Analysis
CVE-2026-73570 needs no credentials and no user interaction — a crafted SMTP request executes commands as the zimbra user. Mail servers accept connections from strangers by definition, which is what makes pre-auth bugs in them a different category of problem.
Analysis
CVE-2026-60004 turns repository write access into shell execution as the Gitea service account. The interesting part is not the injection — it is that Git hooks are executable files sitting inside a directory your developers write to all day.
AnalysisMembers
Between 25 and 27 August, KEV gained CVEs from 2015, 2021 and 2022 — most of them local, none of them remote entry points. A catalogue of what attackers are actively using is telling you about the second stage, and about how much end-of-life software is still running.
Full write-up available to members subscribers. See what is included.
Rule PackTeams
Eleven Sigma rules and three YARA signatures covering the persistence and execution techniques that showed up most in this quarter's casework, with measured false-positive budgets.
Full write-up available to team subscribers. See what is included.
AnalysisMembers
A lab reconstruction of a user-level persistence case, and why the Run key timestamp is the least useful thing in the artifact set.
Full write-up available to members subscribers. See what is included.
AnalysisMembers
Four variants of the same PowerShell technique, three of which walked past a rule that looked fine on paper. Notes from a purple team afternoon.
Full write-up available to members subscribers. See what is included.
Analysis
Entropy, subdomain cardinality and query-rate shape — three statistics that find a covert channel faster than any rule matching a known tool.
Lab Note
Six months of a detection lab that was impressive to look at and useless to work in, and the four changes that fixed it.