Research blog
Vulnerability research, threat hunting, cloud and application security, cybercrime, and supply chain risk.

vulnerability|5 min read
CVE-2026-9082 makes Drupal on PostgreSQL an urgent KEV patch priority
Read More

vulnerability|7 min read
Microsoft MDASH surfaces 16 Windows network flaws defenders should patch first
Read More

vulnerability|6 min read
CVE-2024-12802 leaves SonicWall Gen6 VPNs exposed after incomplete patching
Read More

Cloud & Application Security|7 min read
CVE-2026-45829: ChromaDB Pre-Auth RCE Risk in AI Stacks
Read More

vulnerability|5 min read
CVE-2026-41615: Microsoft Authenticator Token Theft Risk
Read More

supply chain attack|6 min read
GitHub Action tag hijack turns CI/CD runs into credential theft
Read More

vulnerability|6 min read
CVE-2026-42945 makes NGINX rewrite chains a live patch priority
Read More

Threat Hunting & Intel|5 min read
Kazuar’s redesign turns a familiar backdoor into a harder-to-hunt botnet
Read More

vulnerability|5 min read
CVE-2026-42897 makes on-prem Exchange an immediate mitigation priority
Read More

vulnerability|6 min read
CVE-2026-20182 makes Cisco SD-WAN controllers an urgent KEV priority
Read More

vulnerability|5 min read
Exim BDAT flaw makes mail servers urgent RCE patch targets
Read More

Cloud & Application Security|5 min read
LiteLLM SQL injection flaw puts AI gateways on the front line
Read More
Follow the research
New vulnerability analysis, threat actor reporting, and supply chain research as we publish it.
Recent Posts
- WordPress Site Owners Face Mass Exploitation of Super Forms and Elementor Pro Upload Flaws
- Dropbox breach shows why third-party identity links need zero trust
- CISA's New KEV Additions Put Edge and AI Control Planes on a Short Patch Clock
- ServiceNow Critical Flaws Expose Enterprise Workflows
- PaperCut NG/MF zero-day chain: CISA adds actively exploited flaws to KEV