Citation-backed research library

Evidence for the technology decisions already on your desk.

Start with the decision you need to make, move into the relevant topic library, then search the reviewed public research set. Zeph Tech organizes current research across AI, cybersecurity, infrastructure, development, data, governance, compliance, and policy.

Reviewed research

Search and filter the current public research set.

Only research that remains outside editorial quarantine and passes the current publication safeguards appears here. Older or superseded material is intentionally withheld from public discovery until it is recertified.

Showing current briefings

Cybersecurity · · 6 min read

SharePoint CVE-2026-65660 Enters the Exploited-Vulnerability Conversation: How to Respond

CVE-2026-65660 is a high-severity SharePoint Server vulnerability associated with active exploitation reporting and CISA KEV tracking. Organizations running on-premises SharePoint should combine patching with compromise assessment and credential review.

  • Microsoft SharePoint
  • CVE-2026-65660
  • CISA KEV
  • Collaboration security
  • Incident response
Open dedicated page

Cybersecurity · · 6 min read

Oracle PeopleSoft CVE-2026-35273: What Renewed ShinyHunters Exploitation Means for Defenders

Google Threat Intelligence reported renewed mass exploitation of Oracle PeopleSoft CVE-2026-35273 by UNC6240, also known as ShinyHunters. The campaign highlights why WAF-only mitigations should not replace vendor remediation and compromise assessment.

  • Oracle PeopleSoft
  • CVE-2026-35273
  • ShinyHunters
  • WAF bypass
  • Enterprise applications
Open dedicated page

Cybersecurity · · 6 min read

File-Notification Side Channels: How Windows, Linux and macOS Can Leak User Activity

Academic research on file-notification APIs shows that legitimate operating-system monitoring interfaces can reveal timing and behavioral information to local attackers. The work is a useful reminder that privacy risk can arise from metadata and observation, not only direct file reads.

  • Side channels
  • Windows security
  • Linux security
  • macOS security
  • Privacy
Open dedicated page

Cybersecurity · · 6 min read

TeamCity CVE-2026-63077: What Active Exploitation Means for CI/CD Security

CVE-2026-63077 lets unauthenticated attackers execute operating-system commands on vulnerable TeamCity On-Premises servers. With active exploitation and ransomware activity reported, defenders should treat exposed CI/CD infrastructure as a credential and software-supply-chain incident surface.

  • TeamCity
  • CVE-2026-63077
  • CI/CD security
  • Ransomware
  • Software supply chain
Open dedicated page

Cybersecurity · · 6 min read

SalesBleed and Salesforce Agentforce: What Zero-Click Prompt Injection Teaches About AI Agent Security

SalesBleed research showed how malicious content in public Salesforce inputs could influence Agentforce workflows, exfiltrate CRM data or support phishing paths. The flaws were fixed, but the design lessons apply broadly to enterprise AI agents.

  • Salesforce Agentforce
  • SalesBleed
  • Prompt injection
  • AI agent security
  • CRM security
Open dedicated page

Cybersecurity · · 6 min read

Roundcube CVE-2026-48842: Why an Old Patch Became a New Incident Priority

Roundcube CVE-2026-48842 is a pre-authentication SQL injection fixed months earlier but later reported under active exploitation. The case is a reminder that patch age is not the same as remediation and that internet-facing webmail remains a high-value target.

  • Roundcube
  • CVE-2026-48842
  • Webmail security
  • SQL injection
  • Active exploitation
Open dedicated page

Cybersecurity · · 6 min read

WordPress CVE-2026-87902: Path Traversal, Conditional RCE and the Risk of Delayed Core Updates

CVE-2026-87902 affects WordPress versions before the fixed security releases and can allow unauthenticated path traversal leading to local PHP inclusion and conditional remote code execution. Active-exploitation reporting increases urgency for internet-facing sites.

  • WordPress
  • CVE-2026-87902
  • CMS security
  • Path traversal
  • Remote code execution
Open dedicated page

Cybersecurity · · 6 min read

SolarWinds Observability CVE-2026-28324 and CVE-2026-28325: RCE Risk and Patch Priorities

SolarWinds Observability Self-Hosted 2026.2.3 fixes two serious remote-code-execution vulnerabilities. One can be unauthenticated under affected configurations, making observability infrastructure a priority because it often has broad visibility and privileged integrations.

