Vulnerability Management2026-09-07·14 min read
SonicWall SMA 1000: Pre-Auth SSRF Chains to Full Root — Active Exploitation Confirmed
Two zero-day vulnerabilities in SonicWall SMA 1000 remote access gateways — a pre-authentication SSRF rated CVSS 10.0 and a post-auth OS command injection rated CVSS 7.8 — can be chained for unauthenticated remote code execution. SonicWall confirmed attacks are ongoing. Patches are in firmware 12.4.3-03526 and 12.5.0-02952. This is a critical-priority incident for any organization running a SMA 1000 model 6210, 7210, or 8200v with an internet-exposed management interface.
Read more →IAM2026-07-17·3 min read
n8n Token Exchange Flaw Lets Attackers Log In As Other Users
n8n patched a bug in their Enterprise token exchange feature that let attackers log in as other users without passwords. The flaw ignored the JWT issuer claim, matching users on subject alone. Strix's AI security agent found it.
Read more →Threat Intelligence2026-06-30·4 min read
RustDuck Botnet Rebuilds in Rust to Hijack Routers and IoT for DDoS
A Rust-rewritten botnet is hijacking routers, IP cameras, and Android boxes for DDoS attacks. RustDuck uses CVE-2017-17215, CVE-2025-29635, and other old vulnerabilities that should have been patched years ago.
Read more →Hardening2026-07-15·4 min read
Microsoft Patches a Record 570 Security Flaws
Microsoft released 570 patches for July's Patch Tuesday, nearly triple last month's record. Two zero-days are under active attack, including an AD FS privilege escalation flaw. AI is now finding bugs faster than humans can patch them.
Read more →IAM2026-06-01·10 min read
Vibe Coding Security: Enterprise Defense Against Shadow Builder Exposures [2026]
2,000+ publicly accessible vibe-coded applications holding sensitive corporate data. Shadow Builders are bypassing every security control you've built. This is the enterprise defense playbook for a problem most organizations haven't acknowledged exists yet.
Read more →Threat Intelligence2026-06-04·4 min read
Hugging Face Breach: Malicious Dataset Used to Steal Cloud Credentials
The world's largest AI model repository was breached using a malicious dataset. Attackers exploited vulnerabilities in Hugging Face's dataset processing to gain code execution, then escalated to steal cloud credentials from internal infrastructure.
Read more →