Research blog
Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

vulnerability|7 min read
Microsoft Entra ID CVSS 10 RCE is a trust-plane warning
Read More

vulnerability|4 min read
CISA Warns of Active Exploitation in Zimbra Collaboration Suite
Read More

vulnerability|4 min read
CVE-2026-24301: Microsoft Copilot CoSnitch Data Exposure
Read More

vulnerability|7 min read
CVE-2026-33824: Windows IKE RCE Active Exploit Patch Guide
Read More

Cybercrime|5 min read
Cl0p Turns PTC Windchill Exploitation Into a Purpose-Built Extortion Platform
Read More

vulnerability|4 min read
GitLab ships critical GraphQL patch for self-managed instances
Read More

vulnerability|5 min read
macOS Screen Sharing CVE-2026-65400 exploited to gain root and deploy Monero miners
Read More

vulnerability|6 min read
SharePoint JWT Bypass Turns Patch Delay Into an Identity Risk
Read More

vulnerability|6 min read
VMware vCenter RCE exploitation turns syslog exposure into persistence risk
Read More

vulnerability|6 min read
SAP Commerce Cloud CVE-2026-58231 Is a Reminder That Patch Windows Are Now Measured in Days
Read More

vulnerability|6 min read
Metabase zero-day turns BI dashboards into a data-exposure path
Read More

vulnerability|6 min read
Swiss SharePoint breach shows why patching alone may not end the incident
Read More
Follow the research
New vulnerability analysis, threat actor reporting, and supply chain research as we publish it.
Recent Posts
- WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws
- Dropbox breach shows why third-party identity links need zero trust
- CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock
- ServiceNow Critical Flaws Expose Enterprise Workflows
- PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV