HoneyMex Lab

Deception & Honeypots, Network Security, Threat Intel, Cybersecurity research and more.

Open Research Community - Honeynet Mexico Lab

TailBliss Hero
P1

About the project

HoneyMex Lab is an independent, open research cybersecurity group organized by volunteers with diverse backgrounds, including DFIR, Threat Hunting, System Administration, Threat Intelligence, and Cyber Deception/Honeypots.

HoneyMex Lab is a spin-off initiative of Mizton Labs to operate the Honeynet Mexico Chapter of The Honeynet Project and continue developing new projects inspired by the previous work of former UNAM-Chapter. The vision of HoneyMex Lab is to become a reference in the LATAM region.

Our members and collaborators come from both industry and academia. The team's roots trace back to projects developed or inspired by work within the former UNAM-CERT and The Honeynet Project as UNAM Chapter (Mirror archive).

Our Main Focus Areas Include:

  • - Deception and Honeypot Research & Development
  • - Threat Detection Engineering
  • - Network Security
  • - Network Forensics
  • - Malware Analysis
  • - Yes.. AI and CyberSecurity (LLM-based deception/honeypot, LLM Security, etc)

Our Blog and News

Check out our latest activity

Technical articles, security news, events, tutoriasl, and more.

/../assets/images/featured/adobe_critical.png
Adobe Campaign Classic — Second CVSS 10.0 Flaw in a Month Allows Code Execution Without User Interaction (CVE-2026-48449)

Adobe fixed CVE-2026-48449, an incorrect authorization flaw in Campaign Classic with a CVSS score of 10.0 that allows arbitrary code execution without user interaction. It is the second CVSS 10.0 incorrect-authorization flaw in the same product within a single month. The update also resolves a high-severity SQL injection flaw and eight critical Adobe Bridge vulnerabilities.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

9 min read
/../assets/images/featured/Fastjson.png
CVE-2026-16723: Active Exploitation of a Critical RCE (0-Day) Vulnerability in Fastjson 1.x

A flaw in type resolution during JSON deserialization allows unauthenticated remote code execution in Spring Boot applications that use Fastjson 1.x, without needing AutoType to be enabled.

Tags: News
Threat Intelligence Teams

Threat Intelligence Teams

6 min read
/../assets/images/featured/OpenAIHF.png
OpenAI Models Reportedly Escaped Their Testing Environment to Breach Hugging Face Servers

OpenAI acknowledges that, during an internal cybersecurity evaluation, its own models reportedly escaped their testing environment and reached real Hugging Face infrastructure.

Tags: News
Threat Intelligence Desk

Threat Intelligence Desk

4 min read