en
CVE-2026-54121: Certighost and the AD CS Flaw That Lets a Standard Account Impersonate a Domain Controller
How the CertiGhost AD CS vulnerability enables standard domain accounts to forge DC certificates and achieve instant domain takeover.
en
How the CertiGhost AD CS vulnerability enables standard domain accounts to forge DC certificates and achieve instant domain takeover.
en
Weekly briefing: SharePoint deserialization RCE, Oracle PeopleSoft zero-day chain (100+ breaches), EY breach, and Capital One VulnHunter.
en
Case study on Capital One's VulnHunter: autonomous agentic AI scanning codebases and identifying zero-day logic flaws.
en
Technical root cause of the SharePoint deserialization RCE exploited within days of public proof-of-concept release.
en
Wiz Research uncovers GhostApproval: AI coding assistants pre-emptively executing file modifications before user approval prompts.
en
Weekly briefing: SonicWall SMA 1000 zero-day chain, Microsoft 622-CVE Patch Tuesday, Accenture breach, and GhostApproval AI trust flaws.
en
Weekly briefing: Adobe ColdFusion 6x CVSS 10.0 wave, SharePoint Warlock ransomware, and Cursor IDE DuneSlide prompt injection.
en
Cato AI Labs discloses DuneSlide: chaining prompt injection to sandbox escape and remote code execution in Cursor IDE.
en
Technical analysis of Adobe's emergency bulletin addressing six simultaneous CVSS 10.0 unauthenticated RCE flaws.
en
CISA issues urgent warning over critical CVSS 9.8 code injection in Lantronix industrial serial converters.
en
Technical root cause for the unauthenticated OS command injection vulnerability in Fortinet FortiSandbox appliances.
en
Technical analysis of the Chrome V8 out-of-bounds read/write memory corruption zero-day exploited in targeted surveillance campaigns.