Structured data rendered for: graph
INVADERS
Expert Security Insights

Cybersecurity Research & Threat Intelligence

Research active vulnerabilities, cloud and application security, cybercrime, and supply chain risk with practical guidance for defenders.

ConsentFix v3 turns Azure OAuth phishing into a scalable token theft risk

ConsentFix v3 turns Azure OAuth phishing into a scalable token theft risk

ConsentFix v3 turns Azure OAuth phishing into a scalable token theft risk ConsentFix v3 matters because it shifts Azure account compromise away from password th...

Last updated on 17/08/2026 at 12:56 PM
5 min read
BlackCat case shows ransomware risk inside trusted cyber roles

BlackCat case shows ransomware risk inside trusted cyber roles

BlackCat case shows ransomware risk inside trusted cyber roles A new U.S. criminal case tied to BlackCat (ALPHV) is a sharp reminder that ransomware risk is not...

Last updated on 17/08/2026 at 12:56 PM
5 min read
PyTorch Lightning supply-chain compromise puts AI developer credentials at risk

PyTorch Lightning supply-chain compromise puts AI developer credentials at risk

PyTorch Lightning supply-chain compromise puts AI developer credentials at risk The most dangerous supply-chain incidents are not always the ones that hit opera...

Last updated on 17/08/2026 at 12:56 PM
5 min read
CVE-2026-31431: Copy Fail turns routine Linux access into reliable root compromise

CVE-2026-31431: Copy Fail turns routine Linux access into reliable root compromise

CVE-2026-31431: Copy Fail turns routine Linux access into reliable root compromise Copy Fail is the kind of Linux flaw defenders should not shrug off just becau...

Last updated on 17/08/2026 at 12:56 PM
6 min read
CVE-2026-41940 turns exposed cPanel and WHM servers into control-plane takeover targets

CVE-2026-41940 turns exposed cPanel and WHM servers into control-plane takeover targets

CVE-2026-41940 turns exposed cPanel and WHM servers into control-plane takeover targets CVE-2026-41940 is a critical authentication bypass in cPanel and WHM, an...

Last updated on 17/08/2026 at 12:56 PM
5 min read
CVE-2026-42208 turns exposed LiteLLM gateways into a secrets exposure risk

CVE-2026-42208 turns exposed LiteLLM gateways into a secrets exposure risk

CVE-2026-42208 turns exposed LiteLLM gateways into a secrets exposure risk CVE-2026-42208 is a critical SQL injection flaw in LiteLLM's proxy API key verificati...

Last updated on 17/08/2026 at 12:56 PM
5 min read
GlassWorm sleeper extensions turn Open VSX updates into a malware delivery path

GlassWorm sleeper extensions turn Open VSX updates into a malware delivery path

GlassWorm sleeper extensions turn Open VSX updates into a malware delivery path The newest GlassWorm wave matters because it turns the normal extension update p...

Last updated on 17/08/2026 at 12:56 PM
5 min read
CVE-2026-33032 lets attackers take over exposed nginx-ui servers

CVE-2026-33032 lets attackers take over exposed nginx-ui servers

CVE-2026-33032 lets attackers take over exposed nginx-ui servers CVE-2026-33032 is the kind of [vulnerability](https://invaders.ie/resources/glossary/vulnerabil...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Firestarter leaves patched Cisco firewalls at continued risk

Firestarter leaves patched Cisco firewalls at continued risk

Firestarter leaves patched Cisco firewalls at continued risk A newly detailed persistence mechanism called Firestarter changes the defender story around last ye...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Pack2TheRoot flaw puts Linux systems with PackageKit on a local root path

Pack2TheRoot flaw puts Linux systems with PackageKit on a local root path

Pack2TheRoot flaw puts Linux systems with PackageKit on a local root path The newly disclosed Pack2TheRoot issue, tracked as CVE-2026-41651, is a strong reminde...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Bitwarden CLI npm compromise exposes CI/CD credential risk

Bitwarden CLI npm compromise exposes CI/CD credential risk

Bitwarden CLI npm compromise exposes CI/CD credential risk A brief compromise of the Bitwarden CLI npm distribution is still a high-priority defender story beca...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Lovable Incident Raises Cross-Tenant Data Exposure Concerns for AI Development Platforms

Lovable Incident Raises Cross-Tenant Data Exposure Concerns for AI Development Platforms

Lovable Incident Raises Cross-Tenant Data Exposure Concerns for AI Development Platforms Lovable, an AI platform used to build and iterate software projects, is...

Last updated on 23/04/2026 at 9:12 AM
2 min read