Structured data rendered for: graph
INVADERS
Expert Security Insights

Cybersecurity Research & Threat Intelligence

Research active vulnerabilities, cloud and application security, cybercrime, and supply chain risk with practical guidance for defenders.

Microsoft Defender RoguePlanet fix closes a SYSTEM-level escalation path

Microsoft Defender RoguePlanet fix closes a SYSTEM-level escalation path

Microsoft Defender RoguePlanet fix closes a SYSTEM-level escalation path Microsoft has released a fix for CVE-2026-50656, the Microsoft Defender vulnerability p...

Last updated on 17/08/2026 at 12:56 PM
7 min read
Unpatched Tenda router backdoor turns home gateways into a trust problem

Unpatched Tenda router backdoor turns home gateways into a trust problem

Unpatched Tenda router backdoor turns home gateways into a trust problem CERT/CC has disclosed an undocumented authentication backdoor in several Tenda router f...

Last updated on 17/08/2026 at 12:56 PM
8 min read
CISA's July KEV batch puts Joomla page builders and Langflow on emergency patch lists

CISA's July KEV batch puts Joomla page builders and Langflow on emergency patch lists

CISA's July KEV batch puts Joomla page builders and Langflow on emergency patch lists CISA added three vulnerabilities to its Known Exploited Vulnerabilities ca...

Last updated on 08/07/2026 at 8:06 AM
7 min read
Adobe ColdFusion CVE-2026-48282 moves from patch advisory to active exploitation

Adobe ColdFusion CVE-2026-48282 moves from patch advisory to active exploitation

Adobe ColdFusion CVE-2026-48282 moves from patch advisory to active exploitation Adobe ColdFusion administrators have a narrow patch window for CVE-2026-48282,...

Last updated on 07/07/2026 at 8:06 AM
6 min read
Vect and TeamPCP show how stolen build secrets become ransomware access

Vect and TeamPCP show how stolen build secrets become ransomware access

Vect and TeamPCP show how stolen build secrets become ransomware access Sophos says two cybercrime groups, Vect and TeamPCP, have formalized a partnership that...

Last updated on 05/07/2026 at 8:07 AM
7 min read
JADEPUFFER shows how agentic AI can turn exposed Langflow into ransomware

JADEPUFFER shows how agentic AI can turn exposed Langflow into ransomware

JADEPUFFER shows how agentic AI can turn exposed Langflow into ransomware Sysdig has documented what it assesses as one of the first clear examples of agentic r...

Last updated on 04/07/2026 at 7:47 PM
6 min read
CitrixBleed-style NetScaler flaw CVE-2026-8451 is already being tested in the wild

CitrixBleed-style NetScaler flaw CVE-2026-8451 is already being tested in the wild

CitrixBleed-style NetScaler flaw CVE-2026-8451 is already being tested in the wild Citrix NetScaler administrators have another edge-appliance exposure to triag...

Last updated on 04/07/2026 at 8:04 AM
5 min read
SharePoint CVE-2026-45659 active exploitation puts on-prem servers on urgent patch path

SharePoint CVE-2026-45659 active exploitation puts on-prem servers on urgent patch path

SharePoint CVE-2026-45659 active exploitation puts on-prem servers on urgent patch path Microsoft SharePoint Server is back in the active-exploitation lane. CIS...

Last updated on 17/08/2026 at 12:56 PM
8 min read
Progress Kemp LoadMaster CVE-2026-8037 exploitation moves fast after public PoC

Progress Kemp LoadMaster CVE-2026-8037 exploitation moves fast after public PoC

Progress Kemp LoadMaster CVE-2026-8037 exploitation moves fast after public PoC Progress Kemp LoadMaster appliances are now in the familiar danger zone for edge...

Last updated on 17/08/2026 at 12:56 PM
7 min read
SimpleHelp CVE-2026-48558 exploitation turns RMM into a credential-theft path

SimpleHelp CVE-2026-48558 exploitation turns RMM into a credential-theft path

SimpleHelp CVE-2026-48558 exploitation turns RMM into a credential-theft path SimpleHelp has moved from patched vulnerability to active intrusion path. Attacker...

Last updated on 17/08/2026 at 12:56 PM
9 min read
Oracle E-Business Suite CVE-2026-46817 is now an active exploitation risk

Oracle E-Business Suite CVE-2026-46817 is now an active exploitation risk

Oracle E-Business Suite CVE-2026-46817 is now an active exploitation risk Oracle E-Business Suite has another critical exposure that defenders should move out o...

Last updated on 17/08/2026 at 12:56 PM
8 min read
Actively exploited UniFi OS flaws turn network controllers into root-level targets

Actively exploited UniFi OS flaws turn network controllers into root-level targets

Actively exploited UniFi OS flaws turn network controllers into root-level targets CISA has added three Ubiquiti UniFi OS vulnerabilities to its Known Exploited...

Last updated on 17/08/2026 at 12:56 PM
7 min read