Research blog
Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

vulnerability|5 min read
Critical protobuf.js flaw turns untrusted schemas into JavaScript code execution
Read More

vulnerability|5 min read
Leaked Windows Defender zero-days are already being used to gain SYSTEM access
Read More

Threat Hunting & Intel|5 min read
AgingFly campaign hits Ukrainian government and hospital networks
Read More

vulnerability|2 min read
CVE-2026-33032 in nginx-ui Enables Full Nginx Server Takeover via Unauthenticated MCP Access
Read More

Cloud & Application Security|5 min read
Malicious Chrome extensions turn OAuth tokens into enterprise risk
Read More

vulnerability|4 min read
CVE-2026-5194 weakens wolfSSL certificate trust in embedded deployments
Read More

vulnerability|3 min read
Docker AuthZ Plugin Bypass in CVE-2026-34040 Weakens API-Level Container Controls
Read More

Threat Hunting & Intel|5 min read
CPUID breach turned CPU-Z and HWMonitor into a malware delivery path
Read More

Cloud & Application Security|4 min read
CVE-2026-39987 puts exposed Marimo notebooks on a fast credential-theft path
Read More

vulnerability|5 min read
CVE-2026-22557 puts internet-exposed UniFi controllers at account-takeover risk
Read More

Threat Hunting & Intel|7 min read
Iranian PLC Attacks Disrupt U.S. Critical Infrastructure
Read More

Data Breach|5 min read
Snowflake customer breaches show how stolen SaaS tokens can spread one integrator compromise
Read More
Follow the research
New vulnerability analysis, threat actor reporting, and supply chain research as we publish it.
Recent Posts
- WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws
- Dropbox breach shows why third-party identity links need zero trust
- CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock
- ServiceNow Critical Flaws Expose Enterprise Workflows
- PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV