The Perimeter Site

The Desk · Threats · Breaches · Defenses

The Cisco firewall management bypass

CISA put CVE-2026-20079 on the Known Exploited Vulnerabilities list on September 9, and if you're running a Cisco Secure Firewall Management Center (FMC) or Security Cloud Control (SCC), you've got a federal patch deadline hitting on September 12. That leaves about 48 hours from

A Very Large Order of Patient Data

284 million records isn't just a number. It's a map. When McKesson confirmed those records were exposed, they weren't talking about a leak so much as a mass migration. Healthcare ranks third out of twelve most targeted sectors this week, but this is the failure that actually matt

The Kit Is Ready. The Zero-Days Are Already Gone.

The BlueMoon kit has a certain elegance to it that should make every CISO in town feel a bit sick, and normally (and this is where the money is), zero-day exploits are precious things. Nation-states guard them or they fetch seven figures in the darker parts of the web; you don't

Automation of the compromise cycle

A suspected Russian speaker just set loose hundreds of AI agents against PaperCut NG/MF instances. It's the sort of move that wakes up a lead analyst at 3am. The human bottleneck in the exploitation phase is gone.

They Verified Identities. They Lost Them All.

153 million.

Why your vendors are failing you

My inbox is packed with people wondering if they're doing enough. Most of them are watching the wire and seeing a volume of failure that feels personal; when 438 data breach stories hit in one week, it doesn't feel like a few random accidents. It feels like a leak in the hull of

ShinyHunters Claims Florida DMV Breach as High Volume Data Theft Spikes

ShinyHunters is all over my data this week, and four different stories just hit the wire. They have this habit of stealing big databases, like the Florida DMV most recently, and then setting a countdown timer. Why do they do that? It's just to fake a sense of urgency. It's predic

Chinese Hacker Alerts South Korean Regulators First After Credit Card Breach

Companies panic when they find a breach. But it's a different, colder sort of dread when the regulator calls to tell them they've been hacked; that's exactly where some South Korean payment gateways found themselves this week. A suspected Chinese hacker didn't just lift credit ca

Who Actually Controls Your N-central?

CISA put CVE-2026-86218 on the Known Exploited Vulnerabilities list yesterday, September 8, and for those of you who don't spend your afternoons reading federal advisories (who does?), it's a pre-authentication remote code execution flaw in N-able N-central. The government patch

Profiling the opportunistic attacker

This week's data highlights one category dominating the wire: the unknowns. North of 17 stories fall under this label, but there is no catchy group name or manifesto behind them. It is simply the bucket where we dump every script kiddie, freelance extortionist, and automated botn

Why Did They Keep 220 Million Passports?

The most staggering number on the wire this morning isn't a CVSS score or a ransom demand. It's nine years.

Is WeWorm Actually a Worm?

People are panicking on the wire this week. They found WeWorm, a zero-click exploit that spreads via WeChat calls on Android and iOS, and now everyone is calling it a return of the mobile epidemic. The logic makes sense. If an attacker hits a device without any user action and th

Which Zero-Day Actually Matters?

The industry has an obsession with the word "critical" that's made it useless, and every vendor wants their advisory to scream from the rooftops (usually because they found a flaw that might lead to remote code execution). There's a catch. A dozen specific conditions have to be m

Mathspace and the Metabase failure

If you're checking the wires this morning and wondering why Education ranks 5 out of 14 for targeted sectors, look at Mathspace, and they just leaked data on 1.07 million students and parents. Calling this a "security incident" is too kind. It's an architectural failure.

Your e-commerce platform is not a black box

Look at what's on the wire this morning; the sheer volume of stolen data isn't what surprises me. It's the tools doing the stealing. Attackers are using a zero-day vulnerability in Adobe Commerce and Magento (they've named it StyleSmuggler) to drop Rust-based backdoors into onlin

The Federal Government Is Now Officially Behind Schedule

CISA sets deadlines like they actually believe bureaucracy works fast. They added a few things to this week's Known Exploited Vulnerabilities list and gave federal agencies until September 5 to fix them. It's Monday evening, September 7 now. In the world of regulatory compliance,

They Build for the Long Haul. Their Security Failed in an Instant.

13,000,000.

The high cost of trust in remote management

Hackers stopped trying to pick locks since they can just trick you into handing over the master key. The real story on the wire isn't how much data they stole, but how they got it. There is a worm-like campaign out there using modified ScreenConnect clients and a file transfer vu

The Patch Cycle Accelerated. The Exploits Moved Faster.

Tech takes the hit this week with 341 stories. It makes sense. The same tools we use to run our gear are what hackers use to tear it down, and two things stand out right now: Mathspace and the mess with N-able's N-central.

Critical Infrastructure Was Hardened. Medusa Hit 500 Organizations Anyway.

500.

Every edition runs in one of these standing sections. How stories are chosen.