CVE-2026-50321. How a normal WinUSB feature exposed a pipe-lifetime raceRead the analysis
Delphos LabsDelphos Labs
Use CasesBlogAbout UsSign InRequest Access
Use CasesBlogAbout UsSign InRequest Access

Delphos Labs Blog

Featured
Sep 10, 2026

Delphos outscores commercial decompilers on DecBench

Delphos Lantern takes first place on the overall metric and first place on elusive types metric

Tiago Pinho
TP
Luiz Fernando Guedes dos Santos
LS
Kamil Leoniak
KL
Tiago Pinho, Luiz Fernando Guedes dos Santos, Kamil Leoniak
Delphos outscores commercial decompilers on DecBenchDelphos outscores commercial decompilers on DecBench
Delphos outscores commercial decompilers on DecBench thumbnailDelphos outscores commercial decompilers on DecBench thumbnail
Security Research

Delphos outscores commercial decompilers on DecBench

Delphos Lantern takes first place on the overall metric and first place on elusive types metric

Tiago Pinho
TP
Luiz Fernando Guedes dos Santos
LS
Kamil Leoniak
KL
Tiago Pinho, Luiz Fernando Guedes dos Santos, Kamil LeoniakSep 10, 2026
The USB Camera That Freezes Windows: A usbvideo.sys Descriptor Parser DoS Microsoft Won't Fix thumbnailThe USB Camera That Freezes Windows: A usbvideo.sys Descriptor Parser DoS Microsoft Won't Fix thumbnail
Security Research

The USB Camera That Freezes Windows: A usbvideo.sys Descriptor Parser DoS Microsoft Won't Fix

A usbvideo.sys descriptor-parser DoS: a USB Video device with bLength=0 can pin kernel CPU and block USB enumeration. MSRC closed it without a fix.

Kamil Leoniak
KL
Kamil LeoniakSep 4, 2026
CVE-2026-50321. How A Normal WinUSB Feature Exposed A Pipe-Lifetime Race thumbnailCVE-2026-50321. How A Normal WinUSB Feature Exposed A Pipe-Lifetime Race thumbnail
Security Research

CVE-2026-50321. How A Normal WinUSB Feature Exposed A Pipe-Lifetime Race

CVE-2026-50321: an unsynchronized free-then-null window in winusb.sys leaves a pipe-context pointer dangling for other contexts to use — reliably a BSOD, potentially an EoP.

Kamil Leoniak
KL
Kamil LeoniakAug 25, 2026
Delphos Labs Selected by AFWERX for SBIR Phase I to Advance AI-Powered Analysis of Software Artifacts thumbnailDelphos Labs Selected by AFWERX for SBIR Phase I to Advance AI-Powered Analysis of Software Artifacts thumbnail
Company
News

Delphos Labs Selected by AFWERX for SBIR Phase I to Advance AI-Powered Analysis of Software Artifacts

Delphos Labs selected by AFWERX for an SBIR Phase I to advance AI-powered analysis of source-denied software for Air Force cybersecurity and assurance.

David Dubick
DD
Caleb Fenton
CF
Cindy Berman
CB
Michael Quinn
MQ
Joseph Szczerba
JS
David Dubick, Caleb Fenton, Cindy Berman, Michael Quinn, Joseph SzczerbaAug 21, 2026
Threat Intel: ValleyRAT. A Zero-Detection Stager Classified 24 Hours Before Its First Signature thumbnailThreat Intel: ValleyRAT. A Zero-Detection Stager Classified 24 Hours Before Its First Signature thumbnail
Security Research

Threat Intel: ValleyRAT. A Zero-Detection Stager Classified 24 Hours Before Its First Signature

A Chinese-language ValleyRAT stager, zero AV detections, pulling a second-stage payload from AWS S3, classified in 5 minutes, 24 hours before first signature.

Evgeny Pinchuk
EP
Evgeny PinchukJul 14, 2026
Threat Intel: libpsl-5.dll. A Sideloading DLL Padded to 55MB, Undetected by 60+ AV Engines for Six Days thumbnailThreat Intel: libpsl-5.dll. A Sideloading DLL Padded to 55MB, Undetected by 60+ AV Engines for Six Days thumbnail
Security Research

Threat Intel: libpsl-5.dll. A Sideloading DLL Padded to 55MB, Undetected by 60+ AV Engines for Six Days

The real payload is 3.3MB. The other 52MB is junk padding, appended to slip past scanners. Its code overlaps several known info-stealer families.

Evgeny Pinchuk
EP
Evgeny PinchukJul 14, 2026
fast16: From Stripped Binary to Sabotage Finding in Minutes thumbnailfast16: From Stripped Binary to Sabotage Finding in Minutes thumbnail
Security Research

fast16: From Stripped Binary to Sabotage Finding in Minutes

The Delphos Labs agent analyzed fast16, a 2005 nation-state sabotage framework, starting from two stripped binaries and no context.

Itai Liba
IL
Itai LibaJul 13, 2026
DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write thumbnailDirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write thumbnail
Security Research

DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write

Linux kernel page-cache poisoning via AES-256 chosen-plaintext on the RxGK RESPONSE path and why authenticated encryption did not stop it.

Kamil Leoniak
KL
Kamil LeoniakMay 15, 2026
Introducing Delphos Labs: Securing the Software That Actually Runs thumbnailIntroducing Delphos Labs: Securing the Software That Actually Runs thumbnail
Company
Product

Introducing Delphos Labs: Securing the Software That Actually Runs

Revealing hidden threats in compiled software without source code.

David Dubick
DD
Caleb Fenton
CF
David Dubick, Caleb FentonMay 4, 2026
Delphos LabsDelphos Labs

No source code required. No signatures. No blind spots.

Company
About UsBlogSecurity Trust CenterBug Bounty ProgramVulnerability Research Policy
Account
Privacy PolicyTerms of Service
Help & Feedback
Contact SupportEmail Us
Social
LinkedInXGitHub
Copyright © 2026 Delphos Labs Inc.
Compliance & memberships
SOC 2 Type IINVIDIA Inception ProgramFS-ISAC Early Stage Affiliate