Latest Insights

Silent Logins: How Russian-Linked Threat Actors Weaponise AnyDesk Against APAC Organisations

A Login Nobody Initiated Once upon a time in a incident response engagement, we discovered an unusual root cause for an otherwise run-of-the-mill ransomware attack. In the middle of the night, a non-production server belonging to an APAC-based Financial Institution accepted an inbound AnyDesk connection. Access (mysteriously) granted, the incomer proceeded with internal reconnaissance to…

We Followed the Wallet: Tracking GlassWorm Through Nine C2 Rotations

TL;DR Introduction On April 24, 2026, a Solana wallet executed a transaction that cost less than a fraction of a cent. To anyone watching the blockchain as a whole, it was noise in millions of daily memos moving through the network. For our team, this was a signal we had been waiting for. The wallet…

RCE in PIXERA TWO Media Server (CVE-2026-7703, CVE-2026-7704)

The PIXERA TWO Media Server is an Audio-Visual (AV) solution widely adopted to create large-scale, high-quality visual experiences in live events, stage productions, and creative projects. PIXERA servers are typically deployed in internal or isolated networks as part of professional AV setups, where performance and stability are critical. The following advisory presents two (2) vulnerabilities…

Prioritizing Agentic Workflows Before Models: The Story Behind CVE-2026-34311

Everyone is obsessing over which model powers their security agent. Is it the largest? The most expensive? The one topping the benchmarks? We took a different bet. We ran with GLM-4.7 and uncovered CVE-2026-34311, a critical   unauthenticated SSRF in Oracle OPERA PMS (again!). GLM-4.7 is certainly not the flashiest model on the market, but instead it strikes a balance…

Supply Chain As the Perimeter

When the threat enters through the vendor, detection starts too late. Here is what we saw in the past twelve months — and what it demands from defenders. The perimeter is dead — and the supply chain buried it. Just over a month ago, we were invited by the Cyber Security and Technology Crime Bureau…

Something went wrong. Please refresh the page and/or try again.