Human Security Microsoft 365 phishing from your own domain: complex routing explained
Microsoft documented internal-looking phishing enabled by complex mail routing and weak spoof protection. A technical analysis of headers, DMARC and connectors.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Human Security Microsoft documented internal-looking phishing enabled by complex mail routing and weak spoof protection. A technical analysis of headers, DMARC and connectors.
Threats and Incidents 2025 was a record year for Poland: attacks on hospitals, DDoS on infrastructure and disinformation. We summarise the threats and lessons for businesses.
Vulnerabilities and CVEs CVE-2025-55182 React2Shell is a CVSS 10.0 unauthenticated RCE. Affected React and Next.js versions, public PoC, attacks and patches.
Vulnerabilities and CVEs CVE-2025-64446 (CVSS 9.4) lets unauthenticated attackers run FortiWeb admin commands. Public PoC, KEV, versions, hunting and fixes.
Vulnerabilities and CVEs CVE-2025-59287 (CVSS 9.8) enables RCE in Windows Server Update Services. OOB patches, KEV, defensive PoC, detection and remediation.
Vulnerabilities and CVEs CVE-2025-61882 (CVSS 9.8) enables unauthenticated code execution in Oracle EBS 12.2.3–12.2.14. PoC, IOCs, patches and threat hunting.
Vulnerabilities and CVEs CVE-2025-10035 (CVSS 10.0) in GoAnywhere MFT was exploited as a zero-day. PoC analysis, Medusa ransomware, IOCs and vendor fixes.
Supply Chain Security In autumn 2025 the Shai-Hulud worm infected hundreds of npm packages, spreading itself. We analyse the supply chain attack and how to secure your pipeline.
Supply Chain Security In 2025, stolen OAuth tokens from Salesloft exposed hundreds of firms' Salesforce data — with no cracked passwords. A lesson on integration risk.
Vulnerabilities and CVEs In summer 2025, CVE-2025-53770 in SharePoint Server let attackers take over servers with no login. We analyse the ToolShell chain and its lessons.
Vulnerabilities and CVEs CVE-2025-47812 (CVSS 10.0) enables RCE in Wing FTP Server before 7.4.4, including via anonymous access. PoC, KEV, detection and fixes.
Vulnerabilities and CVEs CVE-2025-5777 let attackers pull session tokens from Citrix NetScaler gateways, bypassing MFA. We analyse CitrixBleed 2 and the defence.
Vulnerabilities and CVEs CVE-2025-49113 (CVSS 9.9) enables code execution in Roundcube through PHP deserialization. Versions, public PoC, detection and updates.
Threats and Incidents In 2025 Scattered Spider paralysed UK retail. The weapon wasn't a 0-day but a helpdesk call. We break down the technique and the defence.
Vulnerabilities and CVEs CVE-2025-31324 in SAP NetWeaver let attackers upload a web shell with no login and take over the ERP. We analyse attacks on a company's heart.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.