Structured data rendered for: graph
INVADERS

Research blog

Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

RSS
FortiSandbox command injection flaws move from patch queue to exploited risk

vulnerability|7 min read

FortiSandbox command injection flaws move from patch queue to exploited risk

Read More
Firefox and Chrome fixes turn browser patching into this week's urgent control

vulnerability|8 min read

Firefox and Chrome fixes turn browser patching into this week's urgent control

Read More
Exploited SonicWall SMA zero-days put remote access gateways on the clock

vulnerability|7 min read

Exploited SonicWall SMA zero-days put remote access gateways on the clock

Read More
Exploited Joomla extension flaws turn file uploads into emergency patch work

vulnerability|9 min read

Exploited Joomla extension flaws turn file uploads into emergency patch work

Read More
BeyondTrust auth bypass flaws put remote support appliances on the urgent patch list

vulnerability|8 min read

BeyondTrust auth bypass flaws put remote support appliances on the urgent patch list

Read More
Gitea Docker flaw turns a trusted proxy header into account takeover

vulnerability|7 min read

Gitea Docker flaw turns a trusted proxy header into account takeover

Read More
U-Boot FIT signature flaws expose a fragile pre-OS trust boundary

vulnerability|8 min read

U-Boot FIT signature flaws expose a fragile pre-OS trust boundary

Read More
Microsoft Defender RoguePlanet fix closes a SYSTEM-level escalation path

vulnerability|7 min read

Microsoft Defender RoguePlanet fix closes a SYSTEM-level escalation path

Read More
Unpatched Tenda router backdoor turns home gateways into a trust problem

vulnerability|8 min read

Unpatched Tenda router backdoor turns home gateways into a trust problem

Read More
CISA's July KEV batch puts Joomla page builders and Langflow on emergency patch lists

vulnerability|7 min read

CISA's July KEV batch puts Joomla page builders and Langflow on emergency patch lists

Read More
Adobe ColdFusion CVE-2026-48282 moves from patch advisory to active exploitation

vulnerability|6 min read

Adobe ColdFusion CVE-2026-48282 moves from patch advisory to active exploitation

Read More
Vect and TeamPCP show how stolen build secrets become ransomware access

Cybercrime|7 min read

Vect and TeamPCP show how stolen build secrets become ransomware access

Read More