Research blog
Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

Threat Hunting & Intel|7 min read
Russian Zimbra Campaign Turns Email Preview Into an Exfiltration Path
Read More

vulnerability|8 min read
Check Point SmartConsole CVE-2026-16232 turns exposed management into firewall takeover risk
Read More

Threat Hunting & Intel|7 min read
Iran-linked PLC attacks show why internet-exposed OT is now an incident-response priority
Read More

vulnerability|6 min read
Check Point CVE-2026-16232 puts firewall management in the blast radius
Read More

vulnerability|7 min read
Windmill CVE-2026-29059 turns log access into a secrets problem
Read More

vulnerability|7 min read
SharePoint CVE-2026-50522 makes patching only the first step
Read More

vulnerability|8 min read
ServiceNow CVE-2026-6875 turns AI workflow platforms into urgent patch targets
Read More

vulnerability|9 min read
7-Zip CVE-2026-14266 turns archive handling into an endpoint patch priority
Read More

vulnerability|9 min read
NGINX CVE-2026-42533 turns a narrow map regex bug into an urgent patch window
Read More

vulnerability|7 min read
SharePoint RCE zero-day forces a July 19 incident-response deadline
Read More

vulnerability|6 min read
wp2shell puts WordPress core in emergency patch mode
Read More

vulnerability|8 min read
Oracle E-Business Suite flaw hits CISA KEV as payment systems face takeover risk
Read More
Follow the research
New vulnerability analysis, threat actor reporting, and supply chain research as we publish it.
Recent Posts
- WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws
- Dropbox breach shows why third-party identity links need zero trust
- CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock
- ServiceNow Critical Flaws Expose Enterprise Workflows
- PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV