Skip to main content

Research Blog

Vulnerability analysis, proof of concepts, and code reviews

Five CVEs in Tryton ERP: Stored XSS, Broken Access Controls, and Server Info Leaks

Five CVEs disclosed in Tryton ERP through responsible disclosure -- stored XSS that escalates to unauthenticated via email, access control bypasses on data exports, and stack traces handed to any logged-in user. All patched, all basic, all in production for years.

xsserptrytoncve-2025-66420cve-2025-66421cve-2025-66422access-control

Trust Wallet's $7M Christmas Gift to Hackers: A Supply Chain Masterclass

Trust Wallet's browser extension got backdoored via supply chain attack on Christmas Eve. Attackers pushed malicious code to production that drained $7M in user funds. Binance-owned wallet, developer negligence, APT-level execution.

supply-chaintrust-walletaptcryptocurrencybrowser-extension