// BLOG BackBox Labs

Ricerca, threat intelligence e insight di cybersecurity.

Articoli tecnici, metodologie offensive, cyber operations potenziate dall'AI e analisi di minacce emergenti.

Technical Writeup 21 settembre 2026 EN

Breaking Chrome 152: A Complete V8 Sandbox Escape and Renderer RCE

BackBox AI built a complete exploit chain against the v8CTF Chrome 152 target: an address leak, arbitrary read and write inside the V8 sandbox, a parser overflow that writes outside it, and a ROP chain that opens and reads a file on disk. Here is how each stage works, and what it says about patch lag.

Leggi
Security Advisory 20 agosto 2026 EN

Security Advisory: Stored XSS in nopCommerce via an SVG animate Handler That Slips Past the HtmlFormatter Blocklist

During a client-commissioned penetration test, BackBox AI pivoted from gray-box to white-box, fingerprinted the exact nopCommerce version, pulled the matching source, and found a stored XSS: an SVG animate onbegin handler that slips past the platform's HtmlFormatter blocklist and a fronting web application firewall. The sanitizer root cause is unfixed through the latest release (4.90.6).

Leggi
Technical Writeup 15 luglio 2026 EN

AI Malware Analysis: Reasoning Through the Glitch SPY Android RAT

We pointed BackBox AI at a live Android RAT and asked for a full analysis. It unpacked a dropper, decoded an XOR-obfuscated C2 URL straight from smali bytecode, confirmed that the C2 infrastructure was still responding by speaking the malware's own protocol, and attributed the operation. This is what evidence-driven analytical reasoning looks like when it reaches past red teaming.

Leggi
Penetration Testing 19 luglio 2025 IT

Threat Led Penetration Testing: rafforzare la resilienza cyber

Come BackBox Labs applica una metodologia di Threat Led Penetration Testing (TLPT) adversary-driven che unisce threat intelligence, attack surface discovery potenziata dall'AI e competenza umana per misurare la reale resilienza operativa.

Leggi