HIVE PRO LEARNING CENTER

Research, guides, and live sessions for security teams doing the actual work.

Threat reports from HiveForce Labs, practitioner eBooks, live demo recordings, datasheets, and upcoming CISO dinner events. All research is free to download. All guides are written for practitioners, not executives.

NEW . THREAT INTELLIGENCE REPORT

The Iranian Cyber War Intensifies (Part 2)

31 Days Dark. 200,000+ Devices Wiped. Cloud Infrastructure Under Kinetic Fire. The follow-up to HiveForce Labs' most-read report covers the Stryker MDM wiper attack, IRGC drone strikes on AWS data centers, and MuddyWater pre-positioning inside US critical infrastructure.

Blog
Blog

Everything You Need to Know About the Spring Cloud Vulnerability

This is a Hive Pro security advisory for CVE-2026-40982, a critical (CVSS 9.8) path traversal flaw in Spring Cloud Config Server's ResourceController. The core problem: a prior fix (CVE-2026-22739) only protected the profile parameter in one controller, leaving three sibling parameters — name, label, and path — unchecked in an adjacent controller. An unauthenticated attacker can send a single crafted HTTP GET request with a traversal sequence in any of those three variables and read arbitrary files off the server. No credentials, no user interaction, network access only. Deployments using a custom ResourceRepository are most exposed, since the built-in repository's fallback check doesn't apply to them. Why it matters: Config Server is the "master keyring" for a microservice mesh, so one file read typically hands over database passwords, cloud provider keys, and JWT signing secrets — enough to pivot into every downstream system, with regulatory fallout under GDPR, HIPAA, PCI-DSS, and SOC 2 / ISO 27001. The bigger narrative is a seven-year pattern: five CVEs in the same module, each fix scoped narrowly to the reported parameter while leaving adjacent ones open. HivePro found this one during BAS exploit development, disclosed it responsibly, and Spring patched all five affected branches (3.1.14 / 4.1.10 / 4.2.7 / 4.3.3 / 5.0.3) within 13 days — before public disclosure, no known exploitation. Recommendation: patch immediately, audit any custom ResourceRepository for path validation, and lock down network exposure regardless of patch status.

→

READY TO GO DEEPER

See how Hive Pro handles
your actual exposure.

Book a 30-minute working session. We ingest a sample of your scan data, surface the top 1% of exposures most likely to be exploited, and show you what changes when prioritization is threat-relevant rather than CVSS-driven.

Reduce real exposure. Not just vulnerability volume.