  • SolarWinds
  • CVE-2026-28324
  • CVE-2026-28325
  • Observability security
  • Remote code execution
Open dedicated page

Cybersecurity · · 6 min read

Compromised AWS IAM Credentials: Detection, Quarantine and Recovery Without Making the Incident Worse

AWS and security researchers continue to emphasize automated detection and quarantine for exposed IAM credentials. A disciplined response must contain the key, preserve evidence, identify what it accessed and avoid leaving replacement credentials just as exposed.

  • AWS IAM
  • Credential exposure
  • Cloud incident response
  • Secret scanning
  • Identity security
Open dedicated page

Cybersecurity · · 6 min read

Orkes Conductor CVE-2026-58138: Why Workflow Engines Need the Same Security Discipline as CI/CD

CVE-2026-58138 is an unauthenticated remote-code-execution issue affecting vulnerable Orkes Conductor versions through inline workflow expression handling. Workflow orchestration platforms deserve privileged-infrastructure controls because they routinely connect applications, credentials and automation.

  • Orkes Conductor
  • CVE-2026-58138
  • Workflow security
  • Remote code execution
  • Automation security
Open dedicated page

Cybersecurity · · 6 min read

Microsoft Patches 18 AI and Cloud Vulnerabilities: What Security Teams Should Review Beyond Windows

Microsoft disclosed fixes for 18 vulnerabilities across AI and cloud products in September 2026. The cluster is a reminder that patch governance must include managed AI services, cloud tooling, developer platforms and customer-controlled components—not only operating systems.

  • Microsoft security
  • Cloud security
  • AI security
  • Patch management
  • Privilege escalation
Open dedicated page

Cybersecurity · · 6 min read

AWS AgentCore Prompt Injection and Credential Exposure: Securing Tool-Enabled AI Agents

Unit 42 showed how prompt injection against permissive AWS AgentCore configurations could expose plaintext credentials available to an agent runtime. The research highlights shared-responsibility controls around tools, egress, identity scope and untrusted content.

  • AWS AgentCore
  • Prompt injection
  • AI agent security
  • IAM
  • Cloud security
Open dedicated page

Cybersecurity · · 6 min read

BIND 9 September 2026 Security Release: DNS DoS Flaws and Why Authoritative Infrastructure Needs Fast Patching

ISC's September 2026 BIND advisories include multiple denial-of-service vulnerabilities affecting DNS servers, including remotely triggerable crash or CPU-exhaustion conditions. DNS availability is foundational, so exposed recursive and authoritative servers deserve rapid patch verification.

  • BIND 9
  • DNS security
  • CVE-2026-81736
  • CVE-2026-77692
  • Denial of service
Open dedicated page

Cybersecurity · · 6 min read

Atomic macOS Stealer in 2026: Defending Macs Against AMOS Credential and Wallet Theft

Atomic macOS Stealer continues to evolve through malicious installers, fake tools and credential-stealing workflows aimed at browser data, passwords and cryptocurrency wallets. macOS fleets need application control, download hygiene and identity monitoring—not assumptions that Macs are low-risk.

  • Atomic macOS Stealer
  • AMOS
  • macOS security
  • Infostealer
  • Credential theft
Open dedicated page

Cybersecurity · · 6 min read

VMware vCenter CVE-2026-59310: Ransomware Exploitation Raises the Stakes for Virtualization Security

CVE-2026-59310 is a critical vCenter Server directory-traversal flaw that can lead to arbitrary code execution. Reports of active exploitation and ransomware activity make exposed or unpatched virtualization management infrastructure a priority incident-response target.

  • VMware
  • vCenter
  • CVE-2026-59310
  • Virtualization security
  • Ransomware
Open dedicated page

Cybersecurity · · 6 min read

SPIFFE and SPIRE Workload Identity After Node Compromise: What Kubernetes Teams Need to Know

Unit 42 research showed that a root-level attacker on a Kubernetes node can abuse workload-attestation assumptions in some SPIFFE/SPIRE deployments to impersonate co-located workloads and obtain their identities. The issue is a post-compromise trust-boundary problem, not a remote SPIRE zero-day.

