Section

Cybersecurity

Deep coverage of cybersecurity — benchmarks, launches and the long-form analysis we wish we had.

18 articles

Showing 9 of 18

Metabase Zero-Day (CVE-2026-72898): CVSS 10.0 SQL Injection Exploited in the Wild
01Cybersecurity

Metabase Zero-Day (CVE-2026-72898): CVSS 10.0 SQL Injection Exploited in the Wild

CVE-2026-72898 is a CVSS 10.0 unauthenticated SQL injection in Metabase's password-reset endpoint, exploited in the wild to hand attackers admin access. Patch to a fixed release now, or block the endpoint.

WAWaqas Ahmed Waseer7 min read
ShinyHunters Turned OAuth Consent Into a Master Key: The 2026 Salesforce Breach Wave
02Cybersecurity

ShinyHunters Turned OAuth Consent Into a Master Key: The 2026 Salesforce Breach Wave

In July 2026 Microsoft detailed how ShinyHunters breached hundreds of Salesforce tenants through OAuth consent phishing, not stolen passwords. Here's how the ShinyHunters Salesforce OAuth campaign worked, who it hit, and how to defend your own SaaS stack.

WAWaqas Ahmed Waseer6 min read
SimpleHelp CVE-2026-48558: Max-Severity Auth Bypass Dropping Djinn Stealer Through MSPs. Patch to 5.5.16 Now
03Cybersecurity

SimpleHelp CVE-2026-48558: Max-Severity Auth Bypass Dropping Djinn Stealer Through MSPs. Patch to 5.5.16 Now

SimpleHelp CVE-2026-48558 is a CVSS 10.0 auth bypass on CISA's KEV list, already dropping Djinn Stealer via MSPs. Patch to 5.5.16 or 6.0 RC2 now.

WAWaqas Ahmed Waseer7 min read
Certighost (CVE-2026-54121): The AD CS Flaw That Lets Any Domain User Take Over Your Domain
04Cybersecurity

Certighost (CVE-2026-54121): The AD CS Flaw That Lets Any Domain User Take Over Your Domain

Certighost (CVE-2026-54121) is a critical AD CS flaw, CVSS 8.8, that lets any low-privileged domain user impersonate a Domain Controller and seize the whole domain. Patched July 14; a working exploit went public July 24. Patch now.

WAWaqas Ahmed Waseer7 min read
wp2shell (CVE-2026-63030): A WordPress Core Pre-Auth RCE, and What to Do Now
05Cybersecurity

wp2shell (CVE-2026-63030): A WordPress Core Pre-Auth RCE, and What to Do Now

wp2shell (CVE-2026-63030 + CVE-2026-60137) is a pre-authentication RCE in WordPress Core, already exploited in the wild. Here's who is affected, how the exploit chain works, how to patch, and how to check whether your server was already compromised.

WAWaqas Ahmed Waseer8 min read
New Langflow RCE (CVE-2026-10134) Is a Perfect 10 — Patch Now and Rotate Your Keys
06Cybersecurity

New Langflow RCE (CVE-2026-10134) Is a Perfect 10 — Patch Now and Rotate Your Keys

CVE-2026-10134 is a CVSS 10.0 unauthenticated RCE in Langflow (versions 1.0.0 through 1.9.3) that lets attackers read every secret on the server. Here is the flaw, the pattern behind Langflow's 2026 RCEs, and how to patch.

WAWaqas Ahmed Waseer8 min read
SharePoint Zero-Day CVE-2026-58644: Patch Now and Rotate Your Machine Keys
07Cybersecurity

SharePoint Zero-Day CVE-2026-58644: Patch Now and Rotate Your Machine Keys

SharePoint CVE-2026-58644 is a CVSS 9.8 remote-code-execution zero-day already exploited in the wild. CISA gave federal agencies until July 19, 2026 to patch on-prem SharePoint Server — and rotating your IIS machine keys matters as much as the patch.

WAWaqas Ahmed Waseer6 min read
Adobe ColdFusion CVE-2026-48282: A Max-Severity (CVSS 10) Bug Already Under Attack — Patch Now
08Cybersecurity

Adobe ColdFusion CVE-2026-48282: A Max-Severity (CVSS 10) Bug Already Under Attack — Patch Now

CVE-2026-48282 is a CVSS 10.0 path-traversal flaw in Adobe ColdFusion that lets an unauthenticated attacker run code over the network. Adobe patched it June 30, 2026; it's already exploited and on CISA's KEV list. Here's what it is and how to respond.

WAWaqas Ahmed Waseer6 min read
Januscape (CVE-2026-53359): a 16-Year-Old KVM Flaw Lets VMs Escape the Host
09Cybersecurity

Januscape (CVE-2026-53359): a 16-Year-Old KVM Flaw Lets VMs Escape the Host

Januscape (CVE-2026-53359) is a 16-year-old use-after-free in Linux KVM's shadow MMU that lets a guest VM escape to the host on Intel and AMD. Here's how the flaw works, who's exposed, and the patched kernel versions to deploy now.

WAWaqas Ahmed Waseer7 min read