Back to Blog
Lucas Oliveira

Lucas Oliveira

Research

A DevOps engineer and cybersecurity enthusiast with a passion for uncovering the latest in zero-day exploits, automation, and emerging tech. I write to share real-world insights from the trenches of IT and security, aiming to make complex topics more accessible and actionable. Whether I’m building tools, tracking threat actors, or experimenting with AI workflows, I’m always exploring new ways to stay one step ahead in today’s fast-moving digital landscape.

110
Articles
5
Avg. Read Time
13
Categories
2024
Joined

Expertise Areas

vulnerability
Threat Hunting & Intel
Cloud & Application Security
Cybercrime
Supply Chain Security
Data Breach
Ransomware Trends
Data Protection
supply chain attack
Cloud Security
Security
Ransomware Groups
Infostealer

Articles by Lucas Oliveira

CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path

CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path

CVE-2026-0300 puts exposed PAN-OS User-ID portals on a zero-day attack path A critical point in the new PAN-OS warning is that defenders are not looking at a ro...

May 7, 2026
4 min read
DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path

DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path

DAEMON Tools supply-chain attack turns trusted installers into a malware delivery path The most important part of the DAEMON Tools incident is not that malware...

May 6, 2026
5 min read
Vishing and SSO abuse are accelerating rapid SaaS extortion

Vishing and SSO abuse are accelerating rapid SaaS extortion

Vishing and SSO abuse are accelerating rapid SaaS extortion The most dangerous part of modern SaaS intrusions is not always malware. Sometimes it is speed, trus...

May 5, 2026
5 min read
ConsentFix v3 turns Azure OAuth phishing into a scalable token theft risk

ConsentFix v3 turns Azure OAuth phishing into a scalable token theft risk

ConsentFix v3 turns Azure OAuth phishing into a scalable token theft risk ConsentFix v3 matters because it shifts Azure account compromise away from password th...

May 4, 2026
5 min read
BlackCat case shows ransomware risk inside trusted cyber roles

BlackCat case shows ransomware risk inside trusted cyber roles

BlackCat case shows ransomware risk inside trusted cyber roles A new U.S. criminal case tied to BlackCat (ALPHV) is a sharp reminder that ransomware risk is not...

May 3, 2026
5 min read
PyTorch Lightning supply-chain compromise puts AI developer credentials at risk

PyTorch Lightning supply-chain compromise puts AI developer credentials at risk

PyTorch Lightning supply-chain compromise puts AI developer credentials at risk The most dangerous supply-chain incidents are not always the ones that hit opera...

May 2, 2026
5 min read
CVE-2026-31431: Copy Fail turns routine Linux access into reliable root compromise

CVE-2026-31431: Copy Fail turns routine Linux access into reliable root compromise

CVE-2026-31431: Copy Fail turns routine Linux access into reliable root compromise Copy Fail is the kind of Linux flaw defenders should not shrug off just becau...

May 1, 2026
6 min read
CVE-2026-41940 turns exposed cPanel and WHM servers into control-plane takeover targets

CVE-2026-41940 turns exposed cPanel and WHM servers into control-plane takeover targets

CVE-2026-41940 turns exposed cPanel and WHM servers into control-plane takeover targets CVE-2026-41940 is a critical authentication bypass in cPanel and WHM, an...

April 30, 2026
5 min read
CVE-2026-42208 turns exposed LiteLLM gateways into a secrets exposure risk

CVE-2026-42208 turns exposed LiteLLM gateways into a secrets exposure risk

CVE-2026-42208 turns exposed LiteLLM gateways into a secrets exposure risk CVE-2026-42208 is a critical SQL injection flaw in LiteLLM's proxy API key verificati...

April 29, 2026
5 min read
...