Blog
Updates, blog posts, analysis, and technical deep-dives
Blog
Updates, blog posts, analysis, and technical deep-dives

In May 2026 we published "Your Private Container Images Weren't Private" and deliberately did not say how it worked. The Gitea maintainer team has since shipped v1.26.2, the CVE is public, and the ecosystem has had the time it needed. This is the other half of that post.

NoScope's pentesting agent discovered a vulnerability in Monica CRM that allowed account takeover without any credentials. This post covers the finding, the exposure, and the steps to protect a Monica deployment.

How NoScope uncovered an authenticated remote code execution flaw in Alf.io's extension system. A single exposed Java binding turned that into full remote code execution on the underlying server.

Gitea private container images were accessible to anyone on the internet, no credentials required, across healthcare, aerospace, and critical infrastructure worldwide.

AI tools ship faster than your security process can keep up. Here's what's falling through the cracks.