HoneyMex Lab

Deception & Honeypots, Network Security, Threat Intel, Cybersecurity research and more.

Open Research Community - Honeynet Mexico Lab

TailBliss Hero
P1

About the project

HoneyMex Lab is an independent, open research cybersecurity group organized by volunteers with diverse backgrounds, including DFIR, Threat Hunting, System Administration, Threat Intelligence, and Cyber Deception/Honeypots.

HoneyMex Lab is a spin-off initiative of Mizton Labs to operate the Honeynet Mexico Chapter of The Honeynet Project and continue developing new projects inspired by the previous work of former UNAM-Chapter. The vision of HoneyMex Lab is to become a reference in the LATAM region.

Our members and collaborators come from both industry and academia. The team's roots trace back to projects developed or inspired by work within the former UNAM-CERT and The Honeynet Project as UNAM Chapter (Mirror archive).

Our Main Focus Areas Include:

  • - Deception and Honeypot Research & Development
  • - Threat Detection Engineering
  • - Network Security
  • - Network Forensics
  • - Malware Analysis
  • - Yes.. AI and CyberSecurity (LLM-based deception/honeypot, LLM Security, etc)

Our Blog and News

Check out our latest activity

Technical articles, security news, events, tutoriasl, and more.

/../assets/images/featured/CVE-2026-23111.png
CVE-2026-23111: A Single Character in the Linux Kernel Opens the Door to Full System Compromise

A misplaced exclamation mark (`!`) inside `nft_map_catchall_activate()` inverts the validation logic in nf_tables, allowing any unprivileged local user to trigger a Use-After-Free, corrupt kernel memory, and escalate to root.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

6 min read
/../assets/images/featured/RoguePlanet.png
RoguePlanet: The Zero-Day Exploit Compromising Microsoft Defender

A zero-day exploit released hours after Microsoft's largest Patch Tuesday on record allows any local user to obtain SYSTEM privileges on fully patched Windows 10 and 11 systems by abusing the Microsoft Defender engine itself.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

10 min read
CVE-2026-20245: The Seventh Actively Exploited Zero-Day in Cisco SD-WAN Enables Root Command Execution — No Patch Available

CVE-2026-20245. A privilege escalation flaw under active exploitation in Cisco Catalyst SD-WAN Manager, with no patch available, that allows an attacker to execute arbitrary commands as root through command injection in the CLI.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

9 min read