Research blog
Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

vulnerability|6 min read
Gitea Org-mode flaw turns public repositories into a server file-read risk
Read More

vulnerability|6 min read
Active exploitation of TeamCity RCE puts CI/CD control planes on the front line
Read More

vulnerability|7 min read
ChainDrop shows how npm worms are moving from package compromise to CI/CD takeover
Read More

vulnerability|7 min read
TP-Link Omada ZTP flaws expose the trust chain behind managed networks
Read More

vulnerability|5 min read
N-able N-central flaw exposes MSP consoles to account takeover
Read More

vulnerability|6 min read
Hugging Face Diffusers flaws turn model loading into a code execution risk
Read More

vulnerability|5 min read
Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list
Read More

vulnerability|7 min read
AWS Kiro flaw shows why AI coding agents need platform-level guardrails
Read More

vulnerability|7 min read
Cisco FMC Static Credential Flaw Lands in KEV After Active Exploitation
Read More

vulnerability|7 min read
JetBrains TeamCity RCE Puts Self-Hosted CI/CD Servers on an Urgent Patch Clock
Read More

vulnerability|9 min read
AI-Assisted Linux Kernel Exploit Turns a Traffic-Control Race Into Root Access
Read More

vulnerability|7 min read
Arista VeloCloud Zero-Day Puts SD-WAN Orchestrators in the Blast Radius
Read More
Follow the research
New vulnerability analysis, threat actor reporting, and supply chain research as we publish it.
Recent Posts
- WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws
- Dropbox breach shows why third-party identity links need zero trust
- CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock
- ServiceNow Critical Flaws Expose Enterprise Workflows
- PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV