PostgreSQL Extension Vulnerability Enables Remote Code Execution at Multiple Managed Database Providers
A researcher went looking for a managed Postgres provider and instead found a way to execute code on the servers of NeonDB, Supabase, and Xata. The culprit wasn't a failure in the core database engine or a mistake by these specific companies. It was a vulnerability in a widely us
The risk of shipping encrypted hardware
14,000.
Old Code Lives On. New Targets Fall Fast.
Twenty stories in a single week is not a trend. It's an obsession. Gunra has spent the last seven days dominating my wire, appearing in some 26 separate reports if you count the overlapping aliases. Most ransomware groups prefer to operate in the shadows until the ransom note hit
TeamPCP Supply Chain Attack Hits North of 2500 Organizations via Trivy and LiteLLM
Listen up, because you're going to see this pattern for the next decade if we don't stop pretending that "trusted" tools are actually trustworthy.
The Pipeline Is Automated. The Poison Is Efficient.
Technology is currently the most targeted sector on my wire, ranking #1 of 16 with 333 stories this week alone. That isn't just a high number; it's an obsession. While government and healthcare usually fight for the spotlight because they have "critical" infrastructure, a word I
Your Dev Pipeline Has a New Passenger
2,500.
Reverse SSH Exploits Hit VMware vCenter Management Layer in Global Campaign
The wire is currently screaming about a "global threat campaign" targeting a critical remote code execution flaw in VMware vCenter. The consensus narrative is straightforward: we are facing a sophisticated, high-tier offensive where attackers are using RCE to establish reverse SS
Who Actually Controls Belgium's eID?
Belgium's national eID authentication system has a hole that allows for remote code execution on citizen accounts. This isn't some theoretical academic paper or a low-impact bug. It's an RCE in the very mechanism used to prove who a person is to the state. When you compromise the
The Deadline is Fixed. The Window Stays Open.
CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities (KEV) catalogue on 2026-08-11. For those who don't spend their Tuesdays reading federal bulletins, this is the official signal that a bug isn't just theoretical; it's being used in the wild. Along with the listing c
Ten days of downtime
10. That is the number of days the JPS network has been offline following a suspected breach.
Your Firewall is Feeling Neglected
The weekly ritual of the patch cycle is less about security and more about the performative management of anxiety. Every sysadmin has a dashboard that looks like a crime scene, bleeding red alerts across a dozen different vendors. The instinctive reaction is to treat it as a chec
The Firewall Was Active. Gunra Walked In Anyway.
The reports coming off the wire this week regarding Gunra ransomware are frustratingly predictable. We're seeing a surge in activity, 19 distinct stories in the last seven days alone, focused on critical infrastructure breaches via Fortinet vulnerabilities. For the uninitiated, t
Who Actually Has 14 Days to Patch?
Fourteen.
Which Patch Stops Lazarus?
Microsoft just dumped a mountain of updates on us, and CISA is adding to the pile. For the sysadmin staring at a dashboard full of red alerts, the instinct is to panic-patch everything. That's a great way to break your production environment and spend your weekend in a cold serve
Who's Letting Lazarus in the Back Door?
Microsoft just dropped its August Patch Tuesday update, fixing 421 CVEs. For most of us running a ten-person shop, that number is white noise. You can't possibly track four hundred different holes in your software. You just hit "Update" and hope for the best. But if you're ignori
Who's Actually Holding Your Health Records?
If you've spent any time in a waiting room lately, you've signed your life away. You sign a stack of digital forms promising that your data is secure, consenting to "third-party processing" for the sake of efficiency. You think you're trusting your doctor. In reality, you're trus
The cost of a dental record
15 million.
Your Perimeter Has an Open Door Policy
Microsoft just dropped its August Patch Tuesday update, fixing 421 CVEs. In the middle of that noise is CVE-2026-68820, a kernel-mode driver flaw already being used in the wild. Most security teams will spend their week staring at that number, 421, and wondering which ones to pri
The Turbine Stopped. The Network Was Private.
The most interesting failure of the day didn't happen in a cloud instance or a corporate mail server. It happened in Poland, where an attacker managed to shut down a steam turbine at a power plant. The elegance of the move was almost admirable: they didn't go through the front do
Your Managed Service Provider Has a New Guest
Listen up, kid. I want you to stop looking at the fancy telemetry for a second and look at the KEV list from August 4th. Specifically, CVE-2026-18556. It’s an authentication bypass in N-able N-central.
Every edition runs in one of these standing sections. How stories are chosen.