Cybersecurity Research & Threat Intelligence
Research active vulnerabilities, cloud and application security, cybercrime, and supply chain risk with practical guidance for defenders.
Cybersecurity Research Coverage
Explore the research areas where Invaders publishes recurring analysis, from active exploitation and vulnerability management to cloud risk and supply chain security.
144 articles
Vulnerability Research
Active exploitation, CVEs, patch priorities, and exposure analysis.
36 articles
Threat Hunting & Intelligence
Threat actor activity, detection context, and defensive investigation guidance.
16 articles
Cloud & Application Security
Cloud platforms, web applications, identity, and engineering security risk.
11 articles
Cybercrime
Operational reporting on criminal ecosystems, breaches, and attacker activity.
5 articles
Supply Chain Security
Software delivery, third-party dependencies, and CI/CD trust boundaries.
cPanel CVE-2026-65643 turns domain parking into a root-control risk
cPanel CVE-2026-65643 turns domain parking into a root-control risk cPanel has disclosed CVE-2026-65643, a critical [vulnerability](https://invaders.ie/resource...
Lucas Oliveira
Research
Next.js Critical RCE Fixes Put Self-Hosted Apps on a Short Patch Clock
Next.js Critical RCE Fixes Put Self-Hosted Apps on a Short Patch Clock The August 2026 Next.js security release is not a routine framework bump. It fixes two cr...
Lucas Oliveira
Research
Gitea CVE-2026-60004: Patch Self-Hosted Git Before RCE Becomes an Incident
Gitea CVE-2026-60004: Patch Self-Hosted Git Before RCE Becomes an Incident Self-hosted source control is rarely treated like an internet-facing edge appliance,...
Lucas Oliveira
Research
CISA Adds Oracle WebLogic Proxy Plug-in Flaw to KEV as Exploitation Pressure Rises
CISA Adds Oracle WebLogic Proxy Plug-in Flaw to KEV as Exploitation Pressure Rises CISA has added CVE-2026-21962, a maximum-severity Oracle HTTP Server and Orac...
Lucas Oliveira
Research
TrueConf KEV Flaws: When a Video Server Becomes a Malware Distribution Point
TrueConf KEV Flaws: When a Video Server Becomes a Malware Distribution Point CISA has added two exploited TrueConf Server vulnerabilities to its Known Exploited...
Lucas Oliveira
Research
Microsoft Entra ID CVSS 10 RCE is a trust-plane warning
Microsoft Entra ID CVSS 10 RCE is a trust-plane warning Security teams should treat CVE-2026-69836 as a serious [vulnerability](https://invaders.ie/resources/gl...
Lucas Oliveira
Research
CISA Warns of Active Exploitation in Zimbra Collaboration Suite
CISA Warns of Active Exploitation in Zimbra Collaboration Suite CISA has added CVE-2026-73570, an operating-system command injection flaw in Zimbra Collaboratio...
Lucas Oliveira
Research
CVE-2026-24301: Microsoft Copilot CoSnitch Data Exposure
CVE-2026-24301: Microsoft Copilot CoSnitch Data Exposure CVE-2026-24301 is a newly published Microsoft Copilot vulnerability that turns a familiar enterprise ri...
Lucas Oliveira
Research
CVE-2026-33824: Windows IKE RCE Active Exploit Patch Guide
CVE-2026-33824: Windows IKE RCE Active Exploit Patch Guide | 2026 Executive Summary Since August 18, 2026, the critical CVE-2026-33824 vulnerability in Microsof...
Lucas Oliveira
Research
GitLab ships critical GraphQL patch for self-managed instances
GitLab ships critical GraphQL patch for self-managed instances GitLab has released an out-of-band security update for Community Edition and Enterprise Edition a...
Lucas Oliveira
Research
macOS Screen Sharing CVE-2026-65400 exploited to gain root and deploy Monero miners
macOS Screen Sharing CVE-2026-65400 exploited to gain root and deploy Monero miners Executive Summary Threat actors are exploiting CVE-2026-65400, a recently pa...
Lucas Oliveira
Research










