CVE-2026-24858: The Fortinet Patch That Wasn't
Organisations running the latest FortiOS firmware, fully patched against December's critical SSO bypass, still got compromised in January.
ClickFix in 2026: Trust-Flow Patterns, Named Variants, and What Stops Them
Updated April 2026 - The trust-flow patterns behind ClickFix, the variants and vectors carrying it, and the defences that work
MongoBleed Exploit: The MongoDB Memory Leak Hitting 87,000 Servers
Updated January 10, 2026: CISA's remediation deadline for federal agencies is January 19. Ubuntu has retracted its claim
CVE-2025-55182: React2Shell Detection and Fix Guide
UPDATE (Jan 1, 2026): RondoDox botnet now weaponizing React2Shell. Shadowserver reports 90,300 instances still vulnerable. Multiple nation-state actors
Top Infostealers in 2026: How They Work and How to Stop Them
Updated March 2026: Expanded MFA bypass section with Adversary-in-the-Middle (AitM) and the return of Lumma
LinkedIn
Post