Research blog
Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

Cybercrime|6 min read
JADEPUFFER shows how agentic AI can turn exposed Langflow into ransomware
Read More

vulnerability|5 min read
CitrixBleed-style NetScaler flaw CVE-2026-8451 is already being tested in the wild
Read More

vulnerability|8 min read
SharePoint CVE-2026-45659 active exploitation puts on-prem servers on urgent patch path
Read More

vulnerability|7 min read
Progress Kemp LoadMaster CVE-2026-8037 exploitation moves fast after public PoC
Read More

vulnerability|9 min read
SimpleHelp CVE-2026-48558 exploitation turns RMM into a credential-theft path
Read More

vulnerability|8 min read
Oracle E-Business Suite CVE-2026-46817 is now an active exploitation risk
Read More

vulnerability|7 min read
Actively exploited UniFi OS flaws turn network controllers into root-level targets
Read More

vulnerability|8 min read
CISA's June 28 KEV deadline puts PTC Windchill and Cisco Unified CM on emergency footing
Read More

supply chain attack|8 min read
Mastra npm compromise turns AI agent builds into credential-theft risk
Read More

vulnerability|6 min read
Lantronix EDS5000 exploitation shows why edge device patch windows are shrinking
Read More

vulnerability|5 min read
Gravity SMTP bug turns WordPress email settings into an attacker map
Read More

vulnerability|5 min read
Splunk Enterprise CVE-2026-20253 hits KEV as exploitation begins
Read More
Follow the research
New vulnerability analysis, threat actor reporting, and supply chain research as we publish it.
Recent Posts
- WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws
- Dropbox breach shows why third-party identity links need zero trust
- CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock
- ServiceNow Critical Flaws Expose Enterprise Workflows
- PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV