Skip to content
Offensive & Defensive Security

PurpleSec

Where offense meets defense — a living archive of real-world attack paths, Hack The Box pwns, and threat research, built to make defenders think like attackers.

PurpleSec — Cybersecurity Research & Enterprise Defense

Latest Drop

Featured Intel

Freshly published from the research desk.

Latest Post
Critical SAP Commerce Cloud RCE (CVE-2026-58231) Actively Exploited Post-Patch
August 16, 2026 11 min read #SAP
This post details CVE-2026-58231, a critical unauthenticated Remote Code Execution vulnerability in SAP Commerce Cloud (Data Hub Adapter) with a CVSS score of 10.0. Actively exploited post-patch, this flaw allows attackers to compromise internal components, leading to full system compromise.
Read full analysis →
From the blog

Recent Posts

Writeups and research notes, newest first.

Ethos

Words to Hack By

Let's talk security.

Building something, breaking something, or hardening something? I'm always up for a sharp conversation on offensive tradecraft, detection engineering, or where the industry is heading next.