Deep dive
Technical post-mortems and architecture walkthroughs from the Suriq engineering team.
Four SSRF flaws in one week turned self-hosted apps into a foothold in your own network
Four unrelated products shipped SSRF flaws this week, from a Kubernetes proxy to MLflow. Why self-hosted SSRF reaches cloud metadata, and how to contain it.
Command execution was the week's most common bug. Self-hosted software is why.
Command injection and RCE led our threat desk's triage this week at 370, more than any other class.
For this week's most-exploited bugs, the patch was the easy part
This week's most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.
NGINX's new 9.2 heap overflow hits a config most servers actually run, not an exotic one
CVE-2026-42533 is a CVSS 9.2 heap overflow in nginx's string engine, patched July 15. Unlike June's flaws it fires on a common regex map config.
The week's scariest ‘AI’ bugs weren't about AI. They were the confused deputy.
This week's headline ‘AI’ vulnerabilities in Grafana and Apache Camel are the 1988 confused-deputy flaw, the same one that hit Fastify, Directus and OpenShift
The appliances you install to be safer were the week’s most dangerous bugs
Dell Data Domain, Progress ShareFile and BeyondTrust all failed at authorization this week.
The code was clean. The toolchain that shipped it was the attack.
This week's most serious compromises were not in application code but in the tools that build, ship, and assist it. The pattern, and what to do.
The dangerous vulnerabilities this week were already old.
The vulnerability classes that actually shipped this week are the same five from 2010, even in new AI tooling. The pattern, and what to do.
Russia's Turla built a new backdoor for one reason: deleting one tool will not evict them
Google tied Russia's Turla to STOCKSTAY, a new .NET backdoor built as four swappable parts. Why deleting one piece does not evict the group, and what to hunt.
Prinz Eugen ransomware hits your newest files first and never leaves a note
Prinz Eugen ransomware encrypts your most recently changed files first and drops no ransom note, defeating canary traps and note-based SOC alerts. What to do.
Your Fortinet password reset won't lock the FortiBleed attacker out
CISA warned Fortinet users on June 18; reporting counted 86,644 affected devices. Resetting passwords is not enough: kill live sessions and fix the hashing.
A USB worm swaps your crypto address mid-paste, and no breach alarm ever fires
Microsoft found a USB worm that hijacks the clipboard to swap crypto wallet addresses and hides its command channel in Tor. Here is why it beats your controls.
EDR evasion is now a shipped product. Your agent's silence is the only alarm left.
The Gentlemen ransomware gang ships a standardized EDR killer to affiliates using BYOVD. Here is why driver-name hunting fails and what to detect instead.
DragonForce hides its C2 inside Microsoft Teams relays. Your network sensors see a clean call.
DragonForce's Backdoor.Turn routes C2 through Microsoft Teams TURN relays, so network sensors see only Microsoft.
Two NGINX bugs scored 9.2. On a default server you get a crash, not a shell.
F5's two critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) score 9.2, but RCE needs ASLR off and a non-default config. Here is what to actually triage.
Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.
CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.
FortiBleed isn't a Fortinet bug. It's every password you never rotated.
FortiBleed exposed working VPN logins for tens of thousands of Fortinet firewalls. There is no CVE to patch; the fix is rotating credentials and enforcing MFA.
FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In
Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.
LiteSpeed's cPanel plugin gave shared-hosting tenants root twice in 2026. CageFS didn't help.
CVE-2026-54420 and CVE-2026-48172 let shared-hosting tenants reach root through the LiteSpeed cPanel plugin. Why CageFS isolation failed and what to patch now.
Why we built Suriq on Wazuh instead of writing our own detection engine
Suriq runs on Wazuh because a detection engine is a decade of decoders, CVE feeds, and agents you should never rebuild. Here is the reasoning behind the bet.
Ivanti Sentry's CVE-2026-10520: patch the gateway, then hunt for the breach
Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA's new 3-day patch rule applies; patched gateways were already breached.
PeopleSoft's PSEMHUB zero-day turns the patch service into the breach
CVE-2026-35273 sits in PeopleSoft's Updates Environment Management module. Mandiant ties active exploitation to ShinyHunters, with 100+ orgs already breached.
Velvet Ant's PAM-OpenSSH decade is an auth-stack blind spot, not a Linux bug
Sygnia found nine backdoored pam_unix.so variants and four trojanized OpenSSH binaries on one victim. Why auth-stack integrity is the SIEM-invisible gap.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.