// Research Posts

2 posts
2026-07-05
Rogue Sandbox - When the Scan Itself is the Payload

Research on Rogue Sandbox: how an apparently benign scan flow can become browser-granted write access and reshape the threat model without an exploit or local payload.

browser-securitychromiumfile-system-accessMOTWresearchred-team
2026-06-26
Exploiting the iOS Trust Model via Configuration Profiles

An in-depth look at how Apple configuration profiles and the iOS trust model can be abused for realistic phishing and red-team scenarios without exploiting a software ...

mobileiOSred-teamPhishingMDMconfiguration-profiles