Cybersecurity Research & Threat Intelligence
Research active vulnerabilities, cloud and application security, cybercrime, and supply chain risk with practical guidance for defenders.
Cybersecurity Research Coverage
Explore the research areas where Invaders publishes recurring analysis, from active exploitation and vulnerability management to cloud risk and supply chain security.
144 articles
Vulnerability Research
Active exploitation, CVEs, patch priorities, and exposure analysis.
36 articles
Threat Hunting & Intelligence
Threat actor activity, detection context, and defensive investigation guidance.
16 articles
Cloud & Application Security
Cloud platforms, web applications, identity, and engineering security risk.
11 articles
Cybercrime
Operational reporting on criminal ecosystems, breaches, and attacker activity.
5 articles
Supply Chain Security
Software delivery, third-party dependencies, and CI/CD trust boundaries.
Veeam CVE-2026-44963 puts domain-joined backup servers at RCE risk
Veeam CVE-2026-44963 puts domain-joined backup servers at RCE risk Veeam has patched CVE-2026-44963, a critical [vulnerability](https://invaders.ie/resources/gl...
Lucas Oliveira
Research
Oracle PeopleSoft alert follows breach claims at 100+ organizations
Oracle PeopleSoft alert follows breach claims at 100+ organizations Claims of mass compromise across Oracle PeopleSoft environments were already serious on June...
Lucas Oliveira
Research
Chrome Zero-Day CVE-2026-11645 Enters KEV After Google Ships Emergency V8 Patch
Chrome Zero-Day CVE-2026-11645 Enters KEV After Google Ships Emergency V8 Patch Google has patched an actively exploited [zero-day](https://invaders.ie/resource...
Lucas Oliveira
Research
Cisco CUCM SSRF bug turns WebDialer exposure into a path toward root
Cisco CUCM SSRF bug turns WebDialer exposure into a path toward root Cisco's latest Unified Communications Manager advisory deserves attention because it turns...
Lucas Oliveira
Research
CVE-2026-45247: Mirasvit Cache Warmer RCE Threatens Magento Stores
CVE-2026-45247: Mirasvit Cache Warmer RCE Threatens Magento Stores Executive Summary CVE-2026-45247 is a critical [vulnerability](https://invaders.ie/resources/...
Lucas Oliveira
Research
Cisco SD-WAN zero-day turns earlier auth bypass flaws into root access risk
Cisco SD-WAN zero-day turns earlier auth bypass flaws into root access risk Cisco's new CVE-2026-20245 advisory matters because it is not just another isolated...
Lucas Oliveira
Research
GitHub breach forces GHES signing-key rotation
GitHub breach forces GHES signing-key rotation | 2026 GitHub's May 2026 incident is a useful reminder that developer tooling is now part of the production trust...
Lucas Oliveira
Research
One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens
One-Click github.dev Attack Lets Malicious Repos Steal Full GitHub Tokens | 2026 Executive Summary Security researcher Ammar Askar disclosed a one-click attack...
Lucas Oliveira
Research
FlagLeft Turns Microsoft 365 Android Apps Into a Silent Account Takeover Path
FlagLeft Turns Microsoft 365 Android Apps Into a Silent Account Takeover Path | 2026 Executive Summary Enclave disclosed a research finding it calls FlagLeft, d...
Lucas Oliveira
Research
LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure
LLMShare Turns Trusted AI Domains Into Malware Delivery Infrastructure | 2026 Executive Summary Push Security disclosed a live campaign it tracks as LLMShare, w...
Lucas Oliveira
Research
Drupal PostgreSQL SQLi shows how SELECT-only injection becomes RCE
Drupal PostgreSQL SQLi shows how SELECT-only injection becomes RCE Lexfo's May 26, 2026 write-up on CVE-2026-9082 matters because it breaks a common defensive a...
Lucas Oliveira
Research
Unfixed Gogs flaw can turn pull requests into server-side RCE
Unfixed Gogs flaw can turn pull requests into server-side RCE A newly disclosed Gogs bug matters because it blurs the line between "authenticated" and "practica...
Lucas Oliveira
Research











