The Federal Government Is Now Officially Behind Schedule
CISA sets deadlines like they actually believe bureaucracy works fast. They added a few things to this week's Known Exploited Vulnerabilities list and gave federal agencies until September 5 to fix them. It's Monday evening, September 7 now. In the world of regulatory compliance,
They Build for the Long Haul. Their Security Failed in an Instant.
13,000,000.
The high cost of trust in remote management
Hackers stopped trying to pick locks since they can just trick you into handing over the master key. The real story on the wire isn't how much data they stole, but how they got it. There is a worm-like campaign out there using modified ScreenConnect clients and a file transfer vu
The Patch Cycle Accelerated. The Exploits Moved Faster.
Tech takes the hit this week with 341 stories. It makes sense. The same tools we use to run our gear are what hackers use to tear it down, and two things stand out right now: Mathspace and the mess with N-able's N-central.
Critical Infrastructure Was Hardened. Medusa Hit 500 Organizations Anyway.
500.
The risk of ignoring the print server
It's a common ritual in institutional IT. You buy an appliance—a piece of software that comes bundled with a promise of "set it and forget it"—and you tuck it away in a VLAN where you hope it'll stay quiet. For years, PaperCut NG/MF has lived in this blind spot. It manages the pr
Shipping partners and Magento zero days
The pursuit of absolute security usually ends in a spreadsheet owned by a third party. Trezor users spent years convincing themselves that hardware wallets are the final word in asset protection because they keep keys offline. That holds true for the private keys, but it doesn't
A Very Efficient Way to Leak Eight Million People
The Manchester Airports Group (MAG) has managed to do in one fell swoop what usually takes a dozen smaller breaches: they’ve turned 8.8 million travelers into an open directory. When the data hit the wire, the reaction followed the standard corporate script. There were mentions o
Unauthenticated SSH Flaw Gives Attackers Full Control of MikroTik Routers
I spent my morning looking at the wire. There are 30 data breach stories today alone. If you're running a ten-person shop, that number is noise. What isn't noise is the "MikroTrick" chain hitting MikroTik routers. It allows attackers to take full administrative control via SSH wi
Your Boarding Pass Is Now Public Domain
8.8 million.
Who Is Still Trusting Their Print Server?
Print servers are basically the forgotten closets of any enterprise. They just sit there in some quiet corner of the network, getting completely ignored by everyone who isn't currently fighting with a jammed tray or hunting for a missing toner cartridge; we end up treating them l
Profiling this week's most active threat actor
Twenty-nine stories. That's how many times an "unknown" ransomware gang appeared in the data this week.
The cost of centralized identity verification
The FBI is investigating a breach. More than 170 million people in North America are affected, and most of this, about 153 million records, seems to be driver's license data tied to IDScan. Why do we always assume the worst? When a set of data this big leaks, the industry looks f
Why Is Your Print Server a Domain Admin?
Sit down. Stop staring at that dashboard for five minutes. The colors don't mean anything. All that matters is if you can kill a process on a remote host without a system you didn't know existed shouting permission denied in your face.
The Patch is Out. The Breach Already Happened.
Chrome V8 type confusion. CVE-2026-85046. It’s the sixth zero-day Google has patched this year. CISA added it to the KEV on September 4. Federal deadline for patching is September 18. If you're seeing "Update available" in the browser, your users are already sitting ducks.
Who Is Still Running Elementor Pro?
440,000.
Three Cisco Nexus 9000 Flaws Allow Remote Root Access as KEV Grows
The Monday morning ritual for most security teams is a slow drift through a sea of CVEs, looking for a reason to tell the production lead that they need to take systems offline. The production lead's incentive is simple: zero downtime. The security team's incentive is slightly mo
Patient Records Are Gold. The Locks Are Plastic.
Healthcare is currently sitting at number three on the targeting list, with 143 stories hitting the wire this week. That's not a fluke or a seasonal spike. It's a targeted harvest. When you look at the numbers, it's clear that attackers aren't just looking for a quick ransomware
The cost of trusting identity verification vendors
Listen, kid. When you see a press release from a security vendor claiming their process is "sophisticated," I want you to immediately assume they've built a gold-plated honeypot for the most motivated criminals on the planet. They aren't selling you a shield; they're selling you
The problem with database encryption
The news out of South Korea this evening is grim. Tving, one of the region's biggest streaming services, has leaked approximately 39.54 million user accounts. It fits into a wider, noisier week where we've seen 429 data breach stories, 110 of which hit just today. Along with Tvin
Every edition runs in one of these standing sections. How stories are chosen.