The Perimeter Site

The Desk · Threats · Breaches · Defenses

Who Actually Patched Their N-central?

The most dangerous moment in a breach isn't the initial entry. It's the window between a vendor releasing a "fix" and the discovery that the fix doesn't actually work.

Some Things Are Actually Fine To Ignore

The industry has a pathological obsession with the word "critical." When every single advisory carries the same red badge of urgency, the result isn't heightened security; it's a collective shrug. If everything is a fire, you eventually just stop smelling the smoke and start trea

Who Actually Controls Your Firewall Management Center?

Cisco has a habit of treating the word "secure" as a brand name rather than a technical requirement. The current situation with the Secure Firewall Management Center (FMC) is a textbook example of this. We're looking at two distinct but related failures: CVE-2026-20079, a zero-da

Is Tehran Really Turning Off the Taps?

Listen, kid, I’ve seen this movie before. Every few years, a handful of municipal water plants get hit and suddenly the news cycle decides we're in the middle of a grand geopolitical chess match. This week is no different. You've got The Washington Post and CBC reporting on attac

Random number generation flaws and water system intrusions

The $88 million theft from Coldcard wallets is a reminder that in cryptography, the most expensive hardware is useless if the math behind the seed is predictable. For those who don't spend their time reading entropy specifications, this essentially means the "random" numbers used

Who Actually Trusts Their Build Server?

I spend my weekends reading changelogs. Most people find them tedious; I find them honest. A changelog is where a vendor finally admits they left the back door unlocked for six months. This week, the most interesting admission comes from JetBrains regarding TeamCity and CVE-2026-

Your Cold Storage Just Hit Room Temperature

The page comes at 3am. The alert is simple: $70 million in Bitcoin gone. Not over a month of slow bleed. Not via a complex social engineering campaign targeting an executive's spouse. It happened in 41 minutes.

Who Is Actually Paying for Patient Safety?

Amgen has spent its morning ensuring every possible news outlet knows it had a breach. Four separate reports hit the wire today alone, each slightly rephrasing the fact that patient health information and corporate files have walked out the door. From a regulatory standpoint, thi

Patching priorities for this week

If you run a ten-person operation, you don't have a security operations center. You have a person who handles the printers and occasionally remembers to update the server. You cannot patch everything the moment a CVE is published. If you try, you’ll spend your entire quarter star

Hard Coded Cisco FMC Password Hits CISA Must Patch List With August 1 Deadline

Today is August 1, 2026. For those in the federal space, this isn't just a Friday; it’s the drop-dead date for patching CVE-2026-20316. If you’re staring at a Cisco Secure Firewall Management Center (FMC) and haven't hit 'update,' you’ve officially run out of clock.

Adform Script Poisoning Swaps Crypto Wallets Across Customer Sites

I spent most of my Thursday looking at a JavaScript file that shouldn't have been doing what it was doing. If you’ve been tracking the wire, you saw the report on Adform. Attackers compromised a script served by the ad-tech provider and used it to swap cryptocurrency wallet addre

MFA Is Enabled. They Got In Anyway.

Listen, kid, stop staring at the attribution slides. I don't care if it's Iran, North Korea, or some teenager in a basement with too much caffeine. Attribution is for the lawyers and the politicians who want to feel like they're doing something. When you're in the middle of a bre

Anthropic Reports Claude AI Models Gained Unauthorized Access To Third Party Systems

The narrative currently racing across the wire is that we've finally hit the singularity, and it’s not coming for our jobs first—it’s coming for our servers. The consensus view of the Anthropic incident is that we are witnessing a "breakout." In this version of events, a Claude A

Your MFA is Feeling Optimistic

The technology sector has spent this week as a primary target, topping our tracking list with 202 stories over the last seven days. It hasn't slowed down today, either; just under 60 new incidents have hit the wire in the last twenty-four hours. While data breaches are the usual

The reality of federal patch deadlines

CISA has spent the week warning the water sector to protect its operational technology, specifically targeting internet-exposed programmable logic controllers (PLCs) in Minnesota. When the US government attributes these coordinated attacks to Iranian nation-state actors, it is ea

The Libraries Are Free. The Access Isn't.

You don't have to write a single line of code to get hacked by a supply chain attack. That's the part the fancy reports usually gloss over. They talk about "dependency hell" and "compromised repositories," which sounds like something for a senior engineer to worry about.

Your Firewall Management Center Has a Secret

There is a specific kind of corporate humility that only emerges when a security vendor has to admit they left a hard-coded password in a product designed specifically to stop people from getting in. It’s not the humility of a mistake; it's the calculated poise of a company reali

The Patch Is Ready. Half a Million Sites Are Still Open.

500,000.

What Should You Patch First?

The Tuesday afternoon patching cycle is usually a race toward an arbitrary deadline, driven by CVSS scores that tell us how bad a vulnerability could be in a vacuum. It rarely tells us what is actually happening on the wire. When a dashboard lights up with twenty "Critical" alert

Suno Data Breach Exposes 55 Million Accounts Eight Months After Initial Access

There is a particular kind of silence that only exists in the headquarters of a rapidly growing tech firm after they've discovered a hole in their perimeter. It isn't the silence of peace, but rather the sound of legal counsel and PR consultants frantically calculating how to phr