  • SPIFFE
  • SPIRE
  • Kubernetes security
  • Workload identity
  • Zero trust
Open dedicated page

Cybersecurity · · 6 min read

Cisco FMC Exploitation: CVE-2026-20079 and CVE-2026-20316 Put Firewall Management at Risk

Cisco reported active exploitation of Secure Firewall Management Center weaknesses including CVE-2026-20079, a critical authentication bypass. The incident reinforces why firewall management systems must be treated as privileged control-plane assets.

  • Cisco FMC
  • CVE-2026-20079
  • CVE-2026-20316
  • Firewall security
  • Control plane
Open dedicated page

Cybersecurity · · 6 min read

Adversarial AI Is Moving From Prompting to Autonomy: What Defenders Need to Change

Google Threat Intelligence Group documented threat actors using AI not only for research and drafting but for operational automation, including an agent-enabled credential-harvesting workflow built and executed within hours. Security teams need controls for faster, more adaptive adversaries.

  • Adversarial AI
  • Agentic AI
  • Threat intelligence
  • Cloud security
  • Identity security
Open dedicated page

Cybersecurity · · 6 min read

BREEZE COMET: What Financially Motivated Attacks on Brazil Reveal About Payment-System Security

Google Threat Intelligence Group linked BREEZE COMET to financially motivated operations targeting Brazilian financial institutions and payment ecosystems. The campaign shows how trusted websites, custom malware and payment-system access can combine into direct financial theft.

  • BREEZE COMET
  • Financial cybercrime
  • Brazil
  • Payment security
  • Threat intelligence
Open dedicated page

Cybersecurity · · 6 min read

CISA BOD 26-04: How Risk-Based Vulnerability Prioritization Changes Federal Patching

CISA's BOD 26-04 pushes federal agencies toward risk-based security-update prioritization using exploitation evidence, asset exposure, exploit automation and technical impact. The underlying model is useful beyond government because it focuses scarce remediation capacity on vulnerabilities most likely to matter.

  • CISA
  • BOD 26-04
  • Vulnerability management
  • CISA KEV
  • Risk-based patching
Open dedicated page

Cybersecurity · · 8 min read

NIST SP 1326 Supplier Due Diligence: A 2026 Public-Sector Buyer Playbook

NIST finalized SP 1326 in July 2026. This buyer briefing turns its five supplier due-diligence components into evidence requests, decision records, and post-award review triggers for public-sector technology procurement.

  • NIST SP 1326
  • C-SCRM
  • Supplier Due Diligence
  • Vendor Risk
  • Technology Procurement
  • Supply Chain Risk
Open dedicated page

Compliance · · 8 min read

Government Web Accessibility Deadlines Changed in 2026: ADA Title II and HHS Section 504 Timelines

DOJ and HHS each extended major web and mobile accessibility compliance dates by one year in 2026. This briefing separates the current ADA Title II and HHS Section 504 timelines and turns the extensions into practical public-sector planning and procurement actions.

  • ADA Title II
  • Section 504
  • WCAG 2.1 AA
  • Government Web Accessibility
  • Public Sector Accessibility
  • Digital Services
Open dedicated page

AI Tools · · 7 min read

Gemini 3.7 Flash Enterprise Evaluation: What Changed From 3.6 and What Buyers Should Test

Google released Gemini 3.7 Flash on August 13, 2026, only weeks after 3.6 Flash. This enterprise evaluation separates Google's vendor-reported benchmark gains from the evidence buyers still need to collect in their own workflows, governance controls, cost models, and acceptance tests.

  • Gemini 3.7 Flash
  • Enterprise AI
  • Model Evaluation
  • AI Procurement
  • Agentic AI
  • AI Governance
Open dedicated page

Showing 50 of 1015 briefings

Use what you learned

Move from reading to a documented decision.

Research is most valuable when the evidence carries forward into requirements, comparisons, and stakeholder questions.

  • Define procurement requirements
  • Score comparable evidence
  • Build a stakeholder-ready evaluation brief