Chinese Hacker Alerts South Korean Regulators First After Credit Card Breach
Companies panic when they find a breach. But it's a different, colder sort of dread when the regulator calls to tell them they've been hacked; that's exactly where some South Korean payment gateways found themselves this week. A suspected Chinese hacker didn't just lift credit ca
Who Actually Controls Your N-central?
CISA put CVE-2026-86218 on the Known Exploited Vulnerabilities list yesterday, September 8, and for those of you who don't spend your afternoons reading federal advisories (who does?), it's a pre-authentication remote code execution flaw in N-able N-central. The government patch
Profiling the opportunistic attacker
This week's data highlights one category dominating the wire: the unknowns. North of 17 stories fall under this label, but there is no catchy group name or manifesto behind them. It is simply the bucket where we dump every script kiddie, freelance extortionist, and automated botn
Why Did They Keep 220 Million Passports?
The most staggering number on the wire this morning isn't a CVSS score or a ransom demand. It's nine years.
Is WeWorm Actually a Worm?
People are panicking on the wire this week. They found WeWorm, a zero-click exploit that spreads via WeChat calls on Android and iOS, and now everyone is calling it a return of the mobile epidemic. The logic makes sense. If an attacker hits a device without any user action and th
Which Zero-Day Actually Matters?
The industry has an obsession with the word "critical" that's made it useless, and every vendor wants their advisory to scream from the rooftops (usually because they found a flaw that might lead to remote code execution). There's a catch. A dozen specific conditions have to be m
Mathspace and the Metabase failure
If you're checking the wires this morning and wondering why Education ranks 5 out of 14 for targeted sectors, look at Mathspace, and they just leaked data on 1.07 million students and parents. Calling this a "security incident" is too kind. It's an architectural failure.
Your e-commerce platform is not a black box
Look at what's on the wire this morning; the sheer volume of stolen data isn't what surprises me. It's the tools doing the stealing. Attackers are using a zero-day vulnerability in Adobe Commerce and Magento (they've named it StyleSmuggler) to drop Rust-based backdoors into onlin
The Federal Government Is Now Officially Behind Schedule
CISA sets deadlines like they actually believe bureaucracy works fast. They added a few things to this week's Known Exploited Vulnerabilities list and gave federal agencies until September 5 to fix them. It's Monday evening, September 7 now. In the world of regulatory compliance,
They Build for the Long Haul. Their Security Failed in an Instant.
13,000,000.
The high cost of trust in remote management
Hackers stopped trying to pick locks since they can just trick you into handing over the master key. The real story on the wire isn't how much data they stole, but how they got it. There is a worm-like campaign out there using modified ScreenConnect clients and a file transfer vu
The Patch Cycle Accelerated. The Exploits Moved Faster.
Tech takes the hit this week with 341 stories. It makes sense. The same tools we use to run our gear are what hackers use to tear it down, and two things stand out right now: Mathspace and the mess with N-able's N-central.
Critical Infrastructure Was Hardened. Medusa Hit 500 Organizations Anyway.
500.
The risk of ignoring the print server
It's a common ritual in institutional IT. You buy an appliance—a piece of software that comes bundled with a promise of "set it and forget it"—and you tuck it away in a VLAN where you hope it'll stay quiet. For years, PaperCut NG/MF has lived in this blind spot. It manages the pr
Shipping partners and Magento zero days
The pursuit of absolute security usually ends in a spreadsheet owned by a third party. Trezor users spent years convincing themselves that hardware wallets are the final word in asset protection because they keep keys offline. That holds true for the private keys, but it doesn't
A Very Efficient Way to Leak Eight Million People
The Manchester Airports Group (MAG) has managed to do in one fell swoop what usually takes a dozen smaller breaches: they’ve turned 8.8 million travelers into an open directory. When the data hit the wire, the reaction followed the standard corporate script. There were mentions o
Unauthenticated SSH Flaw Gives Attackers Full Control of MikroTik Routers
I spent my morning looking at the wire. There are 30 data breach stories today alone. If you're running a ten-person shop, that number is noise. What isn't noise is the "MikroTrick" chain hitting MikroTik routers. It allows attackers to take full administrative control via SSH wi
Your Boarding Pass Is Now Public Domain
8.8 million.
Who Is Still Trusting Their Print Server?
Print servers are basically the forgotten closets of any enterprise. They just sit there in some quiet corner of the network, getting completely ignored by everyone who isn't currently fighting with a jammed tray or hunting for a missing toner cartridge; we end up treating them l
Profiling this week's most active threat actor
Twenty-nine stories. That's how many times an "unknown" ransomware gang appeared in the data this week.
Every edition runs in one of these standing sections. How stories are chosen.