en
CVE-2026-41091 & CVE-2026-45498: Microsoft Defender Zero-Days Under Active Exploitation
Technical root cause for the dual Microsoft Defender zero-days exploited to evade AV scanning and achieve privilege escalation.
en
Technical root cause for the dual Microsoft Defender zero-days exploited to evade AV scanning and achieve privilege escalation.
en
How nation-state threat group UAT-8616 weaponized a Cisco SD-WAN authentication bypass to compromise enterprise transit hubs.
en
Investigation into how TeamPCP used a poisoned VS Code Marketplace extension to pivot into developer workstations and exfiltrate 3,800 GitHub repositories.
en
How threat actors are actively weaponizing an unpatched stored XSS zero-day in Microsoft Exchange OWA to hijack mailbox session tokens.
en
How the Mini Shai-Hulud attack poisoned TanStack npm packages and bypassed SLSA Level 3 build provenance guarantees.
Security Roundup
Weekly briefing: PAN-OS auth portal buffer overflow (root RCE), RubyGems 500+ malicious packages, and SHADOW-EARTH-053 espionage.
CVE Deep Dive
Technical exploit walkthrough of the Linux kernel Netfilter use-after-free vulnerability enabling local root privilege escalation.
Threat Intel
In-depth threat intelligence report on SHADOW-EARTH-053 deploying ShadowPad, Godzilla webshells, and long-term espionage tradecraft.
CVE Deep Dive
Technical root cause and remediation for the unauthenticated administrative RCE flaw in Ivanti EPMM mobile device management systems.
Supply Chain
How campaign BufferZoneCorp flooded RubyGems with over 500 malicious packages using typosquatting and GemStuffer payload obfuscation.
CVE Deep Dive
Technical analysis of the CVSS 10.0 PAN-OS authentication portal buffer overflow granting unauthenticated remote root access.
Security Tools
Secretly is a free open-source Slack bot that detects and masks API keys, database credentials, and private tokens in real time before they leak.