Research blog
Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

supply chain attack|6 min read
GitHub breach forces GHES signing-key rotation
Read More

vulnerability|7 min read
One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens
Read More

vulnerability|7 min read
FlagLeft Turns Microsoft 365 Android Apps Into a Silent Account Takeover Path
Read More

Threat Hunting & Intel|7 min read
LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure
Read More

vulnerability|5 min read
Drupal PostgreSQL SQLi shows how SELECT-only injection becomes RCE
Read More

vulnerability|5 min read
Unfixed Gogs flaw can turn pull requests into server-side RCE
Read More

vulnerability|5 min read
Palo Alto GlobalProtect auth bypass turns cookie trust into VPN access risk
Read More

vulnerability|5 min read
FortiClient EMS exploit turns endpoint management into credential theft at scale
Read More

Threat Hunting & Intel|6 min read
GlassWorm takedown shows how developer malware becomes supply-chain risk
Read More

Supply Chain Security|6 min read
GitHub GHES Signing Key Rotation Puts Admins on the Clock
Read More

Threat Hunting & Intel|7 min read
AI-Assisted Search Poisoning Fuels ScreenConnect Cryptojacking
Read More

vulnerability|5 min read
CVE-2026-48172 puts LiteSpeed cPanel deployments on a KEV deadline
Read More
Follow the research
New vulnerability analysis, threat actor reporting, and supply chain research as we publish it.
Recent Posts
- WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws
- Dropbox breach shows why third-party identity links need zero trust
- CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock
- ServiceNow Critical Flaws Expose Enterprise Workflows
- PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV