en
CVE-2026-56164 & CVE-2026-56155: Microsoft's SharePoint and AD FS Zero-Days in the July 622-CVE Patch Tuesday
Deep dive into Microsoft's record 622-CVE Patch Tuesday featuring active SharePoint and Active Directory Federation Services zero-days.
en
Deep dive into Microsoft's record 622-CVE Patch Tuesday featuring active SharePoint and Active Directory Federation Services zero-days.
en
Technical root cause and exploit chain analysis for the maximum-severity SonicWall SMA 1000 zero-day pair.
en
Weekly briefing: SonicWall SMA 1000 zero-day chain, Microsoft 622-CVE Patch Tuesday, Accenture breach, and GhostApproval AI trust flaws.
en
Weekly briefing: Adobe ColdFusion 6x CVSS 10.0 wave, SharePoint Warlock ransomware, and Cursor IDE DuneSlide prompt injection.
en
Cato AI Labs discloses DuneSlide: chaining prompt injection to sandbox escape and remote code execution in Cursor IDE.
en
Technical breakdown of the 18-month unpatched zero-authentication RCE in Argo CD enabling full Kubernetes takeover.
en
CVE-2026-8037 (CVSS 9.6) is a pre-auth OS command injection in Kemp LoadMaster rooted in escape_quotes() heap mishandling. watchTowr published a full PoC June 29; exploitation began the same day.
en
How Storm-2603 weaponized a SharePoint deserialization flaw to deploy Warlock ransomware across enterprise networks.
en
Technical analysis of Adobe's emergency bulletin addressing six simultaneous CVSS 10.0 unauthenticated RCE flaws.
en
Weekly briefing: 630GB Apple/Tesla trade secrets leaked, Klue OAuth Salesforce data theft, Cisco UCM webshells, and Atomic Arch.
en
Investigation into Atomic Arch: over 1,500 Arch Linux AUR packages poisoned with eBPF stealth rootkits and credential grabbers.
en
CISA issues urgent warning over critical CVSS 9.8 code injection in Lantronix industrial serial converters.