The Perimeter Site

The Desk · Threats · Breaches · Defenses

Who Pays For 550 Gigabytes?

FulcrumSec just dumped 550GB of data belonging to Manchester Airports Group (MAG). The haul covers 8.8 million people. This is the result of a failed ransom negotiation where MAG decided that paying the attackers was not an option.

Please Upload a Photo of Your ID

The page hits because someone is selling a library of identity. A threat actor on the Nexus platform is currently offering over 153 million stolen driver's licenses and IDs from the US and Canada. This isn't a random scrape of social media profiles. These are high-resolution imag

The Repository Is Trusted. The Admin Token Is Forged.

The binary repository is the center of gravity for any modern engineering organization. It's where the compiled code lives before it hits production, the single source of truth that developers, build servers, and deployment agents trust implicitly. When that trust is weaponized,

The problem with trusting tokens

It's evening here on Wednesday 2 September 2026, and the wire has been loud. We've seen 396 data breach stories this week alone, which tells you that the "secure by design" movement is still mostly a marketing slide deck. When I look at the CISA KEV additions from today, specific

The Deadlines Are Fixed. The Attackers Aren't.

If you’re treating your patch queue as a chronological list, you're doing it wrong. Priority isn't about who screamed loudest in the advisory; it's about who is already inside the house.

Two PaperCut Zero-Days Hit CISA KEV With Two-Week Patch Window

Listen, kid. You’re probably staring at your dashboard and wondering why you should care about a print management tool when there are AI agents going off the rails and routers getting backdoored. It looks boring. Printing is boring. But in this job, "boring" is where the blood is

The Route Was Trusted. The Update Was Malicious.

Attackers have found a way to turn the internet's basic routing protocols into a delivery system for malware. By using BGP hijacking, criminals managed to push a malicious update to users of Virtualizor. For those unfamiliar with the plumbing, BGP is essentially the postal servic

Your S3 Bucket Is Now Public Domain

The page hits at 3am because the egress monitors are screaming. You see a massive spike in outbound traffic from an AWS region that should be quiet. By the time you're caffeinated, you realize it's not a glitch. It's an evacuation.

The fourteen day window for print servers

14.

The hidden cost of healthcare vendors

Healthcare is currently the third most targeted sector on my wire this week, with 140 stories hitting the desk. While government and tech are higher in raw volume, the healthcare numbers are uglier because they're more concentrated. We aren't seeing a thousand small clinics getti

The McKesson data breach and the failure of key management

McKesson has finally confirmed the hit. For a few days, the wire was dominated by claims from ShinyHunters that they had exfiltrated 284 million patient records. Now the company admits it happened. Along with the theft comes a $55 million ransom demand.

Which Patches Actually Matter?

Listen up. Your inbox is currently a disaster zone of "Critical" alerts and vendor warnings that all sound like they're screaming for your firstborn. If you try to treat every CVE as an emergency, you'll burn out by lunch and leave the door wide open for someone who actually know

The cost of fragile frameworks

CVE-2026-66066 is the reason you aren't sleeping tonight.

Is Your Third-Party App a Backdoor?

I’ve spent the afternoon reviewing the wire. There are 401 data breach stories this week, but one is dominating the conversation: the claim that ShinyHunters has exfiltrated 284 million patient records from McKesson. The attackers are demanding $55 million to keep the data quiet.

The Manchester Airports Group data breach

There are two ways to handle a breach of this scale: the honest way, which involves immediate transparency and a very expensive set of lawyers, and the corporate way, which begins with a statement about "taking security seriously" while the forensics team is still trying to figur

Infostealers Hijack Claude Sessions to Drain Credits and Steal Data

The latest warning from Anthropic isn't about some sentient AI breaking its chains or a complex prompt injection attack. It is much more boring than that. Attackers are using standard infostealer malware to grab active session cookies from browsers, allowing them to step right in

The reality of Gitea code injection

Your pager goes off at 3am because your DevOps lead is screaming about CPU usage on the internal git server. You log in to find the cores pegged at 95 percent. A quick look at the process list shows a binary running out of /tmp that doesn't belong there. It isn't a sophisticated

Your Gateway is Currently an Open Door

If you’re reading this on a Sunday morning, there is a high probability you are currently ignoring a notification. Or perhaps you’ve already decided that the risk of a server reboot outweighs the risk of a remote code execution flaw. It's a classic internal trade-off: the immedia

Who Is Actually Counting the Records?

The current wire would have you believe we are witnessing an unprecedented coordinated assault on the healthcare sector. The numbers are designed to trigger panic: 3.75 million patient records exposed in one breach, another 3.75 million via CareCloud, and a further 2.8 million fr

Who's Still Hoarding Millions of Records?

I’ve spent most of my adult life cleaning up digital crime scenes. When I started in the early 2000s, we were dealing with worms like Code Red—things that moved fast and broke things because they could. Today, the speed is still there, but the appetite has changed. Attackers aren

Every edition runs in one of these standing sections. How stories are chosen.