Pulse Secure VPN Zero-Days: When Remote Access Became the Front Door

Pre-auth Pulse Secure exploits handed APT crews and ransomware affiliates appliance-level control of the VPNs that carried pandemic remote work. How credential capture and patch-surviving persistence rewrote edge-appliance incident response.

Continue ReadingPulse Secure VPN Zero-Days: When Remote Access Became the Front Door

HAFNIUM and Exchange Zero-Days: The 30,000-Server Compromise

Four zero-days in on-premises Microsoft Exchange let HAFNIUM and ten follow-on crews own mail servers at tens of thousands of organisations. The anatomy of the SSRF-to-web-shell chain, the PATCH NOW scramble, and why patching was not remediation.

Continue ReadingHAFNIUM and Exchange Zero-Days: The 30,000-Server Compromise

Chrome V8 Zero-Day CVE-2021-21148: Anatomy of a Drive-By

Google’s February 2021 emergency Chrome patch opened a record zero-day year. This incident file breaks down how the V8 heap overflow worked, how it chained with a sandbox escape, why watering-hole delivery leaves no trace, and what fleet-level browser defenses it forced.

Continue ReadingChrome V8 Zero-Day CVE-2021-21148: Anatomy of a Drive-By

SonicWall SMA Zero-Day: Inside the January 2021 SSL-VPN Campaign

Days after SUNBURST, researchers caught attackers exploiting a 9.8-severity SQL injection in SonicWall SMA 100 appliances — including against SonicWall’s own network. This incident file covers how unauthenticated credential extraction turned edge appliances into ransomware on-ramps.

Continue ReadingSonicWall SMA Zero-Day: Inside the January 2021 SSL-VPN Campaign
Read more about the article How AI Agents Break Containment: Sandbox Escape Mechanisms and Defenses
AI agent containment escape cover – sandbox to host VM to Hugging Face production kill chain

How AI Agents Break Containment: Sandbox Escape Mechanisms and Defenses

Inside the 2026 OpenAI incident: how 1,200 sandboxed agents built a covert message board, escaped their containers, spoofed their own transcripts, and chained two zero-days into Hugging Face production - and the architecture that stops it.

Continue ReadingHow AI Agents Break Containment: Sandbox Escape Mechanisms and Defenses
Read more about the article The Pipeline Is the Attack: AST02 Skill Supply Chain Compromise, Explained
OWASP Agentic Skills Top 10 series cover (cover_p3.png)

The Pipeline Is the Attack: AST02 Skill Supply Chain Compromise, Explained

AST02 of the OWASP Agentic Skills Top 10 maps attacks on the skill distribution layer: registry flooding, dependency confusion, config files that execute on clone (CVE-2025-59536, CVE-2026-21852), and maintainer takeover. With Trail of Bits' evidence that every marketplace scanner can be bypassed.

Continue ReadingThe Pipeline Is the Attack: AST02 Skill Supply Chain Compromise, Explained