Everything Cefense
knows, written down.

The research behind every match — attack classes, control points, and the reasoning Cefense uses to decide a path is reachable. Open to read and search.

No black boxes

Security should never
be a black box.

Every match points back to a page.

When Cefense flags a path, it isn't asking you to trust a score. Behind the finding is the research you can read here.

The attack class, the control point, and why the code was reachable — nothing in the product happens that isn't written down.

The library

So we wrote
all of it down.

01
Session replay and ownership boundaries

Why a valid token isn't a valid session, and where the ownership recheck belongs.

02
Device-code flows and the admin handoff

How a replayed device code walks a low-privilege login into an admin route.

03
JWT confusion: alg, kid, and audience

The three claims attackers pivot on, and the checks that actually close them.

04
Metadata SSRF across redirect chains

Reaching the instance metadata endpoint through a permissive redirect.

05
IAM role chaining and the confused deputy

When a trusted service assumes a role it was never meant to reach.

06
Public exposure that scanners miss

Buckets and services that read as private but resolve as reachable.

07
Package ownership-transfer risk

A dependency changes hands, then changes behavior in your build.

08
Postinstall scripts in the production image

Where untrusted code executes during image assembly, and how to gate it.

09
Lockfile drift and dependency confusion

How an internal name resolves to a public package under the wrong registry.

10
Delegated tool-permission boundaries

An agent inherits more than it should when tool scopes aren't isolated.

11
Prompt-routed SSRF in tool calls

Model output that steers a tool into an internal request.

12
Base-image provenance and runtime drift

Proving the image you scanned is the image that runs.

13
Build-cache poisoning of untrusted layers

A restored cache layer smuggles a change past review.

14
Object authorization and role drift

Per-object checks that quietly rot as roles accumulate.

15
PII on the path to a public endpoint

Tracing sensitive fields from store to response, one call at a time.

16
Cryptographic inventory and migration paths

Finding every place a quantum-vulnerable primitive is still in use.

17
Where RSA and ECDH still hide

Certificates, protocols, and libraries that outlive the migration plan.

18
How Cefense decides a path is reachable

The reachability model behind every match, in plain language.

Living intelligence

The same signal the
product runs on.

Every entry below is a reconstructed attack primitive — its source, when it was observed, and the semantic variants available for replay.

Living attack primitive explorer

Six primitives, continuously normalized.

Reconstructed from the source layer, deduplicated, and ranked for relevance before anything reaches you.

Updated seconds ago
18s
Authentication · BleepingComputerSession-boundary bypass variant observed

Node and edge-auth stacks · 6 variants

98
7m
Cloud · The Hacker NewsRedirect-assisted metadata SSRF

Three frameworks · replay available · 4 variants

84
22m
Supply chain · OSV.devPackage behavior changed after ownership transfer

Two dependencies away · 9 variants

71
41m
AI agents · Google Project ZeroTool-permission boundary escape

Agentic runtimes and tool routers · 3 variants

67
58m
Authentication · CISA AdvisoriesDevice-code replay reaches an admin handoff

OAuth and SSO middleware · 5 variants

63
1h
Containers · Unit 42Build cache restores an untrusted layer

CI runners and image promotion · 7 variants

58

The source layer

Two hundred feeds.
One useful signal.

Cefense does not turn 254 feeds into 254 inboxes. It reconstructs attacker behavior, groups duplicates, and surfaces a primitive only when it changes your risk.

01CISA Advisories

02NIST NVD

03CVE.org

04MITRE ATT&CK

05FIRST EPSS

06BleepingComputer

07The Hacker News

08Krebs on Security

09Dark Reading

10SecurityWeek

11The Record

12PortSwigger Daily Swig

13Google Project Zero

14Unit 42

15The DFIR Report

16Mandiant

17Microsoft Security

18Google Security Blog

19Cisco Talos

20CrowdStrike

21SentinelOne Labs

22Elastic Security Labs

23VirusTotal

24AlienVault OTX

25GreyNoise

26Shodan

27Censys

28URLhaus

29ThreatFox

30Malpedia

31Exploit DB

32Zero Day Initiative

33Packet Storm

34Hybrid Analysis

35ANY.RUN

36Joe Sandbox

37AbuseIPDB

38Spamhaus

39Cloudflare Radar

40Shadowserver

+ more research, malware, infrastructure, cloud, identity, OT, and OSINT sources

The point of it all

Coverage is table stakes.
Reduction is the product.

Reachability, in plain language.

The single idea the whole product rests on — how a live attack becomes a line in your code.

Written for anyone who needs to understand a finding, not only the person who wrote the code it lives in.

Reading tracks

Learn one attack class, end to end.

Authentication

Session boundaries, device-code flows, and JWT confusion.

3 articles
Cloud

Metadata SSRF, IAM role chaining, and quiet public exposure.

3 articles
Supply chain

Ownership transfer, postinstall scripts, and dependency confusion.

3 articles
AI agents

Delegated tool permissions and prompt-routed requests.

2 articles

Always current

New attack.
Same day.

Put the research to work.

Open Cefense