Structured data rendered for: graph
INVADERS

Research blog

Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

RSS
Cl0p Turns PTC Windchill Exploitation Into a Purpose-Built Extortion Platform

Featured|Cybercrime|5 min read

Cl0p Turns PTC Windchill Exploitation Into a Purpose-Built Extortion Platform

Cl0p Turns PTC Windchill Exploitation Into a Purpose-Built Extortion Platform Product lifecycle management systems are not usually the first asset class defende...

Read More
WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws

vulnerability|5 min read

WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws

Read More
Dropbox breach shows why third-party identity links need zero trust

Data Breach|6 min read

Dropbox breach shows why third-party identity links need zero trust

Read More
CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock

vulnerability|7 min read

CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock

Read More
ServiceNow Critical Flaws Expose Enterprise Workflows

vulnerability|4 min read

ServiceNow Critical Flaws Expose Enterprise Workflows

Read More
PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV

vulnerability|6 min read

PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV

Read More
Citrix NetScaler CVE-2026-8452 is now a KEV patch priority

vulnerability|7 min read

Citrix NetScaler CVE-2026-8452 is now a KEV patch priority

Read More
McKesson Cyber Incident Raises Fresh Questions About Healthcare SaaS Exposure

Data Breach|5 min read

McKesson Cyber Incident Raises Fresh Questions About Healthcare SaaS Exposure

Read More
Berlin Refuses Extortion After State Network Cyberattack

Cybercrime|5 min read

Berlin Refuses Extortion After State Network Cyberattack

Read More
cPanel CVE-2026-65643 turns domain parking into a root-control risk

vulnerability|7 min read

cPanel CVE-2026-65643 turns domain parking into a root-control risk

Read More
Next.js Critical RCE Fixes Put Self-Hosted Apps on a Short Patch Clock

vulnerability|5 min read

Next.js Critical RCE Fixes Put Self-Hosted Apps on a Short Patch Clock

Read More
Gitea CVE-2026-60004: Patch Self-Hosted Git Before RCE Becomes an Incident

vulnerability|6 min read

Gitea CVE-2026-60004: Patch Self-Hosted Git Before RCE Becomes an Incident

Read More
CISA Adds Oracle WebLogic Proxy Plug-in Flaw to KEV as Exploitation Pressure Rises

vulnerability|4 min read

CISA Adds Oracle WebLogic Proxy Plug-in Flaw to KEV as Exploitation Pressure Rises

Read More