Research blog
Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

vulnerability|5 min read
Check Point hotfixes actively exploited IKEv1 VPN bypass
Read More

vulnerability|5 min read
Cisco patches another SD-WAN zero-day after limited exploitation
Read More

vulnerability|5 min read
YellowKey fix lands in June baseline: patch BitLocker fleets now
Read More

vulnerability|6 min read
PAN-OS GlobalProtect auth bypass is now an incident response problem
Read More

supply chain attack|6 min read
Red Hat npm compromise proves provenance alone is not enough
Read More

vulnerability|5 min read
Exchange CVE-2026-42897 patches land after active OWA exploitation
Read More

vulnerability|3 min read
Veeam CVE-2026-44963 puts domain-joined backup servers at RCE risk
Read More

Threat Hunting & Intel|7 min read
Oracle PeopleSoft alert follows breach claims at 100+ organizations
Read More

vulnerability|3 min read
Chrome Zero-Day CVE-2026-11645 Enters KEV After Google Ships Emergency V8 Patch
Read More

vulnerability|5 min read
Cisco CUCM SSRF bug turns WebDialer exposure into a path toward root
Read More

Cloud & Application Security|5 min read
CVE-2026-45247: Mirasvit Cache Warmer RCE Threatens Magento Stores
Read More

vulnerability|6 min read
Cisco SD-WAN zero-day turns earlier auth bypass flaws into root access risk
Read More
Follow the research
New vulnerability analysis, threat actor reporting, and supply chain research as we publish it.
Recent Posts
- WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws
- Dropbox breach shows why third-party identity links need zero trust
- CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock
- ServiceNow Critical Flaws Expose Enterprise Workflows
- PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV