Skip to content
Articles by
Steve Velcev

Steve Velcev

WinSxS: The 6,000-binary blind spot in your EDR

Every Windows 10 and 11 machine ships with thousands of Microsoft-signed executables in “C:\Windows\WinSxS” that can be...

CVE-2026-21509 Analysis: The ghost in the document

In January 2026, Microsoft confirmed active exploitation of a high-severity zero-day, CVE-2026-21509, targeting the...

Direct Memory Access Attacks: An easy way to hack into memory, bypass logon screens and ignore device encryption

Have you ever come across a laptop, server or desktop computer that has Full Device Encryption (FDE) and protected by a...