Cl0p Turns PTC Windchill Exploitation Into a Purpose-Built Extortion Platform Product lifecycle management systems are not usually the first asset class defende...
Lucas Oliveira
Research
Metabase zero-day turns BI dashboards into a data-exposure path Metabase has confirmed active exploitation of CVE-2026-72898, a critical unauthenticated [SQL in...
Lucas Oliveira
Research
Swiss SharePoint breach shows why patching alone may not end the incident Switzerland's federal IT office has confirmed a cyberattack against SharePoint servers...
Lucas Oliveira
Research
Windmill CVE-2026-29059 turns log access into a secrets problem Attackers are now exploiting CVE-2026-29059, a Windmill path traversal flaw that lets unauthenti...
Lucas Oliveira
Research
Vect and TeamPCP show how stolen build secrets become ransomware access Sophos says two cybercrime groups, Vect and TeamPCP, have formalized a partnership that...
Lucas Oliveira
Research
JADEPUFFER shows how agentic AI can turn exposed Langflow into ransomware Sysdig has documented what it assesses as one of the first clear examples of agentic r...
Lucas Oliveira
Research
SimpleHelp CVE-2026-48558 exploitation turns RMM into a credential-theft path SimpleHelp has moved from patched vulnerability to active intrusion path. Attacker...
Lucas Oliveira
Research
Mastra npm compromise turns AI agent builds into credential-theft risk The Mastra npm incident is a sharp warning for teams building AI agents: dependency compr...
Lucas Oliveira
Research
Red Hat npm compromise proves provenance alone is not enough Red Hat has confirmed that multiple packages published under the @redhat-cloud-services npm namespa...
Lucas Oliveira
Research
One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens | 2026 Executive Summary Security researcher Ammar Askar disclosed a one-click attack...
Lucas Oliveira
Research
LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure | 2026 Executive Summary Push Security disclosed a live campaign it tracks as LLMShare, w...
Lucas Oliveira
Research
FortiClient EMS exploit turns endpoint management into credential theft at scale CVE-2026-35616 matters because it breaks a security assumption many teams quiet...
Lucas Oliveira
Research