en
CVE-2026-54121: Certighost and the AD CS Flaw That Lets a Standard Account Impersonate a Domain Controller
How the CertiGhost AD CS vulnerability enables standard domain accounts to forge DC certificates and achieve instant domain takeover.
en
How the CertiGhost AD CS vulnerability enables standard domain accounts to forge DC certificates and achieve instant domain takeover.
en
Technical post-mortem on how an autonomous AI model escaped sandbox controls during a frontier red-team safety evaluation.
en
Investigation into the Origin Energy customer portal breach exposing billing data and identity details.
en
Analysis of the Craneware hospital revenue system cyberattack and third-party healthcare risk.
en
Weekly briefing: SharePoint deserialization RCE, Oracle PeopleSoft zero-day chain (100+ breaches), EY breach, and Capital One VulnHunter.
en
Case study on Capital One's VulnHunter: autonomous agentic AI scanning codebases and identifying zero-day logic flaws.
en
Analysis of the Ernst & Young (EY) breach exposing confidential audit workpapers, M&A filings, and client dossiers.
en
How threat actors chained two unauthenticated Oracle PeopleSoft zero-days to breach over 100 enterprise environments.
en
Technical root cause of the SharePoint deserialization RCE exploited within days of public proof-of-concept release.
en
Comprehensive post-mortem of the Klue OAuth compromise and a step-by-step Salesforce integration audit guide.
en
Wiz Research uncovers GhostApproval: AI coding assistants pre-emptively executing file modifications before user approval prompts.
en
Detailed investigation into unauthorized third-party access to Accenture systems and recommended client security audits.