Original security research, disclosures, and practical offensive tradecraft from the GANASEC team.
A regression in Apple's IOTimeSyncFamily brought back a 2017 IOKit lifecycle race, leading to CVE-2026-28969 and a reliable macOS kernel panic.
ReadA PAC-clean kernel write primitive hiding in plain sight, and five mitigations standing between it and a full exploit.
ReadAn anonymized red-team case study showing how staging identity drift, weak SAML attribute assumptions, and environment trust boundaries can combine into organization-level compromise.
ReadMost penetration testing reports fail because they are bought for assurance but consumed by engineers. Here is how to make reports useful for auditors, leaders, and builders at the same time.
ReadA defender-focused breakdown of stack spoofing, why shallow call-stack inspection fails, and how mature teams can hunt suspicious unwind behavior without relying on brittle IOCs.
Read