Blog
Threat Research
CVE-2026-60004 | Gitea 1.17–1.27.0 – Pre-Authentication Remote Code Execution via diffpatch Git Hook Injection
1. Introduction This document illustrates a pre-authentication Remote Code Execution (RCE) vulnerability in Gitea, the widely deployed open-source, self-hosted Git service used by development teams, enterprises and internal…
News
SAFE Security named a Leader in IDC MarketScape for Third Party Risk Management (TPRM) Software
Safe Security has been named a Leader in the IDC MarketScape: Worldwide Third-Party Risk Management Software 2026 Vendor Assessment. The IDC MarketScape Report evaluated vendors across 20 weighted…
Threat Research
From Authentication Bypass to Cloud Pivot: Exploitation Is Moving Beyond the Initial Foothold
By SAFE Threat Research Team An authentication bypass in Cisco ISE can end in root access. A pre-auth flaw in Marimo can expose cloud credentials and open a…
News
OpenAI Model Misalignment: Why Agentic AI Needs Guardrails and Measurable Trust
OpenAI recently introduced a new framework for tracking and disclosing model misalignment, together with six reports describing unexpected or concerning behavior observed during model training and evaluation. The…
Events
SAFE at Gartner SRM London 2026: Put TPRM and CTEM Into Action
Cyber risk doesn’t wait for your team to clear its backlog. Vendor evidence needs review. Exposures need context, remediation needs owners, and someone has to verify that the…