industry is heading next.