Research blog
Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

Threat Hunting & Intel|5 min read
CVE-2026-41940 turns exposed cPanel and WHM servers into control-plane takeover targets
Read More

Cloud & Application Security|5 min read
CVE-2026-42208 turns exposed LiteLLM gateways into a secrets exposure risk
Read More

Supply Chain Security|5 min read
GlassWorm sleeper extensions turn Open VSX updates into a malware delivery path
Read More

vulnerability|5 min read
CVE-2026-33032 lets attackers take over exposed nginx-ui servers
Read More

Threat Hunting & Intel|5 min read
Firestarter leaves patched Cisco firewalls at continued risk
Read More

vulnerability|5 min read
Pack2TheRoot flaw puts Linux systems with PackageKit on a local root path
Read More

Supply Chain Security|5 min read
Bitwarden CLI npm compromise exposes CI/CD credential risk
Read More

Cloud & Application Security|2 min read
Lovable Incident Raises Cross-Tenant Data Exposure Concerns for AI Development Platforms
Read More

Cloud & Application Security|4 min read
CVE-2026-5752 turns the Terrarium sandbox into a root-level escape risk
Read More

vulnerability|5 min read
CISA KEV flags Quest KACE SMA auth bypass as a high-priority risk
Read More

vulnerability|5 min read
SGLang CVE-2026-5760 turns malicious GGUF models into RCE
Read More

vulnerability|5 min read
Apache ActiveMQ RCE CVE-2026-34197 Lands in CISA KEV
Read More
Follow the research
New vulnerability analysis, threat actor reporting, and supply chain research as we publish it.
Recent Posts
- WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws
- Dropbox breach shows why third-party identity links need zero trust
- CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock
- ServiceNow Critical Flaws Expose Enterprise Workflows
- PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV