Intelligence Feed

Dispatches from the lab

The Sherlock Forensics Intelligence Feed provides expert analysis of AI code security, vibe coding vulnerabilities, CVE advisories and digital forensics methodologies from certified examiners with over 20 years of field experience in Vancouver, BC.

Compare all forensic tool pricing Fact checks on security misconceptions
CVE Analysis

CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL)

CVE-2025-62718 (Security, CVSS 9.9 CRITICAL, CWE-441 and CWE-918 and CWE-1289) affecting axios axios. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.

CVE Analysis

CVE-2026-49875: Cxf Security (CVSS 9.8 CRITICAL)

CVE-2026-49875 (Security, CVSS 9.8 CRITICAL, CWE-611 and CWE-611) affecting apache cxf. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.

CVE Analysis

CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL)

CVE-2025-62718 (Security, CVSS 9.9 CRITICAL, CWE-441 and CWE-918 and CWE-1289) affecting axios axios. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.

CVE Analysis

CVE-2026-49875: Cxf Security (CVSS 9.8 CRITICAL)

CVE-2026-49875 (Security, CVSS 9.8 CRITICAL, CWE-611 and CWE-611) affecting apache cxf. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.

CVE Analysis

CVE-2025-62718: Axios Security (CVSS 9.9 CRITICAL)

CVE-2025-62718 (Security, CVSS 9.9 CRITICAL, CWE-441 and CWE-918 and CWE-1289) affecting axios axios. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.

CVE Analysis

CVE-2025-22225: Esxi Security (CVSS 8.2 HIGH)

CVE-2025-22225 (Security, CVSS 8.2 HIGH, CWE-787 and CWE-123) affecting vmware esxi. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.

CVE Analysis

CVE-2025-22225: Esxi Security (CVSS 8.2 HIGH)

CVE-2025-22225 (Security, CVSS 8.2 HIGH, CWE-787 and CWE-123) affecting vmware esxi. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.

CVE Analysis

CVE-2025-22225: Esxi Security (CVSS 8.2 HIGH)

CVE-2025-22225 (Security, CVSS 8.2 HIGH, CWE-787 and CWE-123) affecting vmware esxi. Full forensic analysis and public exploit availability inventory and Sigma detection signature and mitigation guidance.

Compliance Deep Dive

EoP Auditing for SOC 2 Type 2 Evidence

How Sherlock EoP Auditor produces evidence aligned with SOC 2 Type 2 control objectives covering Windows endpoint privileged access and configuration...

CVE Analysis

CVE-2026-46749: SINEC INS

SINEC INS (All versions vulnerability (CVE-2026-46749) scores CVSS 7.5 HIGH. Analysis of affected systems and remediation steps.

CVE Analysis

CVE-2026-46748: SINEC INS

SINEC INS (All versions privilege escalation (CVE-2026-46748) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.

CVE Analysis

CVE-2026-46746: SINEC INS

SINEC INS (All versions remote code execution (CVE-2026-46746) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.

CVE Analysis

CVE-2026-5415: WP Captcha PRO

WP Captcha PRO (the authentication bypass (CVE-2026-5415) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.

CVE Analysis

CVE-2026-5411: WP Captcha PRO

WP Captcha PRO (the remote code execution (CVE-2026-5411) scores CVSS 8.8 HIGH. Analysis of affected systems and remediation steps.

Tool Comparison

Best Free PST Viewers Compared (2026)

Comparison of the best free PST file viewers for 2026. Feature matrix covering deleted recovery, sensitive-data scanning, OST support and forensic reports.

CVE Analysis

CVE-2026-41551: ROS#

ROS# (All versions < directory traversal (CVE-2026-41551) scores CVSS 9.1 CRITICAL. Analysis of affected systems and remediation steps.

CVE Analysis

CVE-2026-34260: SAP S/4HANA

CVE-2026-34260 (SAP S/4HANA) explained: severity, affected versions, exploit timeline and patch guidance from 20-year forensic examiners.

CVE Analysis

CVE-2026-22925: SIMATICN 4100

SIMATIC CN 4100 (All vulnerability (CVE-2026-22925) scores CVSS 7.5 HIGH. Analysis of affected systems and remediation steps.

CVE Analysis

CVE-2026-22924: SIMATICN 4100

SIMATIC CN 4100 (All vulnerability (CVE-2026-22924) scores CVSS 9.1 CRITICAL. Analysis of affected systems and remediation steps.

Product Launch

Browser Forensic Viewer for $49

Sherlock Forensics Browser Viewer: extract history, bookmarks, downloads from 8 browsers. Free to view, $49 for CSV export. Forensic-grade.

Tool Comparison

Android Forensics Tools Compared 2026

Android forensics tools compared for 2026: Cellebrite ($15K+) vs Sherlock ($399) vs MSAB XRY vs Oxygen. Side-by-side pricing, logical vs physical extraction...

Email Forensics

Best PST Viewers Compared (2026)

Honest comparison of 6 PST viewers: pricing, features, forensic capability. Free options to $299. Find the right one for your use case.

AI Security

You Vibe Coded It. Now Secure It.

Vibe coding ships apps fast. It also ships vulnerabilities. Common risks in Cursor, Bolt and Lovable apps and how to fix them before launch.

Compliance

PIPEDA Compliance Guide for 2026

Mandatory breach notification, privacy impact assessments and security requirements under PIPEDA. Step-by-step compliance guide for Canadian businesses.

AI Security

How Attackers Are Using AI Right Now

Real examples of AI-powered attacks in 2026. AI phishing campaigns, deepfake CEO fraud, automated vulnerability discovery and AI credential stuffing explained.

CVE Intelligence

Latest CVE Alerts

High and critical vulnerabilities relevant to cloud, web and AI infrastructure. Updated daily from the National Vulnerability Database.

CVE Severity CVSS Affected Product Vulnerability
CVE-2026-23696 CRITICAL 9.9 Windmill CE/EE SQL injection in folder ownership management
CVE-2021-4473 CRITICAL 9.8 Tianxin Management System Command injection in Reporter component
CVE-2026-22679 CRITICAL 9.8 Weaver E-cology 10.0 Unauthenticated RCE via debug endpoint
CVE-2026-3296 CRITICAL 9.8 Everest Forms (WordPress) PHP Object Injection via deserialization
CVE-2026-4631 CRITICAL 9.8 Cockpit (Linux) SSH command injection via login endpoint
CVE-2026-1346 CRITICAL 9.3 IBM Verify Identity Access Privilege escalation for local users
CVE-2026-22683 HIGH 8.8 Windmill Missing authorization bypasses operator restrictions
CVE-2026-3357 HIGH 8.8 IBM Langflow Desktop Insecure FAISS deserialization enables code execution
CVE-2026-1342 HIGH 8.5 IBM Verify Identity Access Local users can execute malicious scripts
CVE-2026-4788 HIGH 8.4 IBM Tivoli Netcool Impact Sensitive data exposure in log files
CVE-2026-4740 HIGH 8.2 Red Hat ACM / Open Cluster Mgmt Certificate forgery via improper validation
CVE-2026-5736 HIGH 7.3 PowerJob detailPlus endpoint manipulation
CVE-2026-5739 HIGH 7.3 PowerJob Code injection via OpenAPI workflow endpoint
CVE-2026-5741 HIGH 7.3 docker-mcp-server OS command injection via HTTP interface
CVE-2026-1343 HIGH 7.2 IBM Verify Identity Access SSRF exposes internal auth endpoints
CVE-2026-22682 HIGH 7.1 OpenHarness Improper access control exposes local files
View Weekly Roundup (Jul 27 - Aug 9)