<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>ALittleInsecure</title><description>An Offensive Security Blog</description><link>https://alittleinsecure.com/</link><item><title>Raiding Unraid: XSS to Hypervisor Takeover</title><link>https://alittleinsecure.com/raiding-unraid/</link><guid isPermaLink="true">https://alittleinsecure.com/raiding-unraid/</guid><description>Chaining a stored cross-site scripting vulnerability in the Unraid web GUI into full hypervisor host takeover.</description><pubDate>Thu, 18 Sep 2025 00:01:13 GMT</pubDate></item><item><title>Files that Coerce: Search Connectors and Beyond</title><link>https://alittleinsecure.com/files-that-coerce-search-connectors-and-beyond/</link><guid isPermaLink="true">https://alittleinsecure.com/files-that-coerce-search-connectors-and-beyond/</guid><description>Abusing Windows file formats like search connectors and library files to coerce forced authentication and relay it across Active Directory.</description><pubDate>Wed, 06 Nov 2024 22:15:13 GMT</pubDate></item><item><title>DNS Hijacking: Say My Name</title><link>https://alittleinsecure.com/dns-hijacking-say-my-name/</link><guid isPermaLink="true">https://alittleinsecure.com/dns-hijacking-say-my-name/</guid><description>Techniques for taking over and manipulating Windows DNS records without credentials to coerce and relay NTLM and Kerberos authentication.</description><pubDate>Sat, 17 Feb 2024 15:21:29 GMT</pubDate></item></channel></rss>