Report an Incident Become a Partner Careers Contact
Book a Demo
From our SOC

Threat Research

Detections our analysts wrote and threats they pulled apart — published as we find them, not to a content calendar.

Threat Research

Brevo Supply Chain Attack: One API Key, 100,000 Websites

A hardcoded Cloudflare API key let attackers rewrite Brevo's scripts at the edge, pushing ClickFix and a hidden WordPress backdoor to around 100,000 sites.

19 Sept 2026 8 min
Threat Research

Plugin4Shell: A Zero-Click RCE In Four AI Coding Agents

Four AI coding agents checked out a pinned commit without verifying it landed. A branch named like the hash delivers malicious code, and the pin still looks intact.

18 Sept 2026 7 min
Threat Research

Crystal PDF Malicious Installer Campaign

A fake PDF editor pushed through Google Ads and SEO poisoning, stealing browser credentials and session tokens. Full IOCs, a KQL hunting query, and how to respond.

20 Apr 2026 9 min
Threat Research

WhatsApp Android Zero-Click Media Exploit

A Project Zero disclosure showing how group trust and automatic media download combine to place attacker-controlled files on an Android device with no interaction at all.

14 Apr 2026 8 min
Threat Research

Hunting For CVE-2025-59287 Exploitation In Windows Server Update Services (WSUS)

CVE-2025-59287 is a critical deserialisation flaw in WSUS. How exploitation looks in practice, and how to hunt for it with behavioural indicators rather than static signatures.

10 Feb 2026 8 min
Threat Research

CVE-2025-55241 – Azure Entra Elevation Of Privilege Via Actor Token Vulnerability

A flaw in Entra ID meant any user account could be escalated to Global Administrator. Patched before disclosure — and still the most instructive Entra bug of the year.

24 Sept 2025 6 min
Threat Research

ToolShell Exploits: Inside CVE-2025-53770 And CVE-2025-53771's Critical Threat To SharePoint

Two chained SharePoint flaws giving unauthenticated remote code execution — and both are patch bypasses. Affected versions, attacker tradecraft, IOCs and what to do now.

4 Aug 2025 10 min
Threat Research

From ClickFix To FileFix: A New Frontier In Social Engineering Attacks

ClickFix persuaded users to run commands themselves. FileFix does the same through File Explorer — no download, no Mark-of-the-Web, and almost nothing to distinguish it from normal work.

7 Jul 2025 7 min
Threat Research

Massive Password Leak: Investigating The Alleged 16 Billion Credential Breach

Headlines claimed the largest credential compilation in history. Our threat intelligence team investigated, and the reality is less dramatic and more persistent than the number suggests.

25 Jun 2025 7 min
Threat Research

Dumping System Secrets While EDR Is Running

Blocking the obvious tool is not the same as preventing the technique. Why SAM, SYSTEM and SECURITY remain reachable with EDR running, and what actually detects it.

23 Sept 2024 8 min
Threat Research

Weaponizing Screen Savers: A Deep Dive Into SCR File Exploitation

A .scr file is nominally a screen saver and actually a Windows executable. Why that distinction is an attack vector, why detection struggles with it, and how to shut it down.

27 Aug 2024 8 min
Threat Research

COM Hijacking: Enhancing Red Team Persistence Strategies

A fileless persistence technique that needs no admin rights and leaves almost no forensic trace. How COM hijacking works, why it is hard to see, and the registry telemetry that catches it.

26 Mar 2024 8 min
Threat Research

Escaping a Docker Container: An Attacker's Perspective

A container is not a security boundary by default. How an over-privileged container becomes a host compromise, which capabilities actually matter, and how to detect and prevent it.

5 Feb 2024 9 min