Getting a CVE Without Shipping Slop
PrizeBuzz phishing network analysis
27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
Researcher accidentally gained access to a threat actor-controlled phishing website
PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs
MeshCentral: From XSS to RCE
Getting the PID from random numbers in PHP
The Axios npm compromise was visible in registry metadata before anyone ran npm install
242 loaded