Blog

Cybersecurity Blog

Insights, technical guides and analysis from the Secra team on the latest cybersecurity threats and trends.

Compliance

EU AI Act: A Compliance Guide for Businesses

What the EU AI Act is, the obligations timeline (August 2026), the risk tiers and what businesses must do to comply, from transparency duties to GPAI and high-risk systems.

2026-08-0913 min
DevSecOps

AI-Generated Code Security: The Risks of Vibe Coding

Security risks of AI-generated code (vibe coding): insecure code, hallucinated dependencies (slopsquatting) and secret leakage, and how to control them in the SDLC.

2026-07-2613 min
ofensiva

AiTM Phishing: Session Hijacking and MFA Bypass Explained

What adversary-in-the-middle (AiTM) phishing is, how it steals the session cookie to bypass MFA, and how to defend with phishing-resistant MFA and conditional access.

2026-07-2612 min
ofensiva

CVE-2026-15409 and CVE-2026-15410: SonicWall SMA 1000 Zero-Days

Analysis of the SonicWall SMA 1000 zero-days CVE-2026-15409 (SSRF, CVSS 10) and CVE-2026-15410, chained for code execution. Affected versions and mitigation.

2026-07-2611 min
defensiva

CVE-2026-56155: Active Directory Federation Services Privilege Escalation Zero-Day

Analysis of CVE-2026-56155, an actively exploited elevation-of-privilege zero-day in Active Directory Federation Services (AD FS). Risk to federated identity and mitigation.

2026-07-2611 min
ofensiva

CVE-2026-56164: SharePoint Server Under Active Exploitation

Analysis of CVE-2026-56164 in SharePoint Server: a missing-authentication flaw exploited unauthenticated, chained to RCE, web shells and IIS key theft. Impact and mitigation.

2026-07-2614 min
ofensiva

wp2shell: Unauthenticated RCE in WordPress Core

Analysis of wp2shell (CVE-2026-63030 and CVE-2026-60137): the chain that achieves unauthenticated remote code execution in WordPress core. Impact, versions, detection and mitigation.

2026-07-2014 min
DevSecOps

SBOM and Software Supply Chain Security

What an SBOM is (CycloneDX, SPDX), how to generate it in your pipeline, and why it is key to software supply chain security, SLSA, Sigstore and NIS2.

2026-07-1311 min
Cloud Security

AWS IAM Privilege Escalation: Attack Paths

AWS IAM privilege escalation paths: iam:PassRole abuse, policy versioning, sts:AssumeRole chains and how to detect them with CloudTrail.

2026-07-0610 min
PreviousPage 1 of 14Next

👋Hi! Have any questions? Write to us, we reply in minutes.

Open WhatsApp →