Cybersecurity Research & Threat Intelligence
Research active vulnerabilities, cloud and application security, cybercrime, and supply chain risk with practical guidance for defenders.
Cybersecurity Research Coverage
Explore the research areas where Invaders publishes recurring analysis, from active exploitation and vulnerability management to cloud risk and supply chain security.
144 articles
Vulnerability Research
Active exploitation, CVEs, patch priorities, and exposure analysis.
36 articles
Threat Hunting & Intelligence
Threat actor activity, detection context, and defensive investigation guidance.
16 articles
Cloud & Application Security
Cloud platforms, web applications, identity, and engineering security risk.
11 articles
Cybercrime
Operational reporting on criminal ecosystems, breaches, and attacker activity.
5 articles
Supply Chain Security
Software delivery, third-party dependencies, and CI/CD trust boundaries.
Palo Alto GlobalProtect auth bypass turns cookie trust into VPN access risk
Palo Alto GlobalProtect auth bypass turns cookie trust into VPN access risk CVE-2026-0257 matters because it turns a trust shortcut on the VPN edge into an iden...
Lucas Oliveira
Research
FortiClient EMS exploit turns endpoint management into credential theft at scale
FortiClient EMS exploit turns endpoint management into credential theft at scale CVE-2026-35616 matters because it breaks a security assumption many teams quiet...
Lucas Oliveira
Research
GlassWorm takedown shows how developer malware becomes supply-chain risk
GlassWorm takedown shows how developer malware becomes supply-chain risk Executive Summary The coordinated disruption of GlassWorm on May 26, 2026 is useful bec...
Lucas Oliveira
Research
GitHub GHES Signing Key Rotation Puts Admins on the Clock
GitHub GHES Signing Key Rotation Puts Admins on the Clock Executive Summary GitHub warned on May 26, 2026 that administrators running GitHub Enterprise Server (...
Lucas Oliveira
Research
AI-Assisted Search Poisoning Fuels ScreenConnect Cryptojacking
AI-Assisted Search Poisoning Fuels ScreenConnect Cryptojacking Executive Summary Microsoft disclosed an active campaign on May 26, 2026 in which attackers push...
Lucas Oliveira
Research
CVE-2026-48172 puts LiteSpeed cPanel deployments on a KEV deadline
CVE-2026-48172 puts LiteSpeed cPanel deployments on a KEV deadline CVE-2026-48172 has escalated from vendor emergency to federal patching priority. On May 26, 2...
Lucas Oliveira
Research
CVE-2026-9082 makes Drupal on PostgreSQL an urgent KEV patch priority
CVE-2026-9082 makes Drupal on PostgreSQL an urgent KEV patch priority CVE-2026-9082 is no longer just a critical Drupal patch note. It is now an actively target...
Lucas Oliveira
Research
Microsoft MDASH surfaces 16 Windows network flaws defenders should patch first
Microsoft MDASH surfaces 16 Windows network flaws defenders should patch first Microsoft's May 12, 2026 security disclosures included a point that deserves more...
Lucas Oliveira
Research
CVE-2024-12802 leaves SonicWall Gen6 VPNs exposed after incomplete patching
CVE-2024-12802 leaves SonicWall Gen6 VPNs exposed after incomplete patching CVE-2024-12802 is the kind of edge-device flaw that can fool defenders twice: once d...
Lucas Oliveira
Research
CVE-2026-45829: ChromaDB Pre-Auth RCE Risk in AI Stacks
CVE-2026-45829: ChromaDB Pre-Auth RCE Risk in AI Stacks | 2026 Executive Summary CVE-2026-45829 is a critical ChromaDB flaw that can let unauthenticated attacke...
Lucas Oliveira
Research
CVE-2026-41615: Microsoft Authenticator Token Theft Risk
CVE-2026-41615: Microsoft Authenticator Token Theft Risk | 2026 Executive Summary CVE-2026-41615 is a critical Microsoft Authenticator flaw that can expose ente...
Lucas Oliveira
Research
GitHub Action tag hijack turns CI/CD runs into credential theft
GitHub Action tag hijack turns CI/CD runs into credential theft A fresh GitHub Actions supply chain incident is a good reminder that "pinned" does not mean safe...
Lucas Oliveira
Research











