LSCP Responsible Disclosure Lab
New research
What's new, as it happens – research clearing disclosure, keynotes that back it, authored machines, project news. Subscribe by RSS.
- Keynote recording: WebRTC Top-10 Vulnerabilities – OWASP Columbus 2026-07-18
The keynote behind the OWASP Audio/Video Communications Top 10 project. - CVE-2026-35050 – advisory live for oobabooga/textgen 2026-07-17
A current finding, cleared through responsible disclosure; details in the GitHub security advisory. - OWASP Audio/Video Communications Top 10 – project approved, onboarding 2026-07-17
The WebRTC Top-10 research behind the project was presented at OWASP Columbus in November 2025 – the recording is public. - MakeSense – an authored machine in the Hack The Box catalog 2026-07-17
A learning machine the community trains on, built from live practice.
Archived research
Systematic white-box 0-day research and practitioner notes, run from 2020 until the full-scale invasion of Ukraine stopped the series in February 2022. Preserved as published.
How White-Box Hacking Works (0-day research series)
- InvoicePlane – a Lot of XSS and a Couple of BAC Vulnerabilities 2022
- XSS + CSRF in Arunna 2021
- Database Leakage in Mini Inventory & Sales Management System 2021
- Remote Code Execution and Stored XSS in PhotoShow 3.0 2021
- Stored XSS in ntopng 2021
- XSS in OroCRM 2021
- Scipio ERP – RCE / CSRF and Co 2021
- Authorization Bypass in Alerta 8.0.3 2020
- Authorization Bypass and RCE in Monitorr 1.7.6 2020
- "Ok, Google, I Wanna Pwn This App…" 2020
- webERP Local File Inclusion 2020
- InoERP Authentication Bypass and Remote Code Execution 2020
Lifehacks for Hackers (practitioner notes)
- Does This Scope Need AV? 2023
- What Certification Next? 2021
- The Value of "No" 2021
- The "TODAY" Reporting Model 2021
- Split XSS 2021
- Exploiting the Data Protection API 2021
- How to Monitor a Mobile Device's Filesystem Dynamically 2021
- Mobile Application Threat Analysis @ PCSD 2020
- How to Audit Mobile Apps 2020
- Family Networking Weaknesses – 0-days Guaranteed 2020
- When to Relax and When to Not 2020
- Clipboard File Transfer, Stable Script 2020
Earlier published exploits (2018–2019)
Published before the blog existed – they live in the public registries.
- CVE-2019-5485 (NVD) · HackerOne #685447
- CVE-2019-11017 (NVD) · Exploit-DB 46687
- Exploit-DB 45828
- Exploit-DB 47449
- Exploit-DB 45796
- Shellcode – Exploit-DB 46123 2019
Fresh threat intelligence, monthly: subscribe to the LSCP Newsletter or browse the archive.