en
CVE-2026-41091 & CVE-2026-45498: Microsoft Defender Zero-Days Under Active Exploitation
Technical root cause for the dual Microsoft Defender zero-days exploited to evade AV scanning and achieve privilege escalation.
en
Technical root cause for the dual Microsoft Defender zero-days exploited to evade AV scanning and achieve privilege escalation.
en
How nation-state threat group UAT-8616 weaponized a Cisco SD-WAN authentication bypass to compromise enterprise transit hubs.
en
Investigation into how TeamPCP used a poisoned VS Code Marketplace extension to pivot into developer workstations and exfiltrate 3,800 GitHub repositories.
en
How threat actors are actively weaponizing an unpatched stored XSS zero-day in Microsoft Exchange OWA to hijack mailbox session tokens.
en
How the Mini Shai-Hulud attack poisoned TanStack npm packages and bypassed SLSA Level 3 build provenance guarantees.