Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Cavern (Cav3rn) C2: Detecting DNS Tunneling and Google Apps Script Abuse by Iranian APT Operators
Cavern C2 Blends Into Legitimate Traffic — and Your Perimeter Won't Notice Kaspersky's ongoing tracking of the Cavern (aka Cav3rn) command-a...
Hugging Face Supply-Chain Attack & PHANTOM-B: Threat Modeling Lessons for Defending AI/ML Pipelines
Introduction When Adam Shostack — arguably the most authoritative voice in threat modeling alive — says he was "blown away" by an attack dis...
Snowflake GitHub Actions Workflow Injection: Defending Against Crafted-Issue Command Injection in CI/CD Pipelines
Snowflake GitHub Actions Workflow Injection: What Defenders Need to Know Security researchers at Wiz disclosed a GitHub Actions workflow inj...
LiteLLM Supply-Chain Attack (SANDCLOCK/TeamPCP): Credential Exposure Across 2,000+ Repos — Detection and Remediation Guide
Introduction The compromise of LiteLLM — the widely adopted open-source LLM proxy and gateway — is shaping up to be one of the most conseque...
CVE-2026-15748: Critical Forminator WordPress RCE — Detection, Hunting, and Remediation Guide
CVE-2026-15748: Critical Forminator WordPress RCE — Detection, Hunting, and Remediation Guide A critical vulnerability has been disclosed in...
CVE-2026-75110: MemOS AI Agent Authentication Bypass (CVSS 9.8) — Detection and Remediation Guide
CVE-2026-75110: When "Authentication Enabled" Still Means Wide Open NVD has published CVE-2026-75110, a CVSS 9.8 (Critical) vulnerability in...
CVE-2026-18432: Critical Privilege Escalation in WordPress Frontend Admin Plugin — Detection and Remediation Guide
What Happened NVD has published CVE-2026-18432, a CVSS 9.8 (Critical) vulnerability in the Frontend Admin by DynamiApps plugin for WordPress...
CVE-2026-16098: Critical Unauthenticated File Upload in ProSolution WP Client — Detection, Hunting, and Remediation Guide
Introduction On the surface, this is another WordPress plugin vulnerability — but CVE-2026-16098 is the kind defenders lose sleep over. NVD ...
Blind Eagle (APT-C-36) Evolving Toolkit: AsyncRAT, njRAT & LimeRAT Campaign Targeting Colombian Finance — OTX Detection Pack
Blind Eagle (APT-C-36) Evolving Toolkit: AsyncRAT, njRAT & LimeRAT Campaign Targeting Colombian Finance Threat Summary Open threat exchange ...