Entry Thumbnail

Attack arithmetic: how an integer overflow in PostgreSQL libpq leads to denial of service

Databases serve as the foundation of the digital world, organizing and storing critical information: from financial transactions and medical records to website content. However, like any complex software product, they are not immune to flaws, and discovered vulnerabilities can turn this repository into a prime target for attacks. This applies […]

Posted by
Entry Thumbnail

Getting a Shell on the Tapo C260 Webcam (CVE-2026-0651, CVE-2026-0652, CVE-2026-0653)

As shared in my previous blogpost, I reverse-engineered the TP-Link Tapo C260 webcam for the SPIRITCYBER IoT hardware hacking contest. Despite being one of the latest Tapo webcams, I was able to discover some pretty interesting vulnerabilities – local file disclosure (CVE-2026-0651), guest-privilege Remote Code Execution (CVE-2026-0652), and privilege escalation […]

Posted by
Entry Thumbnail

The MCP AuthN/Z Nightmare

# The MCP AuthN/Z Nightmare 05 Mar 2026 – Posted by Francesco Lacerenza This article shares our perspective on the current state of authentication and authorization in enterprise-ready, remote MCP server deployments. Before diving into that discussion, we’ll first outline the most common attack vectors. Understanding these threats is essential […]

Posted by
Entry Thumbnail

Interplay between Iranian Targeting of IP Cameras and Physical Warfare in the Middle East

## Key Findings – During the ongoing conflict, we identified intensified targeting of IP cameras from two manufacturers starting on February 28, originating from infrastructure we attribute to Iranian threat actors. – The targeting extends across Israel, Qatar, Bahrain, Kuwait, the UAE, and Cyprus – countries that have also experienced […]

Posted by
Entry Thumbnail

Silver Dragon Targets Organizations in Southeast Asia and Europe

In recent months, Check Point Research (CPR) has been tracking a sophisticated, Chinese-aligned threat group whose activity demonstrates operational correlation with campaigns previously associated with APT41. We have designated this activity cluster as Silver Dragon. This group actively targets organizations in Southeast Asia and Europe, with a particular focus on […]

Posted by
Entry Thumbnail

Sometimes, You Can Just Feel The Security In The Design (Junos OS Evolved CVE-2026-21902 RCE)

# Sometimes, You Can Just Feel The Security In The Design (Junos OS Evolved CVE-2026-21902 RCE) On today’s ‘good news disguised as other things’ segment, we’re turning our gaze to CVE-2026-21902 – a recently disclosed “Incorrect Permission Assignment for Critical Resource” vulnerability affecting Juniper’s Junos OS Evolved platform. This vulnerability […]

Posted by