Cybersecurity Research & Threat Intelligence
Research active vulnerabilities, cloud and application security, cybercrime, and supply chain risk with practical guidance for defenders.
Cybersecurity Research Coverage
Explore the research areas where Invaders publishes recurring analysis, from active exploitation and vulnerability management to cloud risk and supply chain security.
144 articles
Vulnerability Research
Active exploitation, CVEs, patch priorities, and exposure analysis.
36 articles
Threat Hunting & Intelligence
Threat actor activity, detection context, and defensive investigation guidance.
16 articles
Cloud & Application Security
Cloud platforms, web applications, identity, and engineering security risk.
11 articles
Cybercrime
Operational reporting on criminal ecosystems, breaches, and attacker activity.
5 articles
Supply Chain Security
Software delivery, third-party dependencies, and CI/CD trust boundaries.
CISA's June 28 KEV deadline puts PTC Windchill and Cisco Unified CM on emergency footing
CISA's June 28 KEV deadline puts PTC Windchill and Cisco Unified CM on emergency footing CISA's latest Known Exploited Vulnerabilities update has turned Sunday,...
Lucas Oliveira
Research
Mastra npm compromise turns AI agent builds into credential-theft risk
Mastra npm compromise turns AI agent builds into credential-theft risk The Mastra npm incident is a sharp warning for teams building AI agents: dependency compr...
Lucas Oliveira
Research
Lantronix EDS5000 exploitation shows why edge device patch windows are shrinking
Lantronix EDS5000 exploitation shows why edge device patch windows are shrinking CISA has added CVE-2025-67038 to its Known Exploited Vulnerabilities catalog af...
Lucas Oliveira
Research
Gravity SMTP bug turns WordPress email settings into an attacker map
Gravity SMTP bug turns WordPress email settings into an attacker map Attackers are actively exploiting CVE-2026-4020, a Gravity SMTP [vulnerability](https://inv...
Lucas Oliveira
Research
Splunk Enterprise CVE-2026-20253 hits KEV as exploitation begins
Splunk Enterprise CVE-2026-20253 hits KEV as exploitation begins Splunk's June 18, 2026 advisory update changed CVE-2026-20253 from a patch-now issue into an ac...
Lucas Oliveira
Research
Joomla JCE exploitation forces defenders beyond simple patching
Joomla JCE exploitation forces defenders beyond simple patching On Friday, June 19, 2026, defenders running Joomla sites with the JCE editor are at a deadline,...
Lucas Oliveira
Research
Check Point hotfixes actively exploited IKEv1 VPN bypass
Check Point hotfixes actively exploited IKEv1 VPN bypass CVE-2026-50751 is the kind of security flaw that punishes organizations for leaving legacy remote-acces...
Lucas Oliveira
Research
Cisco patches another SD-WAN zero-day after limited exploitation
Cisco patches another SD-WAN zero-day after limited exploitation Cisco has disclosed yet another actively exploited weakness in its SD-WAN stack, and the import...
Lucas Oliveira
Research
YellowKey fix lands in June baseline: patch BitLocker fleets now
YellowKey fix lands in June baseline: patch BitLocker fleets now Microsoft has now closed the patch gap for CVE-2026-45585, the public BitLocker bypass widely r...
Lucas Oliveira
Research
PAN-OS GlobalProtect auth bypass is now an incident response problem
PAN-OS GlobalProtect auth bypass is now an incident response problem Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, an authentication by...
Lucas Oliveira
Research
Red Hat npm compromise proves provenance alone is not enough
Red Hat npm compromise proves provenance alone is not enough Red Hat has confirmed that multiple packages published under the @redhat-cloud-services npm namespa...
Lucas Oliveira
Research
Exchange CVE-2026-42897 patches land after active OWA exploitation
Exchange CVE-2026-42897 patches land after active OWA exploitation Microsoft has now shipped the June 2026 Exchange security updates for CVE-2026-42897, ending...
Lucas Oliveira
Research











