Neutron, our AI engine, scored 96.75% on UC Berkeley's CyberGym benchmark. Learn more

Category

Security

Vulnerability research, CVE deep dives, and practical guides for mobile and web application security.

127 articles

A technical breakdown of CVE-2026-42208, a CVSS 9.3 critical unauthenticated SQL Injection vulnerability in the LiteLLM Proxy API. Improper parameterization of the Bearer token within raw SQL queries used for complex multi-table joins allows blind boolean-based timing attacks, enabling unauthenticated attackers to exfiltrate sensitive data including virtual API keys, user information, and LLM spend logs directly from the database.

Security

DirtyFrag: Universal Linux Local Privilege Escalation via Page-Cache Write

A technical breakdown of DirtyFrag, a pair of Linux kernel local privilege escalation vulnerabili...

May 13, 2026

Security

Exploit CVE-2026-44109 : OpenClaw Feishu Webhook Authentication Bypass to RCE

A technical breakdown of CVE-2026-44109, a CVSS 9.2 Critical authentication bypass vulnerability ...

May 07, 2026

Security

CVE-2026-5205: Critical SSRF in Chatwoot — How a Single Upload Parameter Exposes Cloud Credentials

A deep dive into a critical Server-Side Request Forgery (SSRF) vulnerability in Chatwoot's upload...

Apr 29, 2026

More in Security

DORA Compliance Checklist for Banking & Fintech: Audit-Ready Operational Resilience Validation

A DORA compliance checklist helps banking and fintech organizations evaluate operational resilience across core areas like ICT risk, incident response, resilience testing, third-party governance, and oversight, while tracking implementation progress and supporting audit readiness.

Apr 29, 2026

BeatBanker/BTMOB Android Banking Malware Analysis

Static analysis of TV_V_23.apk, BeatBanker/BTMOB Android banking malware disguised as a flashlight app: four-stage chain, anti-analysis, attribution and IOCs.

Apr 28, 2026

HarmonyOS Next Security Testing: Tools and Risks

How HarmonyOS Next security testing differs from Android: ArkTS, DSoftBus, testing tools, SafetyDetect, ArkGuard, common flaws and OWASP MASVS mapping.

Apr 28, 2026

Android Intent Redirection: Attacks and Fixes

How intent redirection lets attackers reach unexported Android components, leak data via setResult() and abuse PendingIntents, plus six ways to prevent it.

Apr 23, 2026

Mobile Game Security Testing: Prevent Hacks, Cheating, and Revenue Loss

Mobile game security testing prevents cheating, hacks, and revenue loss by securing client, network, and backend layers. This guide covers the latest threats, testing methodologies, and best practices for mobile security teams and mobile game developers looking to keep their game safe, fair, and compliant.

Apr 20, 2026

Mobile AppSec Testing Best Practices at Scale

Mobile AppSec testing for teams shipping iOS and Android fast: MAST vs SAST vs DAST, a testing checklist, CI/CD patterns and severity-based release gating.

Apr 16, 2026

Healthcare Application Security Testing Guide

How to security test patient portals, medical apps, APIs and SaMD: ePHI risks, HIPAA and GDPR duties, SDLC testing, continuous monitoring and incident response.

Apr 16, 2026

Mobile Banking Security Testing: Protecting Financial Apps, Data, and Transactions

Protecting mobile banking apps requires more than securing the client alone. This guide explores the risks across devices, networks, and backend systems, and explains why continuous mobile security testing is essential for protecting financial data and transactions.

Apr 16, 2026

Twenty CRM Serverless Functions Expose Critical RCE and Permanent Unauthenticated Backdoor Risk (CVE-2026-26720) - PoC & Exploit

A technical breakdown of CVE-2026-26720, a CVSS 9.8 Critical authenticated Remote Code Execution vulnerability in Twenty CRM (≤ v1.15.0). Any workspace member can create and execute serverless functions that run unsandboxed with full access to process.env, leaking APP_SECRET, PG_DATABASE_URL, and all server-side credentials. When combined with webhook-triggered workflows exposed via PublicEndpointGuard, a single authenticated attacker can install a permanent unauthenticated RCE backdoor accessible from anywhere on the internet.

Apr 15, 2026

DORA Third-Party Risk: Mobile SDK Governance

Manage DORA third-party risk in mobile apps with per-release SDK inventories and diffs, approval and ban rules, patch SLAs and audit-ready evidence packs.

Apr 14, 2026