Structured data rendered for: graph
INVADERS
Expert Security Insights

Cybersecurity Research & Threat Intelligence

Research active vulnerabilities, cloud and application security, cybercrime, and supply chain risk with practical guidance for defenders.

CISA's June 28 KEV deadline puts PTC Windchill and Cisco Unified CM on emergency footing

CISA's June 28 KEV deadline puts PTC Windchill and Cisco Unified CM on emergency footing

CISA's June 28 KEV deadline puts PTC Windchill and Cisco Unified CM on emergency footing CISA's latest Known Exploited Vulnerabilities update has turned Sunday,...

Last updated on 17/08/2026 at 12:56 PM
8 min read
Mastra npm compromise turns AI agent builds into credential-theft risk

Mastra npm compromise turns AI agent builds into credential-theft risk

Mastra npm compromise turns AI agent builds into credential-theft risk The Mastra npm incident is a sharp warning for teams building AI agents: dependency compr...

Last updated on 17/08/2026 at 12:56 PM
8 min read
Lantronix EDS5000 exploitation shows why edge device patch windows are shrinking

Lantronix EDS5000 exploitation shows why edge device patch windows are shrinking

Lantronix EDS5000 exploitation shows why edge device patch windows are shrinking CISA has added CVE-2025-67038 to its Known Exploited Vulnerabilities catalog af...

Last updated on 17/08/2026 at 12:56 PM
6 min read
Gravity SMTP bug turns WordPress email settings into an attacker map

Gravity SMTP bug turns WordPress email settings into an attacker map

Gravity SMTP bug turns WordPress email settings into an attacker map Attackers are actively exploiting CVE-2026-4020, a Gravity SMTP [vulnerability](https://inv...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Splunk Enterprise CVE-2026-20253 hits KEV as exploitation begins

Splunk Enterprise CVE-2026-20253 hits KEV as exploitation begins

Splunk Enterprise CVE-2026-20253 hits KEV as exploitation begins Splunk's June 18, 2026 advisory update changed CVE-2026-20253 from a patch-now issue into an ac...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Joomla JCE exploitation forces defenders beyond simple patching

Joomla JCE exploitation forces defenders beyond simple patching

Joomla JCE exploitation forces defenders beyond simple patching On Friday, June 19, 2026, defenders running Joomla sites with the JCE editor are at a deadline,...

Last updated on 17/08/2026 at 12:56 PM
6 min read
Check Point hotfixes actively exploited IKEv1 VPN bypass

Check Point hotfixes actively exploited IKEv1 VPN bypass

Check Point hotfixes actively exploited IKEv1 VPN bypass CVE-2026-50751 is the kind of security flaw that punishes organizations for leaving legacy remote-acces...

Last updated on 17/06/2026 at 8:07 AM
5 min read
Cisco patches another SD-WAN zero-day after limited exploitation

Cisco patches another SD-WAN zero-day after limited exploitation

Cisco patches another SD-WAN zero-day after limited exploitation Cisco has disclosed yet another actively exploited weakness in its SD-WAN stack, and the import...

Last updated on 16/06/2026 at 8:05 AM
5 min read
YellowKey fix lands in June baseline: patch BitLocker fleets now

YellowKey fix lands in June baseline: patch BitLocker fleets now

YellowKey fix lands in June baseline: patch BitLocker fleets now Microsoft has now closed the patch gap for CVE-2026-45585, the public BitLocker bypass widely r...

Last updated on 17/08/2026 at 12:56 PM
5 min read
PAN-OS GlobalProtect auth bypass is now an incident response problem

PAN-OS GlobalProtect auth bypass is now an incident response problem

PAN-OS GlobalProtect auth bypass is now an incident response problem Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, an authentication by...

Last updated on 17/08/2026 at 12:56 PM
6 min read
Red Hat npm compromise proves provenance alone is not enough

Red Hat npm compromise proves provenance alone is not enough

Red Hat npm compromise proves provenance alone is not enough Red Hat has confirmed that multiple packages published under the @redhat-cloud-services npm namespa...

Last updated on 17/08/2026 at 12:56 PM
6 min read
Exchange CVE-2026-42897 patches land after active OWA exploitation

Exchange CVE-2026-42897 patches land after active OWA exploitation

Exchange CVE-2026-42897 patches land after active OWA exploitation Microsoft has now shipped the June 2026 Exchange security updates for CVE-2026-42897, ending...

Last updated on 17/08/2026 at 12:56 PM
5 min read