Research blog
Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

vulnerability|7 min read
FortiSandbox command injection flaws move from patch queue to exploited risk
Read More

vulnerability|8 min read
Firefox and Chrome fixes turn browser patching into this week's urgent control
Read More

vulnerability|7 min read
Exploited SonicWall SMA zero-days put remote access gateways on the clock
Read More

vulnerability|9 min read
Exploited Joomla extension flaws turn file uploads into emergency patch work
Read More

vulnerability|8 min read
BeyondTrust auth bypass flaws put remote support appliances on the urgent patch list
Read More

vulnerability|7 min read
Gitea Docker flaw turns a trusted proxy header into account takeover
Read More

vulnerability|8 min read
U-Boot FIT signature flaws expose a fragile pre-OS trust boundary
Read More

vulnerability|7 min read
Microsoft Defender RoguePlanet fix closes a SYSTEM-level escalation path
Read More

vulnerability|8 min read
Unpatched Tenda router backdoor turns home gateways into a trust problem
Read More

vulnerability|7 min read
CISA's July KEV batch puts Joomla page builders and Langflow on emergency patch lists
Read More

vulnerability|6 min read
Adobe ColdFusion CVE-2026-48282 moves from patch advisory to active exploitation
Read More

Cybercrime|7 min read
Vect and TeamPCP show how stolen build secrets become ransomware access
Read More
Follow the research
New vulnerability analysis, threat actor reporting, and supply chain research as we publish it.
Recent Posts
- WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws
- Dropbox breach shows why third-party identity links need zero trust
- CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock
- ServiceNow Critical Flaws Expose Enterprise Workflows
- PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV