Cymulate Research Labs
September 3, 2026
Read-Only Is a Lie: An Entra ID Privilege Escalation
August 11, 2026
When Monitored Content Strikes Back: Account Takeover in Microsoft Purview
July 1, 2026
The Pipe That Trusted Everyone
June 17, 2026
CVE-2026-35603: One Writable Folder, Every User Compromised: Exploiting Configuration Trust in AI Coding Tools
May 28, 2026
CVE-2026-7791: Privileged by Default
May 20, 2026
When a Web Search Becomes a Backdoor: Remote Code Execution in Codex CLI via Prompt Injection and Binary Hijacking on Windows
May 13, 2026
AKS RunCommand Vulnerability Enables Cross-Cluster Privilege Escalation
May 6, 2026
When AI Tools Become the Backdoor: Zero-Click RCE via Prompt Injection
April 15, 2026
CVE-2026-32196: One-Click RCE via Windows Admin Center Control Flow Hijacking
April 7, 2026
The Race to Ship AI Tools Left Security Behind. Part 1: Sandbox Escape
March 16, 2026
Handala Hack: From Regional Disruption to Digital Destruction — Why Security Validation Matters Now
March 10, 2026