Analysis
CVE-2026-60004 turns repository write access into shell execution as the Gitea service account. The interesting part is not the injection — it is that Git hooks are executable files sitting inside a directory your developers write to all day.
Analysis
CVE-2026-73570 needs no credentials and no user interaction — a crafted SMTP request executes commands as the zimbra user. Mail servers accept connections from strangers by definition, which is what makes pre-auth bugs in them a different category of problem.
Rule PackTeams
Eleven Sigma rules and three YARA signatures covering the persistence and execution techniques that showed up most in this quarter's casework, with measured false-positive budgets.
Full write-up available to team subscribers. See what is included.
AnalysisMembers
Four variants of the same PowerShell technique, three of which walked past a rule that looked fine on paper. Notes from a purple team afternoon.
Full write-up available to members subscribers. See what is included.