Cybersecurity Blog
Insights, technical guides and analysis from the Secra team on the latest cybersecurity threats and trends.
EU AI Act: A Compliance Guide for Businesses
What the EU AI Act is, the obligations timeline (August 2026), the risk tiers and what businesses must do to comply, from transparency duties to GPAI and high-risk systems.
AI-Generated Code Security: The Risks of Vibe Coding
Security risks of AI-generated code (vibe coding): insecure code, hallucinated dependencies (slopsquatting) and secret leakage, and how to control them in the SDLC.
AiTM Phishing: Session Hijacking and MFA Bypass Explained
What adversary-in-the-middle (AiTM) phishing is, how it steals the session cookie to bypass MFA, and how to defend with phishing-resistant MFA and conditional access.
CVE-2026-15409 and CVE-2026-15410: SonicWall SMA 1000 Zero-Days
Analysis of the SonicWall SMA 1000 zero-days CVE-2026-15409 (SSRF, CVSS 10) and CVE-2026-15410, chained for code execution. Affected versions and mitigation.
CVE-2026-56155: Active Directory Federation Services Privilege Escalation Zero-Day
Analysis of CVE-2026-56155, an actively exploited elevation-of-privilege zero-day in Active Directory Federation Services (AD FS). Risk to federated identity and mitigation.
CVE-2026-56164: SharePoint Server Under Active Exploitation
Analysis of CVE-2026-56164 in SharePoint Server: a missing-authentication flaw exploited unauthenticated, chained to RCE, web shells and IIS key theft. Impact and mitigation.
wp2shell: Unauthenticated RCE in WordPress Core
Analysis of wp2shell (CVE-2026-63030 and CVE-2026-60137): the chain that achieves unauthenticated remote code execution in WordPress core. Impact, versions, detection and mitigation.
SBOM and Software Supply Chain Security
What an SBOM is (CycloneDX, SPDX), how to generate it in your pipeline, and why it is key to software supply chain security, SLSA, Sigstore and NIS2.
AWS IAM Privilege Escalation: Attack Paths
AWS IAM privilege escalation paths: iam:PassRole abuse, policy versioning, sts:AssumeRole chains and how to detect them with CloudTrail.

