RSSAmplifier

Blog

ZephrSec - Adventures In Information Security

ZephrSec Blog: Featuring Write-Ups, Projects & Andy Gill's Security Adventures

blog.zsec.ukRSS feed ↗15 posts

Latest posts

MQTT and Friends - Introducing BrokerLine

Using PubSub and MQTT for Azure C2

wp2shell - Code Trace Deep Dive

wp2shell carries two CVEs (so far); CVE-2026-63030 & CVE-2026-60137.

Harnessing Harnesses - Climbing the LLM Hills

Trying to coerce useful work out of LLMs without the harness is like supervising a room full of drunk toddlers, each convinced they're helping, none of them checking with each other and falling over the next.

BSides Leeds 2026 Badge - Firmware Exploration

Tearing apart the BSides Leeds 2026 badge with radare2: an 8 KB ATtiny814 owl hiding three games behind a one-byte EEPROM unlock you can flip.

(Re)Building my Homelab - Reloaded

Rebuilding my homelab with Proxmox, 10Gb networking, Homepage and dedicated research infrastructure for bug hunting, course development and FAFO.

Baselining Windows To Blend In

A look at Windows baseline behaviour through the lens of observability, telemetry, and detection engineering.

Jenny was a Friend of Mine - MCPs and Friends

Alt title: Bullying LLMs into submission to find 0days at scale

Roll Your Own... LMS

People say don't roll your own crypto but nobody ever warns you not to roll your own LMS (when you have minimal dev experience).

LTR101 - Getting into Industry in 2026

Breaking into cybersecurity in 2026: SOC roles, blue team skills, labs, certifications, and practical advice to help you land your first job.

Enabling Car Play and Android Auto for free on Audi MMI 2026

Free CarPlay and Android Auto activation on Audi MMI. Covers compatibility across Audi models, firmware decoding. No dealer visit required.

2025 - Excelling at the Edge of Burnout

A look at my year: moving back to technical work, recovering from shoulder surgery, diving into photography, and building tools, blogs and labs.

Making CloudFlare Workers Work for Red Teams

Conditional Access Payload Delivery (CAPD) Use Cloudflare Workers to for payload delivery behind custom headers.

Living off the Hypervisor - LOLPROX

Living off the land in Proxmox for red teams. Covers guest agent abuse, vsock tunnelling, disk access, and hypervisor persistence. LOLPROX

LOLPROX - Through a Defender's Eyes

Defending against LOLPROX, detect hypervisor compromise in Proxmox environments.

One Armed Hacker - Accessibility Hacking

Learning to work one-handed after shoulder surgery showed me how essential dictation, accessibility tools and AI really are day-to-day.