Vuln research.
Coordinated disclosures, CVE writeups, and exploit analysis.
Seven flaws in the Securly content-filtering extension.
Vuln research
→
A review of v3.0.7 of the Securly Chrome extension, used on K-12 Chromebooks, found seven issues: plaintext-HTTP config, hardcoded AES keys, MD5/SHA-1 hashing, a Caesar-cipher "access control", and an undeclared content script. Coordinated by CERT/CC as VU#595768.
2026-06-03 - CVE-2026-8874, -8876, -8878, -8879, -8881, -8888, -8889.
Pre-authentication session fixation in Vaultwarden SSO.
Vuln research
→
Vaultwarden's OpenID Connect SSO flow was not bound to the browser that started it, allowing account takeover of any SSO user who completes a login. The flaw, the exploit, and the 1.36.0 fix.
2026-05-19 - CVE-2026-47158, CVSS 8.3.