<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Noman Nasir Minhas (Sheldon) — Cybersecurity Researcher</title>
    <description>Security research, Windows internals, offensive tools, and a practical pentesting book by Noman Nasir Minhas, also known as Sheldon.</description>
    <link>https://nomannasirminhas.com</link>
    <atom:link href="https://nomannasirminhas.com/rss.xml" rel="self" type="application/rss+xml"/>
    <language>en-us</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:40:42 GMT</lastBuildDate>
    
    <item>
      <title><![CDATA[Why Air-Gapped OT Environments Are Still Insecure]]></title>
      <description><![CDATA[A technical analysis of OT isolation: Stuxnet, TRITON, offline malware channels, industrial protocols, WirelessHART, measurement integrity, and maintenance—with reproducible simulation labs.]]></description>
      <link>https://nomannasirminhas.com/blog/why-air-gapped-ot-environments-are-still-insecure</link>
      <guid>https://nomannasirminhas.com/blog/why-air-gapped-ot-environments-are-still-insecure</guid>
      <pubDate>Fri, 02 Oct 2026 00:00:00 GMT</pubDate>
    </item>

    <item>
      <title><![CDATA[Exploiting CVE-2025-62215: A Reference-Count Race in the Object Manager]]></title>
      <description><![CDATA[A deep-dive into CVE-2025-62215 — an actively exploited race in ntoskrnl's Object Manager that double-frees the token's SID Values Block, reclaimed with a same-bucket spray and pivoted into a data-only token flip for SYSTEM.]]></description>
      <link>https://nomannasirminhas.com/blog/cve-2025-62215-object-manager-double-free-race</link>
      <guid>https://nomannasirminhas.com/blog/cve-2025-62215-object-manager-double-free-race</guid>
      <pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate>
    </item>

    <item>
      <title><![CDATA[Inside the petshub[.]qa ClickFix: From a Fake CAPTCHA to an ACR Stealer Implant]]></title>
      <description><![CDATA[Full teardown of the petshub[.]qa ClickFix campaign: a fake CAPTCHA that drops a blockchain-resolved macOS stealer and a four-stage Windows chain ending in an ACR Stealer implant flagged by 33/69 engines — Realtek masquerade, Heaven's Gate, and CVE-2024-38193 in tow.]]></description>
      <link>https://nomannasirminhas.com/blog/petshub-qa-clickfix-acr-stealer-implant</link>
      <guid>https://nomannasirminhas.com/blog/petshub-qa-clickfix-acr-stealer-implant</guid>
      <pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
    </item>

    <item>
      <title><![CDATA[Exploiting CVE-2026-21241: A Use-After-Free Race in AFD.sys]]></title>
      <description><![CDATA[A deep-dive into CVE-2026-21241 — a use-after-free race in afd.sys's socket notification path, where a notification object is freed across a spinlock release, reclaimed with a named-pipe spray, and pivoted through kCFG-legal RtlSetBit calls into a KDP-evading SeDebugPrivilege flip and SYSTEM.]]></description>
      <link>https://nomannasirminhas.com/blog/cve-2026-21241-afd-sys-use-after-free</link>
      <guid>https://nomannasirminhas.com/blog/cve-2026-21241-afd-sys-use-after-free</guid>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>

    <item>
      <title><![CDATA[Exploiting CVE-2024-30088: A TOCTOU Race in the Windows Kernel]]></title>
      <description><![CDATA[A deep-dive into CVE-2024-30088 — a TOCTOU race in ntoskrnl's AuthzBasepCopyoutInternalSecurityAttributes, exploited by flipping a user-memory pointer to redirect the kernel's own copy into kernel space, then pivoting the fixed-value write through an I/O Ring into SYSTEM.]]></description>
      <link>https://nomannasirminhas.com/blog/cve-2024-30088-windows-kernel-toctou-race</link>
      <guid>https://nomannasirminhas.com/blog/cve-2024-30088-windows-kernel-toctou-race</guid>
      <pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate>
    </item>

    <item>
      <title><![CDATA[Exploiting CVE-2025-7771 in the ThrottleStop Driver: Kernel-Exploitation Series]]></title>
      <description><![CDATA[A complete walkthrough of reverse engineering the ThrottleStop driver, understanding its physical memory read/write IOCTL handlers, and building a data-only privilege escalation exploit — from opening the device to spawning a SYSTEM shell.]]></description>
      <link>https://nomannasirminhas.com/blog/throttlestop-physical-memory-exploit</link>
      <guid>https://nomannasirminhas.com/blog/throttlestop-physical-memory-exploit</guid>
      <pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate>
    </item>

    <item>
      <title><![CDATA[The Kernel Attack Surface: How Windows Internals Enable Exploitation]]></title>
      <description><![CDATA[A subsystem-by-subsystem map of the Windows kernel attack surface — how the syscall interface, I/O manager, memory manager, object manager, and kernel pool each create exploitable primitives, which techniques still work, and which ones died.]]></description>
      <link>https://nomannasirminhas.com/blog/kernel-exploitation-techniques-ioctl-read-write</link>
      <guid>https://nomannasirminhas.com/blog/kernel-exploitation-techniques-ioctl-read-write</guid>
      <pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate>
    </item>

    <item>
      <title><![CDATA[Windows Internals You Need To Know Before Kernel Exploitation]]></title>
      <description><![CDATA[Every defense mechanism between a user-mode process and kernel code execution, explained from first principles — PatchGuard, VBS, HVCI, SMEP, SMAP, CET, KASLR, and the rest.]]></description>
      <link>https://nomannasirminhas.com/blog/windows-internals-before-kernel-exploitation</link>
      <guid>https://nomannasirminhas.com/blog/windows-internals-before-kernel-exploitation</guid>
      <pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate>
    </item>

    <item>
      <title><![CDATA[Nanga: Process Telemetry from the Syscall Layer]]></title>
      <description><![CDATA[A kernel-driver approach to malware dynamic analysis that captures process telemetry below user-mode evasion, at the syscall layer.]]></description>
      <link>https://nomannasirminhas.com/blog/nanga-process-telemetry-syscall-layer</link>
      <guid>https://nomannasirminhas.com/blog/nanga-process-telemetry-syscall-layer</guid>
      <pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>