en
CVE-2026-26980: Ghost CMS SQL Injection Actively Exploited to Hijack 700+ Sites for ClickFix Attacks
Technical breakdown of the Ghost CMS SQL injection exploited at scale to inject fake browser update (ClickFix) malware into 700+ websites.
en
Technical breakdown of the Ghost CMS SQL injection exploited at scale to inject fake browser update (ClickFix) malware into 700+ websites.
en
How campaign Megalodon weaponized infostealer-harvested developer secrets to backdoor 5,561 GitHub repositories in automated CI runs.
en
Technical breakdown of CopyFail, Dirty Frag, and Fragnesia: how three page-cache memory flaws enabled unprivileged local root escalation in the Linux kernel.
en
Weekly briefing: Microsoft Exchange OWA zero-day XSS, TeamPCP GitHub breach (3.8K repos), Cisco SD-WAN UAT-8616, and Defender zero-days.
en
Technical root cause for the dual Microsoft Defender zero-days exploited to evade AV scanning and achieve privilege escalation.
en
How nation-state threat group UAT-8616 weaponized a Cisco SD-WAN authentication bypass to compromise enterprise transit hubs.
en
Investigation into how TeamPCP used a poisoned VS Code Marketplace extension to pivot into developer workstations and exfiltrate 3,800 GitHub repositories.
en
How threat actors are actively weaponizing an unpatched stored XSS zero-day in Microsoft Exchange OWA to hijack mailbox session tokens.
en
How the Mini Shai-Hulud attack poisoned TanStack npm packages and bypassed SLSA Level 3 build provenance guarantees.