Skip to content
Xenops logoXenops
  • About
  • Products
    Qannas

    Interested In Qannas?

    Request a demoGet Your Exposure Report
    ProductsQannasHunt leaked credentials before attackers do.
  • Services
  • Contact
Research
AboutProductsQannasServicesContactResearch
XENOPS Research
Author

XENOPS Research

Research Team

Focusing on proactive security research, we aim to help organizations stay ahead of emerging threats and vulnerabilities.

One Byte Is Plenty: Reversing IceWarp CVE-2025-14500
Aug 08, 2026
XENOPS Research

One Byte Is Plenty: Reversing IceWarp CVE-2025-14500

IceWarp's X-File-Operation RCE (CVE-2025-14500) is really a missing null-byte check in the FastCGI parameter builder. One null byte in a request is enough for unauthenticated code execution as root.

  • Reverse Engineering
  • PHP
  • Penetration Testing
We’re Inviting Guests to Admin Groups Now? Broad Dynamic Membership Rules & Guest Accounts
May 16, 2026
XENOPS Research

We’re Inviting Guests to Admin Groups Now? Broad Dynamic Membership Rules & Guest Accounts

We have seen broad membership rules in multiple penetration tests and red team engagements; let's take a look at one case we encountered recently and how to (ab)use it should you come across it

  • Cloud
  • Active Directory
  • Red Team
Breaking the Cube: Under the Hood of ionCube Loader
Mar 06, 2026
XENOPS Research

Breaking the Cube: Under the Hood of ionCube Loader

Reverse engineering ionCube's Zend VM hooks and the opcode dispatch it drives.

  • Reverse Engineering
  • PHP
  • ionCube
XENOPS logo

Offices

Command hub in Abu Dhabi.

Contact

support@xenops.ae

Links

About XENOPS
Product lineup
Service catalog
Qannas - Exposure Intelligence
Research labs

© 2026 Xenops Security Group. All rights reserved.