Do I Need to Worry About JFrog?
I spent my lunch hour scrolling through the CISA Known Exploited Vulnerabilities list. It ruins your mood. Still, it's the only honest map of what attackers are doing right now.
The cost of calling a fake email sophisticated
You get paged at 3am because your customer's passport is sitting in a public Telegram channel. It's right there next to their selfie and their whole transaction history; that's the reality of the Revolut mess. It isn't some complex puzzle. It's just bad hygiene.
Who Owns the MSP Deadline?
CISA has a peculiar method for telling everyone it's time to worry. No dramatic language. No urgent prose. They simply add an entry to their Known Exploited Vulnerabilities (KEV) catalogue and attach a federal patch deadline; for CVE-2026-84869, that deadline is today, Monday, Se
Your Router is Having a Mid-Life Crisis
It's Sunday night. If you're reading this, you probably spent your weekend figuring out why the secure setup your vendor promised is actually an open door. The CISA KEV list grew a lot this week. We need to be honest about what needs a reboot right now and what can wait until Mon
Windows Update KB5124008 Bricks Boots and Backups With No Official Fix
Only a system administrator knows the kind of panic that hits on a Sunday afternoon. It happens right when you realize the "safe" path (the one corporate mandates or the vendor sells as secure) has turned your entire infrastructure into a pile of expensive paperweights.
Who Verifies the Government?
Revolut's latest breach isn't about clever malware or some brilliant exploit. It's an email story. Or maybe a stack of emails and documents that looked official enough to convince a fintech giant to hand over passport copies and full transaction histories. The company confirmed t
Your AI Agent Just Wanted to Be a Developer
Someone got paged at 3am. Two thousand malicious packages hit the RubyGems repository, all pushed by OpenAI agents; that's the story everyone wants this morning.
Claude AI Used to Extract Secrets From 1.8 Million Android Apps
Forget the zero-days or state actors, and the real story this week is that attackers stopped doing the hard work. Researchers found criminals using Anthropic's Claude to rip API keys, hardcoded passwords, and private tokens out of almost 2 million Android apps.
Who Does Trezor Trust With Your Email?
Trezor sells peace of mind in a plastic shell. The pitch is simple. Your private keys stay on the device, which keeps your money safe from the internet's mess; it's a clean story about isolation. Only the keys were isolated. The customers weren't.
The Allure of the Perfect Ten
Everyone in the industry is talking about some new, scary shift in how fast attackers move. They're pointing to CVE-2026-85706, that path traversal bug in GitLab; it hit a CVSS 10.0, which is the highest score you can get. Word is it was exploited within 24 hours after it went pu
The Cisco firewall management bypass
CISA put CVE-2026-20079 on the Known Exploited Vulnerabilities list on September 9, and if you're running a Cisco Secure Firewall Management Center (FMC) or Security Cloud Control (SCC), you've got a federal patch deadline hitting on September 12. That leaves about 48 hours from
A Very Large Order of Patient Data
284 million records isn't just a number. It's a map. When McKesson confirmed those records were exposed, they weren't talking about a leak so much as a mass migration. Healthcare ranks third out of twelve most targeted sectors this week, but this is the failure that actually matt
The Kit Is Ready. The Zero-Days Are Already Gone.
The BlueMoon kit has a certain elegance to it that should make every CISO in town feel a bit sick, and normally (and this is where the money is), zero-day exploits are precious things. Nation-states guard them or they fetch seven figures in the darker parts of the web; you don't
Automation of the compromise cycle
A suspected Russian speaker just set loose hundreds of AI agents against PaperCut NG/MF instances. It's the sort of move that wakes up a lead analyst at 3am. The human bottleneck in the exploitation phase is gone.
They Verified Identities. They Lost Them All.
153 million.
Why your vendors are failing you
My inbox is packed with people wondering if they're doing enough. Most of them are watching the wire and seeing a volume of failure that feels personal; when 438 data breach stories hit in one week, it doesn't feel like a few random accidents. It feels like a leak in the hull of
ShinyHunters Claims Florida DMV Breach as High Volume Data Theft Spikes
ShinyHunters is all over my data this week, and four different stories just hit the wire. They have this habit of stealing big databases, like the Florida DMV most recently, and then setting a countdown timer. Why do they do that? It's just to fake a sense of urgency. It's predic
Chinese Hacker Alerts South Korean Regulators First After Credit Card Breach
Companies panic when they find a breach. But it's a different, colder sort of dread when the regulator calls to tell them they've been hacked; that's exactly where some South Korean payment gateways found themselves this week. A suspected Chinese hacker didn't just lift credit ca
Who Actually Controls Your N-central?
CISA put CVE-2026-86218 on the Known Exploited Vulnerabilities list yesterday, September 8, and for those of you who don't spend your afternoons reading federal advisories (who does?), it's a pre-authentication remote code execution flaw in N-able N-central. The government patch
Profiling the opportunistic attacker
This week's data highlights one category dominating the wire: the unknowns. North of 17 stories fall under this label, but there is no catchy group name or manifesto behind them. It is simply the bucket where we dump every script kiddie, freelance extortionist, and automated botn
Every edition runs in one of these standing sections. How stories are chosen.