Research & field notes

Cloud security and penetration testing research

Technical analysis of attack paths, web and API vulnerabilities, and the security failures that turn isolated findings into reachable impact.

The APR That FrozeA bounds mismatch that locks every depositor out.defi / oracle bounds
Threat Research

Freezing a six-figure crypto vault

A few percent of disagreement between two contracts can freeze every deposit and withdrawal in a live crypto vault — and this one went unnoticed for six weeks.

Trident Research · July 11, 2026 · 10 min read

WebDialer to RootAn SSRF that ends as a root webshell.cisco / unified cm
Threat Research

A phone system, one request, and root

An unauthenticated SSRF in Cisco Unified CM’s WebDialer chains to a JSP webshell and root-level compromise of enterprise voice infrastructure. Cisco patched it on June 3; within weeks attackers were dropping webshells over Tor, and CISA gave federal agencies until June 28 to fix it.

Trident Research · June 29, 2026 · 8 min read

Meta and Trident logos side by side above the title Meta AI Account Takeover
Incident Analysis

Meta's AI got tricked into resetting account passwords

Attackers simply asked Instagram's AI support assistant to send password-reset codes to an email they controlled, and it complied.

Trident Research · June 1, 2026 · 3 min read