Drupal Core SQL Injection Vulnerability (CVE-2026-9082)

Drupal Core SQL Injection Vulnerability (CVE-2026-9082)

|
In May 2026, the Drupal Security Team disclosed a critical SQL injection vulnerability affecting Drupal core. The issue, tracked as CVE-2026-9082, affects Drupal installations using PostgreSQL and has been assigned a Drupal security risk rating of 23/25. The vulnerability can be exploited by anonymous users, and Drupal has confirmed that ... Read More
Windows IKE Service Extensions Vulnerability Enables Remote Code Execution (CVE-2026-33824)

Windows IKE Service Extensions Vulnerability Enables Remote Code Execution (CVE-2026-33824)

|
In April 2026, Microsoft disclosed and patched a critical remote code execution vulnerability affecting the Windows Internet Key Exchange Service Extensions. Tracked as CVE-2026-33824, the issue was addressed as part of Microsoft’s April 2026 Patch Tuesday release. The affected component forms part of the Windows IPsec and IKEv2 stack, which ... Read More
Windows IKE Service Extensions Vulnerability Enables Remote Code Execution (CVE-2026-33824)

Windows IKE Service Extensions Vulnerability Enables Remote Code Execution (CVE-2026-33824)

|
In April 2026, Microsoft disclosed and patched a critical remote code execution vulnerability affecting the Windows Internet Key Exchange Service Extensions. Tracked as CVE-2026-33824, the issue was addressed as part of Microsoft’s April 2026 Patch Tuesday release. The affected component forms part of the Windows IPsec and IKEv2 stack, which ... Read More
Disclosure: SupportCandy Ticket Attachment IDOR (CVE-2026-1251)

Disclosure: SupportCandy Ticket Attachment IDOR (CVE-2026-1251)

|
During independent security research conducted as part of the Wordfence Bug Bounty Program, we identified a broken access control vulnerability in the SupportCandy plugin for WordPress. SupportCandy is a helpdesk and customer support ticketing plugin that enables organisations to manage user-submitted support requests directly within their WordPress environment, including the ... Read More
Critical jsPDF Vulnerability Enables Arbitrary File Read in Node.js (CVE-2025-68428)

Critical jsPDF Vulnerability Enables Arbitrary File Read in Node.js (CVE-2025-68428)

|
In January 2026, a critical security vulnerability was disclosed in jsPDF, a popular JavaScript library used to generate PDF documents. The issue, tracked as CVE-2025-68428, affects server-side Node.js deployments of jsPDF prior to version 4.0.0 and has been assigned a CVSS score of 9.2. The vulnerability is a path traversal ... Read More

The Boardroom Case for Penetration Testing

| | Uncategorized
Cybersecurity risk is no longer an abstract concern relegated to IT teams, it is a material business risk that boards and senior leaders must actively manage.UK government research indicates that around 43% of businesses experienced a cyber security breach or attack in the past year, underlining how common these incidents ... Read More
DeepChat AI agent XSS-to-RCE via Mermaid and Electron IPC

DeepChat AI agent XSS-to-RCE via Mermaid and Electron IPC

|
In December 2025, a critical remote code execution vulnerability was disclosed in DeepChat, an open-source desktop AI agent platform built using Electron. The issue, tracked as CVE-2025-67744, affects all DeepChat versions prior to 0.5.3 and carries a CVSS score of 9.6. The vulnerability arises from the interaction between two separate ... Read More
Google Chrome V8 “type-confusion” zero-day vulnerabilities (CVE-2025-13223 & CVE-2025-13224)

Google Chrome V8 “type-confusion” zero-day vulnerabilities (CVE-2025-13223 & CVE-2025-13224)

|
On 17 November 2025, Google released an out-of-cycle security update for Chrome to address two high-severity flaws in its V8 JavaScript/WebAssembly engine. The first, CVE-2025-13223, was discovered by Clément Lecigne of Google’s Threat Analysis Group (TAG) and is already confirmed to be exploited in the wild. The second, CVE-2025-13224, while ... Read More
Penetration testing vs red teaming: What’s the difference?

Penetration testing vs red teaming: What’s the difference?

| | Uncategorized
In cyber security, two terms are often used interchangeably but mean very different things: penetration testing and red teaming. Both involve authorised simulations of cyber attacks designed to uncover weaknesses, yet they differ in scope, intent, and the insights they provide.  A penetration test reveals where defences can be strengthened, ... Read More
Will penetration testing disrupt my business operations?

Will penetration testing disrupt my business operations?

| | Uncategorized
We are often asked by the business leaders and executives we speak to “will penetration testing disrupt our business operations?”. We frequently hear concerns about downtime, impact to customer services, or unexpected changes to data. These questions are understandable when critical systems underpin daily activity, and outages or loss of ... Read More