Opens in a new tab
The Attack Path Tour

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

 CVE-2026-9181

CVE-2026-9181 is a critical path traversal vulnerability affecting Esri ArcGIS Server that could allow unauthenticated attackers to access sensitive files. Validate exposure with NodeZero® Rapid Response.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-48283 / CVE-2026-48313

CVE-2026-48283 / CVE-2026-48313: Adobe ColdFusion Pre-Authentication Unrestricted File Upload and Path Traversal Vulnerabilities
Read More →

SEARCH

CATEGORIES

Filter - Checkbox

TAGS

Filter - Checkbox

SEARCH

Filter - Checkbox
Filter - Checkbox

    CVE-2026-35273

    June 12, 2026
    CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability affecting Oracle PeopleSoft PeopleTools. Threat intelligence confirms active exploitation by ShinyHunters prior to disclosure.

    CVE-2026-48558: SimpleHelp Authentication Bypass Indicators of Compromise

    June 12, 2026
    Horizon3 details indicators of compromise, affected configurations, and mitigation guidance for CVE-2026-48558, a SimpleHelp OIDC authentication bypass vulnerability.

    AI-Powered Exploit Generation: Speed, Scale & Cyber Risk

    June 12, 2026
    Learn how AI-powered exploit generation collapses the discovery-to-impact gap, accelerates attack chains, and why exploitability-first validation is now essential.

    CVE-2026-10520

    June 11, 2026
    CVE-2026-10520 is a critical pre-authenticated OS command injection vulnerability in Ivanti Sentry that allows remote attackers to execute arbitrary commands as root.

    Autonomous Penetration Testing: The Buyer’s Decision Guide

    June 11, 2026
    Compare autonomous pentesting vs. scanners, BAS, and traditional pentests. Learn what to evaluate, what the limits are, and how to run a proof of value.
    Cybersecurity network visualization highlighting attack paths across interconnected systems

    Patch Tuesday to Pentest Wednesday: How a Global Investment Firm Reduced Security Surprises

    June 10, 2026
    A global investment firm used NodeZero® to reduce attack-path impacts from 251 to 0, eliminate compromised credentials, and build a continuous security validation program across 18 locations.

    Claude Mythos & Enterprise Security: Your Questions Answered

    June 10, 2026
    What is Claude Mythos and how does it affect enterprise security? Get clear answers on exploitability, attack paths, and how to respond with NodeZero.
    Claude Mythos displayed on a laptop

    The First AI State-Sponsored Attack: What It Means for Defenders

    June 10, 2026
    In November 2025, Anthropic disclosed the first AI-orchestrated state-sponsored cyberattack. Here's what GTG-1002 actually changes for security teams.

    CVE-2026-0257

    June 5, 2026
    CVE-2026-0257 is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect that allows unauthorized VPN access and is actively exploited in the wild.

    CVE-2026-44825

    June 2, 2026
    CVE-2026-44825 is a hardcoded credentials vulnerability affecting Apache Solr Basic Authentication setup workflows. The flaw may allow attackers to gain administrative access to vulnerable SolrCloud deployments.