The Perimeter Site

The Desk · Threats · Breaches · Defenses

The Patch Is Public. The Servers Are Still Open.

This is what pages me at 3am. An unauthenticated improper access control flaw in Oracle WebLogic and its HTTP Server Proxy Plug-in. CVE-2026-21962. CISA added it to the KEV list on August 24. For federal agencies, the patch deadline is August 27. That gives them roughly 72 hours

Sanctions Are Live. The Power Plants Are Still Open.

The official line from Washington and London is that the new sanctions on Iranian actors—specifically those linked to the Mabna Institute and MOIS—are a victory for deterrence. The logic is straightforward: by naming names, freezing assets, and making it diplomatically expensive

Automotive head units as botnet proxies

The MoYu Group has found a way to turn car dashboards into infrastructure for ad fraud. By exploiting a software update vulnerability in DoFun car head units, they've integrated these devices into the BadBox botnet. This isn't about stealing GPS coordinates or remotely braking ca

Medusa Has a Very Productive Calendar

Nine stories in seven days. If Medusa were a junior analyst on my team, I’d be worried about their burnout rate. In the world of ransomware gangs, however, that volume suggests a group that has moved past the "experimental" phase and into a streamlined industrial process.

It Stayed Dark for Four Days. The Blame Is Now Political.

Listen up. If you’re reading this because you think a "state-sponsored actor" is a magic word that excuses a total operational collapse, close the tab. I don't care if the attackers had a government budget and a custom toolkit; once they're inside your house, the only thing that

Half Your Neighbors Are Now Public Record

50%.

Automation in industrial controls and medical data exposure

The U.S. government is warning about AI-powered attacks on internet-exposed Siemens S7 Series PLCs. Most people use 'AI' to describe a chatbot that can’t count its own fingers, but we're talking about the automation of reconnaissance and exploit delivery against critical infrastr

Entra ID Remote Code Execution and Zimbra Command Injection Top August Patch List

An RCE in Microsoft Entra ID with a CVSS 10.0 that's already being used in the wild. That pages me at 3am. It's not just about a single server going dark. When your identity provider is compromised, every SaaS app tied to that tenant becomes an open door.

The reality of patching VMware vCenter

The US federal government is currently in breach of its own deadlines. According to the CISA Known Exploited Vulnerabilities (KEV) list, the deadline for agencies to patch CVE-2026-59310 was 21 August. Today is Monday, 24 August. While we cannot peer directly into the server room

The cost of centralizing student data in Italy

The group calling themselves xpl0itrs claims to have walked away with 6.1 TB of data from Spaggiari, a provider serving over 3,000 Italian schools. When you see a number like 6.1 terabytes, don't let the volume distract you. In the context of school records—mostly PDFs, spreadshe

The Patch Is Public. The Attackers Already Have It.

Sunday evening is usually for dread, but for those of us tracking the CISA Known Exploited Vulnerabilities (KEV) list, it's about triage. We have a handful of deadlines hitting tomorrow, August 24, and a few that already expired on Friday. If you're looking at your console and se

Your Dashboard Has New Roommates

Your car just became a proxy botnet node. That's what would page me at 3am.

Is One Billion the New Zero?

The narrative on the wire this week is simple: China just suffered a cybersecurity collapse of biblical proportions. Over 1 billion people have had their data exposed. To most analysts, this is the gold standard of catastrophic failure—a sovereign state unable to protect its own

Zimbra’s Guide to Open-Door Policies

The notification from CISA arrived on Friday, 21 August. For the uninitiated, receiving a Known Exploited Vulnerability (KEV) alert on a Friday afternoon is a particular kind of administrative cruelty. It transforms a quiet weekend into a frantic scramble for logs and version num

Great at Theft, Bad at Branding

Listen up. If you’re looking for a spooky name to put in your slide deck this week, you’re going to be disappointed. The most active actor on the wire right now is listed as "Unknown."

Patching priorities for late August

If you're checking your dashboard this morning and seeing a sea of red "Critical" labels, take a breath and ignore them. Most vendors use that word to describe any bug that allows an attacker to do something they aren't supposed to do. In my book, critical is earned when the expl

The Keys Were Public. The Accounts Were Open.

The most surprising thing on the wire this morning isn't a sophisticated zero-day or a state-sponsored APT utilizing a novel side-channel attack. It's the fact that hundreds of corporate AWS access keys are currently floating around in the open, granting full administrative contr

Healthcare is currently the primary target for extortion

Healthcare has a peculiar relationship with risk. For years, the industry's approach to security was dominated by the availability pillar of the CIA triad—systems had to stay up so patients didn't die. This focus on uptime often came at the expense of confidentiality. Today, that

The problem with patching VMware vCenter

Today is August 21. For a significant number of sysadmins, it's the day the music stops. That’s the federal patch deadline for CVE-2026-59310, a path traversal vulnerability in Broadcom VMware vCenter. CISA added it to the Known Exploited Vulnerabilities catalog on August 18.

Your phone is a bridge for attackers

The most interesting thing on the wire this week isn't a massive breach of a Fortune 500 company, though we have plenty of those. It’s a piece of Android malware called Manic. Most criminals want to get into your network via a phishing email or a leaky VPN. Manic does something d

Every edition runs in one of these standing sections. How stories are chosen.