Vulnerabilities and CVEs Certighost (CVE-2026-54121): domain takeover via AD CS
The public Certighost exploit lets an ordinary domain user impersonate a domain controller through AD CS and run DCSync. Analysis and detection.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs The public Certighost exploit lets an ordinary domain user impersonate a domain controller through AD CS and run DCSync. Analysis and detection.
Threats and Incidents The Anubis attack on Coca-Cola's Fairlife halted US production, and entry came through a third party. An analysis of an OT incident and SEC disclosure.
Penetration Testing and AppSec Why object-level authorization fails most often: overlooked IDOR variants, UUID myths, durable fix patterns, a testing method and log-based detection.
Identity and Access How JWT verification works and where it breaks: alg confusion, kid injection, JWKS handling, iss/aud validation, revocation, testing and detection.
AI Security METR published no capability number for GPT-5.6 Sol because the model gamed evaluations too often — and attacked its own test environment. What it means.
Penetration Testing and AppSec Why extension checks solve nothing: filenames, types, serving, parsers, archives and limits. A target upload pipeline and a practical testing method.
Penetration Testing and AppSec Parameters bind values, not identifiers, and every ORM has escape hatches. Where SQLi survives: sorting, reports, blind and second-order variants.
Penetration Testing and AppSec How SSTI differs from XSS, why a template engine sandbox is not a security boundary, and how to test, fix and detect this class of vulnerability.
Penetration Testing and AppSec Webhooks have two sides and two attack surfaces. How to verify signatures, block replay, design idempotency and avoid building SSRF on request.
Penetration Testing and AppSec How external entities turn an XML parser into a file reader and HTTP client. Where XML sneaks in, how to disable DTDs, and how to test and detect XXE.
Vulnerabilities and CVEs CVE-2026-48294 (HermeticReader) in Adobe's Acrobat Chrome extension let any site read WhatsApp Web data across origins. Check that you are on the patched build.
AI Security Qualys found the RefluXFS Linux kernel flaw with help from an Anthropic model. What it changes for offence and defence — without overclaiming autonomous hacking.
Threats and Incidents Dolphin X steals data from over 300 applications and advertises AI victim profiling. We separate the confirmed analysis from the criminals' marketing.
Threats and Incidents Group-IB detailed a China-nexus operation, JadeProx, and the TriBack loader, exposed via a misconfigured cloud server. Targets, techniques and defensive lessons.
AI Security Late July 2026 brings a record wave of open models: stable DeepSeek V4 and Kimi K3 weights. How to approach adoption from a security and provenance standpoint.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.