Skip to content
SQUID SEC
Menu
  • Home
  • Cheat Sheets
  • Hire SquidSec
  • SquidSec Team
  • Squid Sec Twitter
  • SquidSec Podcast
  • Home
  • Cheat Sheets
  • Hire SquidSec
  • SquidSec Team
  • Squid Sec Twitter
  • SquidSec Podcast

Tag: vulnerabilities

Cyber Geopolitics: Nation-State Actors, Trade Wars, and Sanctions Weaponizing the Digital Economy – Resilience Tactics That Actually Work
Exploits

Cyber Geopolitics: Nation-State Actors, Trade Wars, and Sanctions Weaponizing the Digital Economy – Resilience Tactics That Actually Work

Part 3 of “Building Resilience in a Globalized Digital Economy.” After NPM worms and full-spectrum supply-chain armageddon, here’s the ugly

by ☣️ Mr. The Plague ☣️
Read More
Supply Chain Armageddon Now: Defending Software, Hardware, and MSP Dependencies in a World Without Borders
News

Supply Chain Armageddon Now: Defending Software, Hardware, and MSP Dependencies in a World Without Borders

From Shai-Hulud worms cascading across npm to UEFI bootkit persistence and MSP credential abuse turning one breach into hundreds—2025–2026 proved

by ☣️ Mr. The Plague ☣️
Read More
NPM Attacks in 2026: Escalating Supply Chain Threats in the Globalized JavaScript Ecosystem – And Why Your SBOM Still Won’t Save You
weekly-brief

NPM Attacks in 2026: Escalating Supply Chain Threats in the Globalized JavaScript Ecosystem – And Why Your SBOM Still Won’t Save You

If you read my last deep-dive on NPM supply-chain risks, you remember the punchline: the JavaScript ecosystem is a house

by ☣️ Mr. The Plague ☣️
Read More
NPM Attacks in 2025: Escalating Supply Chain Threats in the JavaScript Ecosystem
weekly-brief

NPM Attacks in 2025: Escalating Supply Chain Threats in the JavaScript Ecosystem

The Node Package Manager (npm) registry faced unprecedented supply chain attacks throughout 2025, marking a significant escalation in threats targeting

by ☣️ Mr. The Plague ☣️
Read More
HTTP Request Smuggling in 2025: How to Distinguish Real Desync Vulnerabilities from HTTP Request Pipelining (And Stop Wasting Everyone’s Time)
pentesting

HTTP Request Smuggling in 2025: How to Distinguish Real Desync Vulnerabilities from HTTP Request Pipelining (And Stop Wasting Everyone’s Time)

Introduction We saw this in 2019 after James popularized modern desync attacks. We saw it again in 2024 after his

by ☣️ Mr. The Plague ☣️
Read More
CVE-2025-53770 Microsoft Releases Urgent Patch for Critical SharePoint Vulnerability Under Active Exploitation
Exploits

CVE-2025-53770 Microsoft Releases Urgent Patch for Critical SharePoint Vulnerability Under Active Exploitation

Microsoft has released out-of-band security updates to address a critical remote code execution vulnerability in on-premises SharePoint Server that is

by ☣️ Mr. The Plague ☣️
Read More
New Episode of SquidSec Podcast is Live! –
red-team

New Episode of SquidSec Podcast is Live! –

by ☣️ Mr. The Plague ☣️
Read More
Coinbase Catastrophe: Uncle Pennybags Loses Big in Bitcoin Hack!
News

Coinbase Catastrophe: Uncle Pennybags Loses Big in Bitcoin Hack!

Key Points and Direct Answer Incident Overview On May 15, 2025, Coinbase disclosed a cyberattack where hackers bribed overseas support

by ☣️ Mr. The Plague ☣️
Read More
Critical SAP Vulnerability CVE-2025-31324: What You Need to Know
Cyber Security

Critical SAP Vulnerability CVE-2025-31324: What You Need to Know

In the fast-evolving world of cybersecurity, a new threat has emerged that demands immediate attention from organizations relying on SAP

by ☣️ Mr. The Plague ☣️
Read More
Cyber Gossip: Top Cybersecurity Discussions in the Hacking Community this Week
red-team

Cyber Gossip: Top Cybersecurity Discussions in the Hacking Community this Week

In the ever-evolving world of cybersecurity, staying informed about the latest threats and incidents is crucial for professionals tasked with

by ☣️ Mr. The Plague ☣️
Read More

Posts pagination

1 2 3 Next
SQUID SECURITY LLC 2026