Back to Blog
Lucas Oliveira

Lucas Oliveira

Research

A DevOps engineer and cybersecurity enthusiast with a passion for uncovering the latest in zero-day exploits, automation, and emerging tech. I write to share real-world insights from the trenches of IT and security, aiming to make complex topics more accessible and actionable. Whether I’m building tools, tracking threat actors, or experimenting with AI workflows, I’m always exploring new ways to stay one step ahead in today’s fast-moving digital landscape.

89
Articles
6
Avg. Read Time
13
Categories
2024
Joined

Expertise Areas

Threat Hunting & Intel
vulnerability
Cloud & Application Security
Data Breach
Ransomware Trends
Supply Chain Security
Data Protection
Cybercrime
supply chain attack
Cloud Security
Security
Ransomware Groups
Infostealer

Articles by Lucas Oliveira

AgingFly campaign hits Ukrainian government and hospital networks

AgingFly campaign hits Ukrainian government and hospital networks

AgingFly campaign hits Ukrainian government and hospital networks A newly reported campaign centered on the AgingFly backdoor is a reminder that targeted intrus...

April 16, 2026
5 min read
CVE-2026-33032 in nginx-ui Enables Full Nginx Server Takeover via Unauthenticated MCP Access

CVE-2026-33032 in nginx-ui Enables Full Nginx Server Takeover via Unauthenticated MCP Access

CVE-2026-33032 in nginx-ui Enables Full Nginx Server Takeover via Unauthenticated MCP Access A critical flaw in nginx-ui, the web-based Nginx management tool, c...

April 15, 2026
2 min read
Malicious Chrome extensions turn OAuth tokens into enterprise risk

Malicious Chrome extensions turn OAuth tokens into enterprise risk

Malicious Chrome extensions turn OAuth tokens into enterprise risk A newly reported cluster of malicious Chrome Web Store extensions is a useful warning for def...

April 15, 2026
5 min read
CVE-2026-5194 weakens wolfSSL certificate trust in embedded deployments

CVE-2026-5194 weakens wolfSSL certificate trust in embedded deployments

CVE-2026-5194 weakens wolfSSL certificate trust in embedded deployments CVE-2026-5194 is a reminder that core cryptographic libraries can create outsized enterp...

April 14, 2026
4 min read
Docker AuthZ Plugin Bypass in CVE-2026-34040 Weakens API-Level Container Controls

Docker AuthZ Plugin Bypass in CVE-2026-34040 Weakens API-Level Container Controls

Docker AuthZ Plugin Bypass in CVE-2026-34040 Weakens API-Level Container Controls A newly disclosed Docker Engine and Moby flaw, tracked as CVE-2026-34040, show...

April 13, 2026
3 min read
CPUID breach turned CPU-Z and HWMonitor into a malware delivery path

CPUID breach turned CPU-Z and HWMonitor into a malware delivery path

CPUID breach turned CPU-Z and HWMonitor into a malware delivery path Executive summary A compromise of the CPUID website briefly turned trusted download links f...

April 13, 2026
5 min read
CVE-2026-39987 puts exposed Marimo notebooks on a fast credential-theft path

CVE-2026-39987 puts exposed Marimo notebooks on a fast credential-theft path

CVE-2026-39987 puts exposed Marimo notebooks on a fast credential-theft path CVE-2026-39987 is a sharp reminder that smaller developer and data-science platform...

April 12, 2026
4 min read
CVE-2026-22557 puts internet-exposed UniFi controllers at account-takeover risk

CVE-2026-22557 puts internet-exposed UniFi controllers at account-takeover risk

CVE-2026-22557 puts internet-exposed UniFi controllers at account-takeover risk CVE-2026-22557 is the kind of infrastructure flaw defenders should treat as urge...

April 10, 2026
5 min read
Iranian PLC Attacks Disrupt U.S. Critical Infrastructure

Iranian PLC Attacks Disrupt U.S. Critical Infrastructure

Iranian PLC Attacks Disrupt U.S. Critical Infrastructure Executive Summary Iranian-affiliated [advanced persistent threat](https://invaders.ie/resources/glossar...

April 9, 2026
7 min read
...