Cybersecurity Research & Threat Intelligence
Research active vulnerabilities, cloud and application security, cybercrime, and supply chain risk with practical guidance for defenders.
Cybersecurity Research Coverage
Explore the research areas where Invaders publishes recurring analysis, from active exploitation and vulnerability management to cloud risk and supply chain security.
144 articles
Vulnerability Research
Active exploitation, CVEs, patch priorities, and exposure analysis.
36 articles
Threat Hunting & Intelligence
Threat actor activity, detection context, and defensive investigation guidance.
16 articles
Cloud & Application Security
Cloud platforms, web applications, identity, and engineering security risk.
11 articles
Cybercrime
Operational reporting on criminal ecosystems, breaches, and attacker activity.
5 articles
Supply Chain Security
Software delivery, third-party dependencies, and CI/CD trust boundaries.
SharePoint JWT Bypass Turns Patch Delay Into an Identity Risk
SharePoint JWT Bypass Turns Patch Delay Into an Identity Risk Attackers have started targeting a critical Microsoft SharePoint Server authentication bypass afte...
Lucas Oliveira
Research
VMware vCenter RCE exploitation turns syslog exposure into persistence risk
VMware vCenter RCE exploitation turns syslog exposure into persistence risk VMware vCenter administrators should treat CVE-2026-59310 as more than a routine [vu...
Lucas Oliveira
Research
SAP Commerce Cloud CVE-2026-58231 Is a Reminder That Patch Windows Are Now Measured in Days
SAP Commerce Cloud CVE-2026-58231 Is a Reminder That Patch Windows Are Now Measured in Days SAP's August Patch Day shipped a maximum-severity fix for SAP Commer...
Lucas Oliveira
Research
Metabase zero-day turns BI dashboards into a data-exposure path
Metabase zero-day turns BI dashboards into a data-exposure path Metabase has confirmed active exploitation of CVE-2026-72898, a critical unauthenticated [SQL in...
Lucas Oliveira
Research
Swiss SharePoint breach shows why patching alone may not end the incident
Swiss SharePoint breach shows why patching alone may not end the incident Switzerland's federal IT office has confirmed a cyberattack against SharePoint servers...
Lucas Oliveira
Research
Gitea Org-mode flaw turns public repositories into a server file-read risk
Gitea Org-mode flaw turns public repositories into a server file-read risk Gitea administrators have a critical patch to verify. The project has fixed CVE-2026-...
Lucas Oliveira
Research
Active exploitation of TeamCity RCE puts CI/CD control planes on the front line
Active exploitation of TeamCity RCE puts CI/CD control planes on the front line JetBrains TeamCity administrators have a narrow patch window for CVE-2026-63077,...
Lucas Oliveira
Research
ChainDrop shows how npm worms are moving from package compromise to CI/CD takeover
ChainDrop shows how npm worms are moving from package compromise to CI/CD takeover Microsoft Threat Intelligence has published a detailed analysis of ChainDrop,...
Lucas Oliveira
Research
TP-Link Omada ZTP flaws expose the trust chain behind managed networks
TP-Link Omada ZTP flaws expose the trust chain behind managed networks TP-Link has published security advisories for a cluster of vulnerabilities affecting Omad...
Lucas Oliveira
Research
N-able N-central flaw exposes MSP consoles to account takeover
N-able N-central flaw exposes MSP consoles to account takeover N-able has released an emergency hotfix for N-central after confirming active exploitation of an...
Lucas Oliveira
Research
Hugging Face Diffusers flaws turn model loading into a code execution risk
Hugging Face Diffusers flaws turn model loading into a code execution risk Security researchers have disclosed a set of Hugging Face Diffusers vulnerabilities t...
Lucas Oliveira
Research
Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list
Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list Adobe has released an urgent security update for Adobe Campaign Classic a...
Lucas Oliveira
Research











