Structured data rendered for: graph
INVADERS

Research blog

Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

RSS
Gitea Org-mode flaw turns public repositories into a server file-read risk

vulnerability|6 min read

Gitea Org-mode flaw turns public repositories into a server file-read risk

Read More
Active exploitation of TeamCity RCE puts CI/CD control planes on the front line

vulnerability|6 min read

Active exploitation of TeamCity RCE puts CI/CD control planes on the front line

Read More
ChainDrop shows how npm worms are moving from package compromise to CI/CD takeover

vulnerability|7 min read

ChainDrop shows how npm worms are moving from package compromise to CI/CD takeover

Read More
TP-Link Omada ZTP flaws expose the trust chain behind managed networks

vulnerability|7 min read

TP-Link Omada ZTP flaws expose the trust chain behind managed networks

Read More
N-able N-central flaw exposes MSP consoles to account takeover

vulnerability|5 min read

N-able N-central flaw exposes MSP consoles to account takeover

Read More
Hugging Face Diffusers flaws turn model loading into a code execution risk

vulnerability|6 min read

Hugging Face Diffusers flaws turn model loading into a code execution risk

Read More
Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list

vulnerability|5 min read

Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list

Read More
AWS Kiro flaw shows why AI coding agents need platform-level guardrails

vulnerability|7 min read

AWS Kiro flaw shows why AI coding agents need platform-level guardrails

Read More
Cisco FMC Static Credential Flaw Lands in KEV After Active Exploitation

vulnerability|7 min read

Cisco FMC Static Credential Flaw Lands in KEV After Active Exploitation

Read More
JetBrains TeamCity RCE Puts Self-Hosted CI/CD Servers on an Urgent Patch Clock

vulnerability|7 min read

JetBrains TeamCity RCE Puts Self-Hosted CI/CD Servers on an Urgent Patch Clock

Read More
AI-Assisted Linux Kernel Exploit Turns a Traffic-Control Race Into Root Access

vulnerability|9 min read

AI-Assisted Linux Kernel Exploit Turns a Traffic-Control Race Into Root Access

Read More
Arista VeloCloud Zero-Day Puts SD-WAN Orchestrators in the Blast Radius

vulnerability|7 min read

Arista VeloCloud Zero-Day Puts SD-WAN Orchestrators in the Blast Radius

Read More