<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>KILSERV — Security Research</title><description>CVE disclosures, offensive research, and technical write-ups by Guilherme Mury.</description><link>https://kilserv.vercel.app/</link><language>en</language><item><title>Breaking SuiteCRM&apos;s Authentication Layer: SQL Injection and LDAP Injection in the Directory Auth Flow</title><link>https://kilserv.vercel.app/research/breaking-suitecrm-authentication-layer-double-cve/</link><guid isPermaLink="true">https://kilserv.vercel.app/research/breaking-suitecrm-authentication-layer-double-cve/</guid><description>Technical walkthrough of identifying, exploiting, and responsibly disclosing a SQL Injection and LDAP Injection vulnerability in SuiteCRM (CVE-2026-33288 and CVE-2026-33289).</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>CVE</category><category>SQL Injection</category><category>LDAP Injection</category><category>Web Security</category><category>SuiteCRM</category></item><item><title>Beyond the Toolset: Advanced Red Teaming via LOTL and WMI Persistence</title><link>https://kilserv.vercel.app/research/beyond-the-toolset-lotl-wmi-persistence/</link><guid isPermaLink="true">https://kilserv.vercel.app/research/beyond-the-toolset-lotl-wmi-persistence/</guid><description>Technical walkthrough of advanced red team tradecraft leveraging Living-off-the-Land techniques and WMI-based persistence mechanisms to evade modern defensive controls.</description><pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate><category>Red Team</category><category>LOTL</category><category>WMI</category><category>Persistence</category><category>EDR Evasion</category></item><item><title>From Code Analysis to CVE: Uncovering SQL Injection in ChurchCRM (CVE-2025-67877)</title><link>https://kilserv.vercel.app/research/churchcrm-sqli-cve-2025-67877/</link><guid isPermaLink="true">https://kilserv.vercel.app/research/churchcrm-sqli-cve-2025-67877/</guid><description>Technical walkthrough of identifying, exploiting, and responsibly disclosing a SQL Injection vulnerability in ChurchCRM (CVE-2025-67877).</description><pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate><category>CVE</category><category>SQL Injection</category><category>Web Security</category><category>ChurchCRM</category></item></channel></rss>