Structured data rendered for: graph
INVADERS

Research blog

Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

RSS
Russian Zimbra Campaign Turns Email Preview Into an Exfiltration Path

Threat Hunting & Intel|7 min read

Russian Zimbra Campaign Turns Email Preview Into an Exfiltration Path

Read More
Check Point SmartConsole CVE-2026-16232 turns exposed management into firewall takeover risk

vulnerability|8 min read

Check Point SmartConsole CVE-2026-16232 turns exposed management into firewall takeover risk

Read More
Iran-linked PLC attacks show why internet-exposed OT is now an incident-response priority

Threat Hunting & Intel|7 min read

Iran-linked PLC attacks show why internet-exposed OT is now an incident-response priority

Read More
Check Point CVE-2026-16232 puts firewall management in the blast radius

vulnerability|6 min read

Check Point CVE-2026-16232 puts firewall management in the blast radius

Read More
Windmill CVE-2026-29059 turns log access into a secrets problem

vulnerability|7 min read

Windmill CVE-2026-29059 turns log access into a secrets problem

Read More
SharePoint CVE-2026-50522 makes patching only the first step

vulnerability|7 min read

SharePoint CVE-2026-50522 makes patching only the first step

Read More
ServiceNow CVE-2026-6875 turns AI workflow platforms into urgent patch targets

vulnerability|8 min read

ServiceNow CVE-2026-6875 turns AI workflow platforms into urgent patch targets

Read More
7-Zip CVE-2026-14266 turns archive handling into an endpoint patch priority

vulnerability|9 min read

7-Zip CVE-2026-14266 turns archive handling into an endpoint patch priority

Read More
NGINX CVE-2026-42533 turns a narrow map regex bug into an urgent patch window

vulnerability|9 min read

NGINX CVE-2026-42533 turns a narrow map regex bug into an urgent patch window

Read More
SharePoint RCE zero-day forces a July 19 incident-response deadline

vulnerability|7 min read

SharePoint RCE zero-day forces a July 19 incident-response deadline

Read More
wp2shell puts WordPress core in emergency patch mode

vulnerability|6 min read

wp2shell puts WordPress core in emergency patch mode

Read More
Oracle E-Business Suite flaw hits CISA KEV as payment systems face takeover risk

vulnerability|8 min read

Oracle E-Business Suite flaw hits CISA KEV as payment systems face takeover risk

Read More