Pre-auth stored XSS in Formidable Forms
An unauthenticated file upload that exposed WordPress administrators to stored cross-site scripting.
Read articleTechnical articles, vulnerability advisories, talks and publications.
An unauthenticated file upload that exposed WordPress administrators to stored cross-site scripting.
Read articleGovernance, operational control and evidence quality when using AI in offensive security.
Independent U-Boot reproduction, MR600 V5 fix analysis, and source-backed OT and IoT signals.
An unauthenticated file upload that exposed WordPress administrators to stored cross-site scripting.
An app could access information about a user’s contacts. Apple addressed the issue with improved checks.
An authorization issue could allow an app to access sensitive user data. Apple addressed it with improved state management.
Processing a maliciously crafted image could corrupt process memory. Apple addressed the issue with improved memory handling.
An SSH handling issue found during a client engagement, fixed in SFTPGo 2.7.5.
Original WebKit research, control-plane analysis, and actions for Australian security leaders.
A WebKit memory-disclosure issue involving case-insensitive regular expressions.
GlobalProtect authentication override, Exchange OWA mitigation limits, and a measured Australian exposure snapshot.
Integer overflow and bounds-checking failures in decompression code.
An Apple CoreMedia privacy issue that could allow an app to access private information.
An Apple ImageIO memory-corruption issue triggered by a maliciously crafted image.
An Apple WebKit issue that could let malicious websites process restricted web content outside the sandbox.
Managing edge device vulnerabilities in 2025. Melbourne Cyber Conference, invited speaker.
Link the article or issue you are referring to and tell us what you need. We reply within one Australian business day.