XENOPS ResearchSecurity research and insights from XENOPS, aiming to help organizations stay ahead with proactive measures.https://xenops.aeen-usSat, 08 Aug 2026 00:00:00 GMTOne Byte Is Plenty: Reversing IceWarp CVE-2025-14500https://xenops.ae/blog/one-byte-is-plentyhttps://xenops.ae/blog/one-byte-is-plentyIceWarp's X-File-Operation RCE (CVE-2025-14500) is really a missing null-byte check in the FastCGI parameter builder. One null byte in a request is enough for unauthenticated code execution as root.Sat, 08 Aug 2026 00:00:00 GMTWe’re Inviting Guests to Admin Groups Now? Broad Dynamic Membership Rules & Guest Accountshttps://xenops.ae/blog/dynamic-groups-guest-accountshttps://xenops.ae/blog/dynamic-groups-guest-accounts We have seen broad membership rules in multiple penetration tests and red team engagements; let's take a look at one case we encountered recently and how to (ab)use it should you come across itSat, 16 May 2026 00:00:00 GMTBreaking the Cube: Under the Hood of ionCube Loaderhttps://xenops.ae/blog/breaking-the-cubehttps://xenops.ae/blog/breaking-the-cubeReverse engineering ionCube's Zend VM hooks and the opcode dispatch it drives.Fri, 06 Mar 2026 00:00:00 GMT