Latest Insights

Beyond Risky Sign-Ins: Behavioural Analysis for AiTM Attack Detection
Social engineering attacks are at an all-time high, amplified by the accessibility of phishing toolkits and open-source Artificial Intelligence (AI) offerings. This is reflected in the fact that 98% of cyberattacks leverage social engineering techniques to exploit the human element to achieve their end objectives.[1] What began as Business Email Compromise (BEC), campaigns that facilitated…
RCE in PIXERA TWO Media Server (CVE-2026-7703, CVE-2026-7704)
The PIXERA TWO Media Server is an Audio-Visual (AV) solution widely adopted to create large-scale, high-quality visual experiences in live events, stage productions, and creative projects. PIXERA servers are typically deployed in internal or isolated networks as part of professional AV setups, where performance and stability are critical. The following advisory presents two (2) vulnerabilities…
Prioritizing Agentic Workflows Before Models: The Story Behind CVE-2026-34311
Everyone is obsessing over which model powers their security agent. Is it the largest? The most expensive? The one topping the benchmarks? We took a different bet. We ran with GLM-4.7 and uncovered CVE-2026-34311, a critical unauthenticated SSRF in Oracle OPERA PMS (again!). GLM-4.7 is certainly not the flashiest model on the market, but instead it strikes a balance…