Structured data rendered for: graph
INVADERS
Expert Security Insights

Cybersecurity Research & Threat Intelligence

Research active vulnerabilities, cloud and application security, cybercrime, and supply chain risk with practical guidance for defenders.

CVE-2026-5752 turns the Terrarium sandbox into a root-level escape risk

CVE-2026-5752 turns the Terrarium sandbox into a root-level escape risk

CVE-2026-5752 turns the Terrarium sandbox into a root-level escape risk A critical flaw in Terrarium, tracked as CVE-2026-5752, deserves attention well beyond a...

Last updated on 17/08/2026 at 12:56 PM
4 min read
CISA KEV flags Quest KACE SMA auth bypass as a high-priority risk

CISA KEV flags Quest KACE SMA auth bypass as a high-priority risk

CISA KEV flags Quest KACE SMA auth bypass as a high-priority risk CVE-2025-32975 is the kind of issue defenders should triage quickly because it affects a manag...

Last updated on 17/08/2026 at 12:56 PM
5 min read
SGLang CVE-2026-5760 turns malicious GGUF models into RCE

SGLang CVE-2026-5760 turns malicious GGUF models into RCE

SGLang CVE-2026-5760 turns malicious GGUF models into RCE Executive summary A newly disclosed flaw in SGLang means a malicious GGUF model file can become an exe...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Apache ActiveMQ RCE CVE-2026-34197 Lands in CISA KEV

Apache ActiveMQ RCE CVE-2026-34197 Lands in CISA KEV

Apache ActiveMQ RCE CVE-2026-34197 lands in CISA KEV Executive summary CISA has added CVE-2026-34197 to the Known Exploited Vulnerabilities catalog after attack...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Critical protobuf.js flaw turns untrusted schemas into JavaScript code execution

Critical protobuf.js flaw turns untrusted schemas into JavaScript code execution

Critical protobuf.js flaw turns untrusted schemas into JavaScript code execution A newly disclosed protobuf.js issue deserves attention well beyond the JavaScri...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Leaked Windows Defender zero-days are already being used to gain SYSTEM access

Leaked Windows Defender zero-days are already being used to gain SYSTEM access

Leaked Windows Defender zero-days are already being used to gain SYSTEM access A fast-moving Windows story matters to defenders this week for a simple reason: p...

Last updated on 17/08/2026 at 12:56 PM
5 min read
AgingFly campaign hits Ukrainian government and hospital networks

AgingFly campaign hits Ukrainian government and hospital networks

AgingFly campaign hits Ukrainian government and hospital networks A newly reported campaign centered on the AgingFly backdoor is a reminder that targeted intrus...

Last updated on 17/08/2026 at 12:56 PM
5 min read
CVE-2026-33032 in nginx-ui Enables Full Nginx Server Takeover via Unauthenticated MCP Access

CVE-2026-33032 in nginx-ui Enables Full Nginx Server Takeover via Unauthenticated MCP Access

CVE-2026-33032 in nginx-ui Enables Full Nginx Server Takeover via Unauthenticated MCP Access A critical flaw in nginx-ui, the web-based Nginx management tool, c...

Last updated on 15/04/2026 at 8:31 PM
2 min read
Malicious Chrome extensions turn OAuth tokens into enterprise risk

Malicious Chrome extensions turn OAuth tokens into enterprise risk

Malicious Chrome extensions turn OAuth tokens into enterprise risk A newly reported cluster of malicious Chrome Web Store extensions is a useful warning for def...

Last updated on 17/08/2026 at 12:56 PM
5 min read
CVE-2026-5194 weakens wolfSSL certificate trust in embedded deployments

CVE-2026-5194 weakens wolfSSL certificate trust in embedded deployments

CVE-2026-5194 weakens wolfSSL certificate trust in embedded deployments CVE-2026-5194 is a reminder that core cryptographic libraries can create outsized enterp...

Last updated on 17/08/2026 at 12:56 PM
4 min read
Docker AuthZ Plugin Bypass in CVE-2026-34040 Weakens API-Level Container Controls

Docker AuthZ Plugin Bypass in CVE-2026-34040 Weakens API-Level Container Controls

Docker AuthZ Plugin Bypass in CVE-2026-34040 Weakens API-Level Container Controls A newly disclosed Docker Engine and Moby flaw, tracked as CVE-2026-34040, show...

Last updated on 13/04/2026 at 10:06 AM
3 min read
CPUID breach turned CPU-Z and HWMonitor into a malware delivery path

CPUID breach turned CPU-Z and HWMonitor into a malware delivery path

CPUID breach turned CPU-Z and HWMonitor into a malware delivery path Executive summary A compromise of the CPUID website briefly turned trusted download links f...

Last updated on 17/08/2026 at 12:56 PM
5 min read