Structured data rendered for: graph
INVADERS
Expert Security Insights

Cybersecurity Research & Threat Intelligence

Research active vulnerabilities, cloud and application security, cybercrime, and supply chain risk with practical guidance for defenders.

SharePoint JWT Bypass Turns Patch Delay Into an Identity Risk

SharePoint JWT Bypass Turns Patch Delay Into an Identity Risk

SharePoint JWT Bypass Turns Patch Delay Into an Identity Risk Attackers have started targeting a critical Microsoft SharePoint Server authentication bypass afte...

Last updated on 17/08/2026 at 1:02 PM
6 min read
VMware vCenter RCE exploitation turns syslog exposure into persistence risk

VMware vCenter RCE exploitation turns syslog exposure into persistence risk

VMware vCenter RCE exploitation turns syslog exposure into persistence risk VMware vCenter administrators should treat CVE-2026-59310 as more than a routine [vu...

Last updated on 16/08/2026 at 2:19 PM
6 min read
SAP Commerce Cloud CVE-2026-58231 Is a Reminder That Patch Windows Are Now Measured in Days

SAP Commerce Cloud CVE-2026-58231 Is a Reminder That Patch Windows Are Now Measured in Days

SAP Commerce Cloud CVE-2026-58231 Is a Reminder That Patch Windows Are Now Measured in Days SAP's August Patch Day shipped a maximum-severity fix for SAP Commer...

Last updated on 16/08/2026 at 8:05 AM
6 min read
Metabase zero-day turns BI dashboards into a data-exposure path

Metabase zero-day turns BI dashboards into a data-exposure path

Metabase zero-day turns BI dashboards into a data-exposure path Metabase has confirmed active exploitation of CVE-2026-72898, a critical unauthenticated [SQL in...

Last updated on 15/08/2026 at 1:46 PM
6 min read
Swiss SharePoint breach shows why patching alone may not end the incident

Swiss SharePoint breach shows why patching alone may not end the incident

Swiss SharePoint breach shows why patching alone may not end the incident Switzerland's federal IT office has confirmed a cyberattack against SharePoint servers...

Last updated on 09/08/2026 at 8:07 AM
6 min read
Gitea Org-mode flaw turns public repositories into a server file-read risk

Gitea Org-mode flaw turns public repositories into a server file-read risk

Gitea Org-mode flaw turns public repositories into a server file-read risk Gitea administrators have a critical patch to verify. The project has fixed CVE-2026-...

Last updated on 08/08/2026 at 8:06 AM
6 min read
Active exploitation of TeamCity RCE puts CI/CD control planes on the front line

Active exploitation of TeamCity RCE puts CI/CD control planes on the front line

Active exploitation of TeamCity RCE puts CI/CD control planes on the front line JetBrains TeamCity administrators have a narrow patch window for CVE-2026-63077,...

Last updated on 16/08/2026 at 11:21 AM
6 min read
ChainDrop shows how npm worms are moving from package compromise to CI/CD takeover

ChainDrop shows how npm worms are moving from package compromise to CI/CD takeover

ChainDrop shows how npm worms are moving from package compromise to CI/CD takeover Microsoft Threat Intelligence has published a detailed analysis of ChainDrop,...

Last updated on 16/08/2026 at 11:21 AM
7 min read
TP-Link Omada ZTP flaws expose the trust chain behind managed networks

TP-Link Omada ZTP flaws expose the trust chain behind managed networks

TP-Link Omada ZTP flaws expose the trust chain behind managed networks TP-Link has published security advisories for a cluster of vulnerabilities affecting Omad...

Last updated on 16/08/2026 at 11:21 AM
7 min read
N-able N-central flaw exposes MSP consoles to account takeover

N-able N-central flaw exposes MSP consoles to account takeover

N-able N-central flaw exposes MSP consoles to account takeover N-able has released an emergency hotfix for N-central after confirming active exploitation of an...

Last updated on 16/08/2026 at 11:21 AM
5 min read
Hugging Face Diffusers flaws turn model loading into a code execution risk

Hugging Face Diffusers flaws turn model loading into a code execution risk

Hugging Face Diffusers flaws turn model loading into a code execution risk Security researchers have disclosed a set of Hugging Face Diffusers vulnerabilities t...

Last updated on 03/08/2026 at 8:05 AM
6 min read
Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list

Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list

Adobe Campaign Classic flaws put on-prem marketing systems on the emergency patch list Adobe has released an urgent security update for Adobe Campaign Classic a...

Last updated on 02/08/2026 at 8:06 AM
5 min read