Blog
CVE breakdowns, hands-on security research, and training insights.
2026-10-04 · CVE-2026-104286
CVE-2026-104286: A NULL Byte, a Path Traversal, and No Patch Yet
An unauthenticated path traversal in FortiMail's webmail interface lets attackers write files to disk at will — and Fortinet hasn't shipped a fix for every branch yet.
2026-10-01 · CVE-2026-88771
CVE-2026-88771 + CVE-2026-88772: A 1-Byte Lie in a DTLS Header, and Root on Your VPN Gateway
Two unauthenticated Citrix NetScaler zero-days — one a command-injection bypass, one a DTLS buffer overflow — chained into pre-auth RCE on internet-facing VPN gateways.
2026-09-28 · CVE-2026-65660
CVE-2026-65660: The SharePoint Bug That Was Mislabeled 'Spoofing' Until It Wasn't
A SharePoint code-injection flaw shipped as a 6.5 spoofing bug, then landed on CISA's KEV list six weeks later as actively exploited RCE.
2026-09-22 · CVE-2026-81963
CVE-2026-81963: The 7.8 Bug Microsoft Patched While Attackers Were Already Using It
A Windows Update Stack privilege-escalation bug scored well below this month's headline CVEs — and was already on CISA's exploited list before the patch shipped.
2026-09-19 · CVE-2026-69730
CVE-2026-69730: An Unauthenticated 9.8 in the Service Every Domain Controller Runs
A use-after-free in Windows DNS Server lets an attacker send one packet and get code execution — on the box that also runs your domain controller.
2026-09-10 · CVE-2026-79696
CVE-2026-79696: The First Real Agent-on-Agent Exploit, and What It Means for CI/CD Trust Boundaries
A CVSS 10 code-injection flaw in Google's Agent Development Kit let one AI agent hijack another in CI — a new attack surface security teams must test for.
2026-09-07 · CVE-2026-76657
CVE-2026-76657 + CVE-2026-76658: Two Perfect 10s in HPE Fabric Composer, and Why 'Internal Only' Isn't a Mitigation
Two unauthenticated CVSS 10.0 flaws in HPE Fabric Composer show why fabric-management planes deserve scrutiny beyond their internal network position.
2026-09-04 · CVE-2026-83548
CVE-2026-83548 + CVE-2026-83549: When Two 'Medium' Bugs Chain Into Unauthenticated Root
A pre-auth SSRF and an authenticated command injection in SonicWall SMA1000 combine into unauthenticated RCE — the chaining pattern is the real lesson.
2026-09-02 · CVE-2026-59310
CVE-2026-59310: What a 5-Day Exploit Window on vCenter Actually Teaches Us
A critical VMware vCenter path traversal flaw went from disclosure to active exploitation in five days — the pattern behind it, and why it matters for training.
2026-08-21
Docker-Based Hacking Labs vs. Virtual Machines: What Actually Scales
Why container-based lab isolation beats per-student VMs for hands-on cybersecurity training — spin-up time, cost, and concurrency, compared honestly.