Home/ Blog/ Deep dive
Category

Deep dive

Technical post-mortems and architecture walkthroughs from the Suriq engineering team.

Deep dive

Four SSRF flaws in one week turned self-hosted apps into a foothold in your own network

Four unrelated products shipped SSRF flaws this week, from a Kubernetes proxy to MLflow. Why self-hosted SSRF reaches cloud metadata, and how to contain it.

Deep dive

Command execution was the week's most common bug. Self-hosted software is why.

Command injection and RCE led our threat desk's triage this week at 370, more than any other class.

Deep dive

For this week's most-exploited bugs, the patch was the easy part

This week's most-exploited bugs each shipped with a fix, yet patching FortiOS, SharePoint, Check Point, and Langflow did not end the incident.

Security news

NGINX's new 9.2 heap overflow hits a config most servers actually run, not an exotic one

CVE-2026-42533 is a CVSS 9.2 heap overflow in nginx's string engine, patched July 15. Unlike June's flaws it fires on a common regex map config.

Deep dive

The week's scariest ‘AI’ bugs weren't about AI. They were the confused deputy.

This week's headline ‘AI’ vulnerabilities in Grafana and Apache Camel are the 1988 confused-deputy flaw, the same one that hit Fastify, Directus and OpenShift

Deep dive

The appliances you install to be safer were the week’s most dangerous bugs

Dell Data Domain, Progress ShareFile and BeyondTrust all failed at authorization this week.

Deep dive

The code was clean. The toolchain that shipped it was the attack.

This week's most serious compromises were not in application code but in the tools that build, ship, and assist it. The pattern, and what to do.

Deep dive

The dangerous vulnerabilities this week were already old.

The vulnerability classes that actually shipped this week are the same five from 2010, even in new AI tooling. The pattern, and what to do.

Security news

Russia's Turla built a new backdoor for one reason: deleting one tool will not evict them

Google tied Russia's Turla to STOCKSTAY, a new .NET backdoor built as four swappable parts. Why deleting one piece does not evict the group, and what to hunt.

Security news

Prinz Eugen ransomware hits your newest files first and never leaves a note

Prinz Eugen ransomware encrypts your most recently changed files first and drops no ransom note, defeating canary traps and note-based SOC alerts. What to do.

Security news

Your Fortinet password reset won't lock the FortiBleed attacker out

CISA warned Fortinet users on June 18; reporting counted 86,644 affected devices. Resetting passwords is not enough: kill live sessions and fix the hashing.

Security news

A USB worm swaps your crypto address mid-paste, and no breach alarm ever fires

Microsoft found a USB worm that hijacks the clipboard to swap crypto wallet addresses and hides its command channel in Tor. Here is why it beats your controls.

Security news

EDR evasion is now a shipped product. Your agent's silence is the only alarm left.

The Gentlemen ransomware gang ships a standardized EDR killer to affiliates using BYOVD. Here is why driver-name hunting fails and what to detect instead.

Security news

DragonForce hides its C2 inside Microsoft Teams relays. Your network sensors see a clean call.

DragonForce's Backdoor.Turn routes C2 through Microsoft Teams TURN relays, so network sensors see only Microsoft.

Security news

Two NGINX bugs scored 9.2. On a default server you get a crash, not a shell.

F5's two critical NGINX flaws (CVE-2026-42530, CVE-2026-42055) score 9.2, but RCE needs ASLR off and a non-default config. Here is what to actually triage.

Security news

Cisco called this SD-WAN flaw medium. Attackers used it to take root on your WAN.

CVE-2026-20262 is an actively exploited Cisco SD-WAN Manager flaw that escalates a low-privilege login to root.

Security news

FortiBleed isn't a Fortinet bug. It's every password you never rotated.

FortiBleed exposed working VPN logins for tens of thousands of Fortinet firewalls. There is no CVE to patch; the fix is rotating credentials and enforcing MFA.

Security news

FortiSandbox Under Attack: The Box That Catches Malware Is Now the Way In

Three critical FortiSandbox flaws are under active exploitation, two unauthenticated and one patched a week ago.

Security news

LiteSpeed's cPanel plugin gave shared-hosting tenants root twice in 2026. CageFS didn't help.

CVE-2026-54420 and CVE-2026-48172 let shared-hosting tenants reach root through the LiteSpeed cPanel plugin. Why CageFS isolation failed and what to patch now.

Thought leadership

Why we built Suriq on Wazuh instead of writing our own detection engine

Suriq runs on Wazuh because a detection engine is a decade of decoders, CVE feeds, and agents you should never rebuild. Here is the reasoning behind the bet.

Security news

Ivanti Sentry's CVE-2026-10520: patch the gateway, then hunt for the breach

Ivanti Sentry CVE-2026-10520 is an unauthenticated root RCE under active attack. CISA's new 3-day patch rule applies; patched gateways were already breached.

Security news

PeopleSoft's PSEMHUB zero-day turns the patch service into the breach

CVE-2026-35273 sits in PeopleSoft's Updates Environment Management module. Mandiant ties active exploitation to ShinyHunters, with 100+ orgs already breached.

Security news

Velvet Ant's PAM-OpenSSH decade is an auth-stack blind spot, not a Linux bug

Sygnia found nine backdoored pam_unix.so variants and four trojanized OpenSSH binaries on one victim. Why auth-stack integrity is the SIEM-invisible gap.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.