Published research and coordinated disclosures.
Independent vulnerability research by the specialists who run our client engagements. Each advisory below was responsibly disclosed, fixed in production, and is publicly verifiable.
RSS feedAdvisories
2023–2026- 01
A connection is not an exploit: what 27 days of honeypot traffic actually contained
Internet-facing services (RDP, SMB, SSH, web, VoIP)
Honeypot reports trade in enormous numbers. Across 27 days OffSeq's Mirage fleet logged 5.4 million events carrying a CVE label – and 99.9% were doorknob-rattling: brute-force logins and port scans, not exploitation. Strip the noise and the real signal is 3,572 actual exploit payloads – a sharp set of web CVEs from 2017 to 2023, led by a five-year-old Exchange bug, and one botnet still typing an eight-year-old SSH key by hand.
Honeypot field report
2026 - 02
Cross-instance configuration poisoning in X-Road
X-Road Security Server (< 7.8.2)
X-Road Security Servers wrote federated global-configuration parts to disk based on the ecosystem identifier carried inside each part, without verifying it matched the actual source. A malicious federation partner could serve a SHARED-PARAMETERS part naming a victim ecosystem – signed with the victim’s own key – and overwrite its authoritative trust configuration, gaining persistent control and the ability to impersonate any of the victim’s members and Security Servers.
Insufficient verification of data authenticity (CWE-345, CWE-346)
CVSS 8.0 High GHSA-c5gr-pcm6-828r 2026 - 03
Pre-authentication denial of service in X-Road signature verification
X-Road Security Server (< 7.8.2)
The hash-chain verifier in X-Road’s batch-signature handling had no cycle detection, depth limit or cap on resolved steps, and the attacker-controlled chain was resolved before signature and certificate checks. A registered ecosystem member could send a small crafted request (a few KB) to trigger exponential CPU use or unbounded recursion, exhausting processing threads and disrupting the data-exchange service before authentication.
Uncontrolled resource consumption (CWE-400)
CVSS 6.5 Medium GHSA-rc33-88jw-c5jp 2026 - 04
Command injection fixed in Estonia’s national eID software
DigiDoc4 – Estonia’s official eID signing application
DigiDoc4’s file-manager integration constructed shell commands using unsanitised filenames. A specially crafted filename could execute arbitrary code when a user selected the file for signing or encryption. The issue affected software used for legally binding electronic signatures.
OS command injection (CWE-78)
Critical 2026 - 05
SWQL injection in SolarWinds Platform
SolarWinds Platform (≤ 2024.1 SR 1)
A query-language injection vulnerability allowed an attacker to manipulate back-end database queries in the SolarWinds Platform. It was identified during penetration testing for the NATO Communications and Information Agency.
SQL / SWQL injection (CWE-89)
CVSS 7.5 High CVE-2024-28996 2024 - 06
Cross-site scripting vulnerability in Oracle Enterprise Command Center
Oracle E-Business Suite – ECC Framework
An unauthenticated attacker could obtain unauthorised read and update access to data in the framework and connected Oracle products. Oracle fixed the issue in its October 2023 Critical Patch Update.
Cross-site scripting (CWE-79)
CVSS 6.1 Medium CVE-2023-22107 2023 - 07
SQL injection affecting customer data, responsibly disclosed
International company (responsibly anonymized)
An SQL injection vulnerability could have exposed customer data. It was reported through a responsible-disclosure process and fixed promptly. CERT.LV has publicly acknowledged our founder’s contributions to the security of Latvia’s internet space.
SQL injection
High 2023 - 08
threat-finder – open-source runtime CVE scanner
OffSeq open-source tools
A runtime vulnerability scanner that identifies CVEs affecting services currently running on a host and prioritises them by network exposure. It is part of the public toolset we develop and use in engagements.
Research & tooling
2025
Have similar exposure in your environment?
[email protected] +371 2256 5353