James Forshaw

@tiraniddo.dev

Security researcher in Google Project Zero. Author of Attacking Network Protocols. Posts are my own etc.

In the final part of his blog series, @tiraniddo.dev tells the story of how a bug was introduced into a Windows API. Code re-writes can improve security, but it’s important not to forget the security properties the code needs to enforce in the process. projectzero.google/2026/02/gphf...

A Deep Dive into the GetProcessHandleFromHwnd API - Project Zero

In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass us...

projectzero.google

🚨 Our new blog post about Windows CVE-2025-33073 which we discovered is live: 🪞The Reflective Kerberos Relay Attack - Remote privilege escalation from low-priv user to SYSTEM with RCE by applying a long forgotten NTLM relay technique to Kerberos: blog.redteam-pentesting.de/2025/reflect...

A Look in the Mirror - The Reflective Kerberos Relay Attack

It is a sad truth in IT security that some vulnerabilities never quite want to die and time and time again, vulnerabilities that have long been fixed get revived and come right back at you. While rese...

blog.redteam-pentesting.de

Maybe I’ll pop down to sf for rsa tomorrow. I’ve fortunately never gone before but this is my last chance and I really need a new ai security product.

My RDP IO Lab presentation on "Decrypting and Inspecting RDP traffic in Wireshark" was just *cancelled* - apparently Microsoft decided they would only do internal presentations, with no guest speakers 😠 What's the point of even trying when you get treated like this?

Marc-André Moreau@awakecoding.com · 2y ago

Who would like to review my slides for my upcoming RDP IO Lab presentation on "Decrypting and Inspecting RDP traffic in Wireshark"? I have finished my first draft, but could use some feedback. It's supposed to be 45 minutes in total, including Q&A. Just DM me with your email and I'll send you a copy

You know you travel too much when you get top tier status on the three main airline alliances at the same time. Fortunately moving back to the UK will probably mean I’ll slow it down as I doubt I’ll travel much to the USA anymore.

It took me about a month, but I've got my win32-appcontainer-tools ready to share. - Launch Win32 apps in AppContainer - Set ACL permissions per-container - ETW tracing for Permissive Learning Mode Special thanks to Fredrik Orderud, @tiraniddo.dev and Helge Klein.

Set AppContainer ACLLaunch AppContainerAppContainer Permissive Learning Mode

Either Keir Starmer is the biggest mark to ever live or he's still hoping for a few 'freebies' from his corpo mates. I cannot understate how atrocious this is.

Politics
‘Mainlined into UK’s veins’: Labour announces huge public rollout of AI
Plans to make UK world leader in AI sector include opening access to NHS and other public dataTechnology companies including Microsoft, Anthropic and OpenAI welcomed the plan as Starmer said the “AI industry needs a government that is on their side”. Regulators will be told to “actively support innovation”, setting up a potential clash with people who believe regulators’ primary role should be to protect the public from harm.