The Patch Is Public. The Servers Are Still Open.
This is what pages me at 3am. An unauthenticated improper access control flaw in Oracle WebLogic and its HTTP Server Proxy Plug-in. CVE-2026-21962. CISA added it to the KEV list on August 24. For federal agencies, the patch deadline is August 27. That gives them roughly 72 hours
Sanctions Are Live. The Power Plants Are Still Open.
The official line from Washington and London is that the new sanctions on Iranian actors—specifically those linked to the Mabna Institute and MOIS—are a victory for deterrence. The logic is straightforward: by naming names, freezing assets, and making it diplomatically expensive
Automotive head units as botnet proxies
The MoYu Group has found a way to turn car dashboards into infrastructure for ad fraud. By exploiting a software update vulnerability in DoFun car head units, they've integrated these devices into the BadBox botnet. This isn't about stealing GPS coordinates or remotely braking ca
Medusa Has a Very Productive Calendar
Nine stories in seven days. If Medusa were a junior analyst on my team, I’d be worried about their burnout rate. In the world of ransomware gangs, however, that volume suggests a group that has moved past the "experimental" phase and into a streamlined industrial process.
It Stayed Dark for Four Days. The Blame Is Now Political.
Listen up. If you’re reading this because you think a "state-sponsored actor" is a magic word that excuses a total operational collapse, close the tab. I don't care if the attackers had a government budget and a custom toolkit; once they're inside your house, the only thing that
Half Your Neighbors Are Now Public Record
50%.
Automation in industrial controls and medical data exposure
The U.S. government is warning about AI-powered attacks on internet-exposed Siemens S7 Series PLCs. Most people use 'AI' to describe a chatbot that can’t count its own fingers, but we're talking about the automation of reconnaissance and exploit delivery against critical infrastr
Entra ID Remote Code Execution and Zimbra Command Injection Top August Patch List
An RCE in Microsoft Entra ID with a CVSS 10.0 that's already being used in the wild. That pages me at 3am. It's not just about a single server going dark. When your identity provider is compromised, every SaaS app tied to that tenant becomes an open door.
The reality of patching VMware vCenter
The US federal government is currently in breach of its own deadlines. According to the CISA Known Exploited Vulnerabilities (KEV) list, the deadline for agencies to patch CVE-2026-59310 was 21 August. Today is Monday, 24 August. While we cannot peer directly into the server room
The cost of centralizing student data in Italy
The group calling themselves xpl0itrs claims to have walked away with 6.1 TB of data from Spaggiari, a provider serving over 3,000 Italian schools. When you see a number like 6.1 terabytes, don't let the volume distract you. In the context of school records—mostly PDFs, spreadshe
The Patch Is Public. The Attackers Already Have It.
Sunday evening is usually for dread, but for those of us tracking the CISA Known Exploited Vulnerabilities (KEV) list, it's about triage. We have a handful of deadlines hitting tomorrow, August 24, and a few that already expired on Friday. If you're looking at your console and se
Your Dashboard Has New Roommates
Your car just became a proxy botnet node. That's what would page me at 3am.
Is One Billion the New Zero?
The narrative on the wire this week is simple: China just suffered a cybersecurity collapse of biblical proportions. Over 1 billion people have had their data exposed. To most analysts, this is the gold standard of catastrophic failure—a sovereign state unable to protect its own
Zimbra’s Guide to Open-Door Policies
The notification from CISA arrived on Friday, 21 August. For the uninitiated, receiving a Known Exploited Vulnerability (KEV) alert on a Friday afternoon is a particular kind of administrative cruelty. It transforms a quiet weekend into a frantic scramble for logs and version num
Great at Theft, Bad at Branding
Listen up. If you’re looking for a spooky name to put in your slide deck this week, you’re going to be disappointed. The most active actor on the wire right now is listed as "Unknown."
Patching priorities for late August
If you're checking your dashboard this morning and seeing a sea of red "Critical" labels, take a breath and ignore them. Most vendors use that word to describe any bug that allows an attacker to do something they aren't supposed to do. In my book, critical is earned when the expl
The Keys Were Public. The Accounts Were Open.
The most surprising thing on the wire this morning isn't a sophisticated zero-day or a state-sponsored APT utilizing a novel side-channel attack. It's the fact that hundreds of corporate AWS access keys are currently floating around in the open, granting full administrative contr
Healthcare is currently the primary target for extortion
Healthcare has a peculiar relationship with risk. For years, the industry's approach to security was dominated by the availability pillar of the CIA triad—systems had to stay up so patients didn't die. This focus on uptime often came at the expense of confidentiality. Today, that
The problem with patching VMware vCenter
Today is August 21. For a significant number of sysadmins, it's the day the music stops. That’s the federal patch deadline for CVE-2026-59310, a path traversal vulnerability in Broadcom VMware vCenter. CISA added it to the Known Exploited Vulnerabilities catalog on August 18.
Your phone is a bridge for attackers
The most interesting thing on the wire this week isn't a massive breach of a Fortune 500 company, though we have plenty of those. It’s a piece of Android malware called Manic. Most criminals want to get into your network via a phishing email or a leaky VPN. Manic does something d
Every edition runs in one of these standing sections. How stories are chosen.