HP One Agent: local privilege escalation through race condition [CVE-2026-5064]

One type of assessment we perform a lot, especially last year with Windows 10 coming to the end of its life, is what we call a workstation assessment. The goal is to identify weaknesses and vulnerabilities within a standard image or build and determine whether they can be exploited from various standpoints.

During such an assessment last year, when vulnerability research wasn’t yet fully performed by Claude, I was faced with an image which had a limited attack surface and very few additional software. One of them was HP One Agent, which I had never heard of at the time, but eventually allowed me to elevate privileges on the workstation due to a race condition and DLL side loading. Interestingly, this could have tied in quite nicely with my colleague Leon‘s research surrounding bloatware which he presented at Defcon last year.

Continue reading HP One Agent: local privilege escalation through race condition [CVE-2026-5064]

From a Regular Red Team Exercise to Developing a Custom C2 Channel over MS Teams

It’s early June 2025, we are preparing our C2 infrastructure and payload for an upcoming red team engagement. We know the client, we also know some aspects of their infrastructure because we do a lot of regular pentests for them throughout the year. We don’t need to worry about the social engineering part because it was agreed to do the tests in an “assume breach” scenario and we’ll thus have a contact on site who will download, open or execute whatever we ask them to. So, the objective is simple, we have approximately 2 months to get an initial foothold on the network and do some post-exploitation.

We can’t say that we felt highly confident, but we had a comfortable margin for error, and we knew that we could go back to the drawing board in case something did not work as intended. Little did we know that we had greatly underestimated the difficulty of the task, and that a key part of their infrastructure would end up completely ruining our plans. We were not quite prepared for what lied ahead of us.

Continue reading From a Regular Red Team Exercise to Developing a Custom C2 Channel over MS Teams

Insomni’Hack 2026 – Golden Payout writeup

The challenge

A massive data breach has just hit our corporate network. Highly sensitive documents have been spotted on a prominent Darknet leaking platform. Preliminary network telemetry has flagged suspicious outbound traffic originating from a specific workstation belonging to one of our DBAs. As part of the Rapid Response Investigation Team, you have been assigned to perform a deep-dive forensic analysis of the suspect’s workstation.

Continue reading Insomni’Hack 2026 – Golden Payout writeup