<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cyshield Seclab</title><link>https://seclab.cyshield.com/</link><description>Recent content on Cyshield Seclab</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Cyshield.</copyright><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://seclab.cyshield.com/index.xml" rel="self" type="application/rss+xml"/><item><title>WAF Evasion 101: How Attackers Bypass “Security Gates”</title><link>https://seclab.cyshield.com/posts/waf-evasion-101-how-attackers-bypass-security-gates/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/waf-evasion-101-how-attackers-bypass-security-gates/</guid><description>Attackers reshape the same malicious payload just enough that the WAF no longer recognizes it, while the backend still executes it exactly as intended. This post walks through the real evasion playbook (encoding tricks, token splitting, noise injection, and reinforcement-learning-driven automated probing) and shows why the problem is structural, not a matter of sloppy engineering.</description></item><item><title>Why High Accuracy Can Still Mean Bad Security !</title><link>https://seclab.cyshield.com/posts/why-high-accuracy-can-still-mean-bad-security/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/why-high-accuracy-can-still-mean-bad-security/</guid><description>High accuracy in security does not guarantee real-world protection. Through the WAMM research study, this post examines what accuracy metrics hide, how false positives and false negatives manifest in production environments, and what a security-grade evaluation framework should actually measure.</description></item><item><title>Augmenting SR-BH 2020: A Technical Methodology for Modern Threat Simulation</title><link>https://seclab.cyshield.com/posts/augmenting-sr-bh-2020-a-technical-methodology-for-modern-threat-simulation/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/augmenting-sr-bh-2020-a-technical-methodology-for-modern-threat-simulation/</guid><description>A comprehensive enhancement of the SR-BH 2020 dataset for WAF training, combining LLM-assisted labeling, diverse benign traffic, and targeted attack injection to improve training data quality.</description></item><item><title>Attacks on the Radio Interface</title><link>https://seclab.cyshield.com/posts/ran-attacks/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/ran-attacks/</guid><description>Part 2 of the RAN Security series. This post explores different attack surfaces, attack vectors, and attack scenarios across the RAN, explaining categories of threats and attacker TTPs supported by attack flow illustrations.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/ran-attacks/featured.webp"/></item><item><title>Can AI Detect Web Attacks Better Than Rules?</title><link>https://seclab.cyshield.com/posts/can-ai-detect-web-attacks-better-than-rules/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/can-ai-detect-web-attacks-better-than-rules/</guid><description>The real challenge is not choosing rules or AI, but designing detection systems that can operate under uncertainty and adversarial pressure. This article examines web attack detection and WAF evasion through scientific research and real-world observations.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/can-ai-detect-web-attacks-better-than-rules/featured.webp"/></item><item><title>CyCTF 2023 Challenge: A Whitebox Walkthrough of "The Secret App v1.0"</title><link>https://seclab.cyshield.com/posts/cyctf-2023-secret-app-walkthrough/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/cyctf-2023-secret-app-walkthrough/</guid><description>A whitebox walkthrough of the CyCTF 2023 &amp;lsquo;Secret App v1.0&amp;rsquo; challenge — chaining second-order blind SQL injection, a CAPTCHA logic flaw, and insecure session handling into a full admin account takeover.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/cyctf-2023-secret-app-walkthrough/featured.webp"/></item><item><title>RAN Introduction and its Criticality</title><link>https://seclab.cyshield.com/posts/ran-introduction-and-criticality/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/ran-introduction-and-criticality/</guid><description>Part 1 of the RAN Security series. When people talk about mobile network security, the conversation almost always gravitates toward the core network. However, there is another part of the network that quietly sits in public spaces, exposed by design: the Radio Access Network (RAN).</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/ran-introduction-and-criticality/featured.webp"/></item><item><title>Remote Code Execution on SolarView Compact Firmware: A Technical Walkthrough</title><link>https://seclab.cyshield.com/posts/solarview-compact-rce-walkthrough/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/solarview-compact-rce-walkthrough/</guid><description>In this post, we demonstrate how we achieved Remote Code Execution (RCE) on a web server connected to a solar system monitoring firmware: SolarView Compact. This walkthrough covers four key stages: Firmware Extraction, Reconnaissance, Code Review, and Exploitation.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/solarview-compact-rce-walkthrough/featured.webp"/></item><item><title>SBOM Demystified: A Practical Guide to Software Supply Chain Transparency</title><link>https://seclab.cyshield.com/posts/sbom-practical-guide/</link><pubDate>Tue, 16 Jun 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/posts/sbom-practical-guide/</guid><description>Software is built like a layer cake full of libraries, packages, and hidden dependencies. But when a security crisis hits, do you really know what&amp;rsquo;s inside your code? This is where a Software Bill of Materials (SBOM) becomes essential.</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seclab.cyshield.com/posts/sbom-practical-guide/featured.webp"/></item><item><title>Multiple TP-Link Routers: Authorization Bypass in HTTP Server</title><link>https://seclab.cyshield.com/advisories/cve-2025-15517/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/advisories/cve-2025-15517/</guid><description>A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configuration operations.</description></item><item><title>Multiple TP-Link Routers: Hardcoded Configuration Encryption Key</title><link>https://seclab.cyshield.com/advisories/cve-2025-15605/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/advisories/cve-2025-15605/</guid><description>A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them, affecting the confidentiality and integrity of device configuration data.</description></item><item><title>Multiple TP-Link Routers: Post Authentication Command Injection in CLI controlBF Handler</title><link>https://seclab.cyshield.com/advisories/cve-2025-15518/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/advisories/cve-2025-15518/</guid><description>Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting the confidentiality, integrity, and availability of the device.</description></item><item><title>Multiple TP-Link Routers: Post Authentication Command Injection in CLI sendAtCmd Handler</title><link>https://seclab.cyshield.com/advisories/cve-2025-15519/</link><pubDate>Mon, 23 Mar 2026 00:00:00 +0000</pubDate><guid>https://seclab.cyshield.com/advisories/cve-2025-15519/</guid><description>Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operating system, impacting the confidentiality, integrity, and availability of the device.</description></item></channel></rss>