Threat Research
Detections our analysts wrote and threats they pulled apart — published as we find them, not to a content calendar.
Threat Research
Brevo Supply Chain Attack: One API Key, 100,000 Websites
A hardcoded Cloudflare API key let attackers rewrite Brevo's scripts at the edge, pushing ClickFix and a hidden WordPress backdoor to around 100,000 sites.
Threat Research
Plugin4Shell: A Zero-Click RCE In Four AI Coding Agents
Four AI coding agents checked out a pinned commit without verifying it landed. A branch named like the hash delivers malicious code, and the pin still looks intact.
Threat Research
Crystal PDF Malicious Installer Campaign
A fake PDF editor pushed through Google Ads and SEO poisoning, stealing browser credentials and session tokens. Full IOCs, a KQL hunting query, and how to respond.
Threat Research
WhatsApp Android Zero-Click Media Exploit
A Project Zero disclosure showing how group trust and automatic media download combine to place attacker-controlled files on an Android device with no interaction at all.
Threat Research
Hunting For CVE-2025-59287 Exploitation In Windows Server Update Services (WSUS)
CVE-2025-59287 is a critical deserialisation flaw in WSUS. How exploitation looks in practice, and how to hunt for it with behavioural indicators rather than static signatures.
Threat Research
CVE-2025-55241 – Azure Entra Elevation Of Privilege Via Actor Token Vulnerability
A flaw in Entra ID meant any user account could be escalated to Global Administrator. Patched before disclosure — and still the most instructive Entra bug of the year.
Threat Research
ToolShell Exploits: Inside CVE-2025-53770 And CVE-2025-53771's Critical Threat To SharePoint
Two chained SharePoint flaws giving unauthenticated remote code execution — and both are patch bypasses. Affected versions, attacker tradecraft, IOCs and what to do now.
Threat Research
From ClickFix To FileFix: A New Frontier In Social Engineering Attacks
ClickFix persuaded users to run commands themselves. FileFix does the same through File Explorer — no download, no Mark-of-the-Web, and almost nothing to distinguish it from normal work.
Threat Research
Massive Password Leak: Investigating The Alleged 16 Billion Credential Breach
Headlines claimed the largest credential compilation in history. Our threat intelligence team investigated, and the reality is less dramatic and more persistent than the number suggests.
Threat Research
Dumping System Secrets While EDR Is Running
Blocking the obvious tool is not the same as preventing the technique. Why SAM, SYSTEM and SECURITY remain reachable with EDR running, and what actually detects it.
Threat Research
Weaponizing Screen Savers: A Deep Dive Into SCR File Exploitation
A .scr file is nominally a screen saver and actually a Windows executable. Why that distinction is an attack vector, why detection struggles with it, and how to shut it down.
Threat Research
COM Hijacking: Enhancing Red Team Persistence Strategies
A fileless persistence technique that needs no admin rights and leaves almost no forensic trace. How COM hijacking works, why it is hard to see, and the registry telemetry that catches it.
Threat Research
Escaping a Docker Container: An Attacker's Perspective
A container is not a security boundary by default. How an over-privileged container becomes a host compromise, which capabilities actually matter, and how to detect and prevent it.
Nothing matches that.