Security Articles

Daily threat intelligence and vulnerability analysis from our security team. We publish expert breakdowns of critical CVEs, active exploits, and emerging attack campaigns as they happen.

Our analysts monitor vendor advisories, CISA alerts, and underground threat activity to give you actionable guidance you can use the same day. Filter by severity below to find what matters most to your environment.

Updated July 26, 2026 — 168 published advisories, with new analysis most weekdays. Recent coverage includes the PTC Windchill FlexPLM remote code execution flaw under Clop exploitation, a Zimbra webmail cross-site scripting campaign stealing two-factor codes, Check Point SmartConsole CVE-2026-16232, the SharePoint machine-key remote code execution chain (CVE-2026-50522), and a ServiceNow AI Platform remote code execution bug. If one of these touches a system you run and you are not sure what to do next, our 24/7 staffed security operations center handles the triage for you.

Severity: All Critical High Medium Low
7 articles found
Featured Story
critical
May 29, 2026
criticalCVE AdvisoryVulnerability

CRITICAL: FortiClient EMS Bug CVE-2026-35616 Weaponized to Push EKZ Infostealer Across Managed Fleets

Threat actors are abusing CVE-2026-35616, a CVSS 9.1 pre-authentication API bypass in FortiClient EMS, to hijack endpoint management consoles and push the newly identified EKZ infostealer to every managed endpoint disguised as FortiEndpoint_Patch.exe. Patch to 7.4.7 immediately and hunt for indicators in EMS logs and on managed hosts.

By Danny MercerRead Full Article
critical
CVE AdvisoryVulnerabilityApr 25, 2026

CRITICAL: FIRESTARTER Backdoor Survives Cisco Firewall Patches in ArcaneDoor Federal Breach

CISA and the UK NCSC went public with a joint advisory on FIRESTARTER, a stealth implant tied to the UAT-4356 ArcaneDoor crew that survived firmware updates and security patches on a Cisco Firepower device inside a federal civilian agency. The malware chains CVE-2025-20333 (CVSS 9.9) and CVE-2025-20362 to gain root on Cisco ASA and FTD appliances, then hooks LINA and persists through reboots until a hard power cycle is performed.

Read more

Is Your Mobile App Secure?

Our CyberOne MobileAssess platform performs deep static analysis, source code decompilation, and runtime security testing for iOS and Android apps. From one-time assessments to year-long continuous testing, we find what surface-level scanners miss.

Stay Informed

Subscribe to our newsletter and get the latest security insights delivered to your inbox.