The Perimeter Site

The Desk · Threats · Breaches · Defenses

Over 335 Million Records Stolen from Philippine Public Sector in H1 2026

The government sector is currently #1 in our tracking for the week, with 242 stories associated with it. That's not just a spike; it's a sustained assault on public administration. While we often focus on the "crown jewels" of intelligence—classified blueprints or diplomatic cabl

The Patch is Live. The Miners are Already In.

Your pager goes off at 3am because your build server is screaming. CPU usage is pegged at 98 percent across all cores. You check the process list and find a binary you don't recognize running out of /tmp, chewing through cycles to mine Monero. This is how CVE-2026-60004 starts.

The risk of hoarding customer data

12.9 million.

Patch priority for the final week of August

Friday is usually the day security teams pretend they've won the week so they can go home and forget the vulnerabilities they ignored on Tuesday. But if you're looking at your dashboard this morning, you'll see that CISA isn't interested in your weekend plans.

Your Personal Cloud is Now a Public Library

The Philippine nuclear research body recently discovered that its internal records weren't so internal after all. They were running ownCloud, and attackers used CVE-2023-49105 to walk right through the front door.

PaperCut Emergency Patches Hit as Attackers Chain Flaws for Remote Code Execution

Listen up. It's Tuesday. In the world of incident response, Tuesday is usually when the wheels fall off. My inbox this morning looks like a digital crime scene, and if you’re feeling overwhelmed, you aren't alone. There have been 380 stories about data breaches this week alone. T

The Perils of Printing in Public

There is a particular kind of silence that descends upon an IT department when they realise the breach didn't come through the firewall, the email gateway, or a sophisticated phishing campaign targeting the CFO. Instead, it came through the printer management software.

Who Is Really Behind Qilin?

The U.S. ATF just confirmed a "major incident" involving its investigative data. The group claiming the win is Qilin. For most of you, the ATF is just another government agency with a badge and a budget you'll never see. But for those of us running ten-person shops, this hit is a

The cost of 284 million patient records

ShinyHunters is claiming they have data on 284 million patients from McKesson. If that number holds, it's not just one of the larger breaches of the year; it's a systemic failure of scale. When you manage data for nearly 300 million people, the margin for error disappears. You ca

Which Fire Do You Put Out First?

Look at your screen. Now look at the list of CVEs that hit your inbox this morning. If you’re feeling a creeping sense of panic, good. That means you've finally stopped trusting the vendor's "low-to-moderate" ratings and started realizing that any hole in the fence is just an inv

The Gear Is Certified. The Shipments Stopped.

Boston Scientific is currently unable to ship medical devices. We don’t have a precise number for the backlog yet, but reports indicate weeks of delays in delivery to hospitals. This is where the abstract nature of "cyber risk" vanishes and becomes an operational failure with a h

8.7 Million Records Gone. The Flights Still Took Off.

8.7 million.

Who's Really Guarding the Gateway?

CISA added CVE-2026-8452 to the Known Exploited Vulnerabilities list on August 26. For federal agencies, the deadline to patch is August 29. That is a 72-hour window to secure the very front door of the enterprise.

What to do when the big guys get hit

My inbox this week looks like a disaster zone. There were 404 stories about data breaches in the last seven days alone. For most of you, that's just noise. You aren't running an airport or a global clothing brand. You don't have a SOC to monitor traffic or a legal team on retaine

The Patches Are Out. The Gear Is Still Broken.

I spend my mornings reading changelogs because they're more honest than press releases. A vendor will tell you a patch "improves stability," while the CVE entry reveals it actually stops an unauthenticated attacker from owning your kernel. This week, CISA added ten entries to the

The Infrastructure Is Gone. The Data Stays Stolen.

The US government just spent a lot of political capital announcing they tore down the QTFY hacking platform. They’re talking about QScan and QTRouter like they just dismantled a nuclear facility. They'll tell you it's a win for the Federal Reserve, the DOJ, and the Senate.

The Edge Is Trusted. The Trust Is Misplaced.

The NetScaler ADC and Gateway are not just pieces of software; they are the front doors to the enterprise. When a company puts a Citrix appliance at its edge, it's essentially telling the rest of the network, "I trust this box to decide who gets in." CVE-2026-8452 is what happens

A Very Thorough Physical for 3.75 Million People

CareCloud has finally put a number on the damage: 3.75 million patients. It is a tidy figure, the kind of number that looks purposeful in a press release but feels like an avalanche when you are the one whose medical history is now a commodity on a dark-web forum. In the world of

Which Hole Are You Ignoring?

If you’re staring at a dashboard of red alerts and feeling paralyzed, stop. Most of what you're seeing is noise. The industry has developed a habit of treating every CVSS 9.8 like a house fire, but in reality, some are just loud alarms in empty rooms while the basement is actuall

The problem with exposed code servers

If you’re running your own Gitea instance and it's facing the public internet, stop reading this and go patch it. Now.

Every edition runs in one of these standing sections. How stories are chosen.