Background
Research & Insights

Cyber Security Knowledge Hub

Explore our latest research, insights, and guidance on emerging security threats and best practices

Our Insights

Latest Research Articles

We regularly publish our security findings, guidance, and analysis to help organizations stay ahead of emerging threats.

The WordPress hole we wrote yesterday is already being used
Vulnerability Management Sep 24, 2026

The WordPress hole we wrote yesterday is already being used

CVE-2026-87902 saw attempts the afternoon 7.1.2 shipped. Patchstack says probes now write PHP files. Previdian counted 68 honeypot tries. Last week's 7.1.1 is still open.

Mathew Potter

Security Analyst

Ottawa says the May Roundcube patch is being used. Four months is long enough.
Vulnerability Management Sep 24, 2026

Ottawa says the May Roundcube patch is being used. Four months is long enough.

CVE-2026-48842 is pre-auth SQL injection in virtuser_query. Cyber Centre updated AV26-503. Fixed in 1.6.16 and 1.7.1. If you cannot update, turn the plugin off.

Mathew Potter

Security Analyst

CISA put a ransomware tag on the July TeamCity hole. About 160 boxes are still out there.
Vulnerability Management Sep 24, 2026

CISA put a ransomware tag on the July TeamCity hole. About 160 boxes are still out there.

CVE-2026-63077 is unauthenticated commands on TeamCity On-Premises. Patched July 25 in 2025.11.7 and 2026.1.3. Federal clock was August 8. Cloud is fine. Internet-facing and old is not.

Mathew Potter

Security Analyst

The docs said third-party.com. That name now serves a ClickFix.
Threat Intelligence Sep 24, 2026

The docs said third-party.com. That name now serves a ClickFix.

third-party.com is not a reserved placeholder. Someone registered it and has been serving a Windows ClickFix since June. 1,700 GitHub hits. Use example.com. Flash the GS1900 today.

Mathew Potter

Security Analyst

cPanel says a calendar login is enough to take the whole server
Vulnerability Management Sep 23, 2026

cPanel says a calendar login is enough to take the whole server

CVE-2026-87899 is CalDAV and CardDAV to root. Any hosting account. Shared boxes are the blast. Fixed in 11.134.0.57, 11.136.0.41, 11.138.0.8. WP Toolkit 6.11.3 is a separate package.

Mathew Potter

Security Analyst

F5 says BIG-IP APM is being used if it hands out OAuth tokens
Vulnerability Management Sep 23, 2026

F5 says BIG-IP APM is being used if it hands out OAuth tokens

CVE-2026-94127 is unauthenticated code execution on APM authorization servers. CISA listed it. Due Friday. Closing the management port does not help. Engineering hotfix or F5's iRule.

Mathew Potter

Security Analyst

Previous 1 2 3 Next

Stay Updated

Subscribe to our research newsletter to receive the latest security insights directly in your inbox.

We respect your privacy. Unsubscribe at any time.