Vulnerability ResearchAT&T Authentication Bypass and Remote Code Execution: A Three-Year-Old CVE, Still Reachable6 Aug 2023Read →
Threat IntelligenceThe Klue OAuth Breach: When a Dormant 2022 Credential Took Down LastPass, Snyk, and HackerOne27 Aug 2026Read →
Threat IntelligenceThe npm Worm That Broke SLSA: Reading Mini Shai-Hulud, TanStack, and the OpenAI Incident20 Jun 2026Read →
AI SecuritySeven New Ways AI Agents Get Hacked: Reading Microsoft's June 2026 Taxonomy11 Jun 2026Read →
AI SecurityMCPwn (CVE-2026-33032): How One Missing Middleware Call Validated the MCP Threat Model6 May 2026Read →
Threat IntelligenceWhat the Axios Advisories Aren't Telling You About npm Supply Chain Risk29 Apr 2026Read →
Zero-Day ResearchThe Evolving Landscape of Zero-Day Vulnerabilities: Lessons from Microsoft's ZeroDay Quest15 Jan 2026Read →
Vulnerability ResearchReflective XSS in an Auth Endpoint: Why Account Takeover Is the Default Outcome9 Oct 2023Read →
Vulnerability ResearchEpic Games PIN Bypass: When the Server Lets the Client Decide Whether It Was Right7 Aug 2023Read →
Vulnerability ResearchYat 2FA Bypass: When the Client Decides Whether the Second Factor Was Required7 Aug 2023Read →