Research blog
Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

vulnerability|5 min read
CVE-2026-34040 puts Docker image-mount trust on the host-root risk path
Read More

Ransomware Trends|7 min read
Storm-1175 turns patch gaps into rapid Medusa ransomware intrusions
Read More

vulnerability|5 min read
CVE-2026-35616 puts exposed FortiClient EMS servers into the incident-response lane
Read More

Data Breach|5 min read
European Commission breach shows how stolen cloud secrets can spill across shared public platforms
Read More

vulnerability|4 min read
CVE-2026-35616 puts FortiClient EMS at risk of unauthenticated code execution
Read More

vulnerability|6 min read
CVE-2025-53521 turns into an actively exploited F5 BIG-IP APM RCE
Read More

vulnerability|5 min read
CVE-2026-3502 turns TrueConf updates into a KEV-listed malware channel
Read More

vulnerability|5 min read
GIGABYTE Control Center flaw turns a convenience utility into a remote compromise path
Read More

Supply Chain Security|5 min read
Cisco Breach Shows the Real Cost of the Trivy Supply-Chain Attack
Read More

Supply Chain Security|5 min read
Axios npm compromise pushed a cross-platform RAT through a fake dependency
Read More

vulnerability|5 min read
CVE-2026-21643: FortiClient EMS exploitation puts exposed endpoint managers at immediate risk
Read More

vulnerability|6 min read
CVE-2025-53521: F5 BIG-IP APM KEV warning raises urgent RCE risk
Read More
Follow the research
New vulnerability analysis, threat actor reporting, and supply chain research as we publish it.
Recent Posts
- WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws
- Dropbox breach shows why third-party identity links need zero trust
- CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock
- ServiceNow Critical Flaws Expose Enterprise Workflows
- PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV