OFFSEC
Offensive Security
Adversarial testing, red teaming and exploit research: finding the gaps before adversaries do.
18 articles
Latest
- Eight Copies, One Backdoor: Why Removal Order Decides Whether a WordPress Cleanup Holds Sucuri has documented a WordPress infection replicated across eight locations that rebuild one another, plus a copy held in shared memory. The durable lesson is about… 6 min 10 sources
- A critical authentication bypass, a maintainer nobody could reach, and a remediation system with no state for it CERT/CC published a signature-verification bypass in Authlib on 28 September and recorded the vendor as unreachable with no patch available. A week later there is still… 5 min 10 sources
- The same authentication boundary has failed four times in one year, and the attacker population has widened Cisco disclosed a fourth exploited authentication or privilege flaw in the Catalyst SD-WAN control plane on 30 September. The pattern matters more than the CVE: what… 5 min 11 sources
- Operators shut down NetScaler appliances two days before anyone would tell them why Citrix confirmed two exploited NetScaler zero-days on 27 September, after a weekend in which administrators were instructed to pull appliances offline without being given a reason.… 6 min 11 sources
- A CVSS 10.0 under active exploitation, and two of its four release trains have no patch Arista's VeloCloud Orchestrator flaw is confirmed exploited and scores 10.0 under CVSS v3.1. Fixes exist for two affected trains. For the 6.1 and 7.0 trains the… 4 min 10 sources
- A cross-tenant exposure with no CVE: the layer below the isolation boundary you were sold Cloudflare disclosed that Containers tenants could recover residual disk blocks left by other customers, caused by a thin-provisioning option rather than a code defect. No CVE… 6 min 11 sources
- Zimbra’s critical flaw this month is in a document editor. August’s was in an SNMP agent. Neither is the mail server CVE-2026-93643 is an unauthenticated remote code execution flaw in Zimbra's OnlyOffice integration, fixed on 24 September. The flaw exploited in August lived in an optional SNMP… 6 min 13 sources
- One CVE, two severities: the Next.js image flaw is critical downstream and moderate upstream CVE-2026-94545 carries a CVSS of 9.5 in Vercel's Next.js advisory and 5.3 in Vercel's Satori advisory. Same vendor, same identifier, two ratings. Which one your tooling… 6 min 11 sources
- The Roundcube fix shipped in May. Exploitation was confirmed in September A pre-authentication SQL injection flaw in Roundcube Webmail was patched on 24 May 2026 and confirmed exploited on 21 September. Over half a million instances are… 5 min 11 sources
- CISA catalogued the exploited WSO2 flaw as a file upload bug. It is a forged-token bypass, and its fix sat in public for five months CVE-2026-5430 lets an unauthenticated attacker present a forged administrator token to WSO2's API management products. The KEV entry added on 24 September describes a path traversal… 7 min 16 sources
