The Perimeter Site

The Desk · Threats · Breaches · Defenses

Who is Mapping the Electorate?

Attribution is rarely a science. It’s a Venn diagram of forensic artifacts, geopolitical timing, and a healthy dose of wishful thinking. When a former president declassifies intelligence to announce a "massive" breach of voter data, the industry reflex is to look for the malware.

The Fences are High. The Gates are Open.

The targeting table doesn't lie, even if the press releases do. Government has reclaimed the #2 spot out of 15 sectors this week, with 214 separate stories hitting the wire. Today alone, 44 new incidents were logged.

The Reactor is Stable. The Data is Gone.

There is a specific kind of panic that accompanies the words "nuclear power plant" in a security briefing. Usually, the panic is about centrifuges spinning the wrong way or valves opening when they shouldn't. But in India, the reports coming out of the Kudankulam plant are more b

The cost of a broken cold chain

KFC is missing its chicken. Supermarkets in Japan are staring at empty shelves. This isn't a supply chain glitch or a sudden poultry shortage. It's the result of a cyberattack on Nichirei Logistics Group, the largest cold-chain operator in Japan.

Texas Secures 150 Million Dollar Settlement Against 23andMe Over Genetic Data Breach

$150 million.

Who is Poisoning the Well?

The targeting table is a blunt instrument, but this week it's screaming. The technology sector has reclaimed the top spot, ranking #1 of 15. We're looking at 266 separate stories over the last seven days, with 102 new incidents hitting the wire today alone.

The Perimeter's Most Productive Ghost

There is a particular kind of silence that descends upon a corporate network just before the telemetry starts screaming. It is the silence of the "Unknown" actor.

CISA Sets Three-Day Patch Window for SharePoint Server Zero-Day CVE-2026-56164

Listen up. If you're the one staring at the SharePoint farm this afternoon, stop whatever you're doing.

The Dashboard is Green. The Servers are Gone.

Microsoft just dropped 622 flaws in a single Tuesday.

Eleven AI Chat Exporter Extensions Caught Stealing Data Despite No-Upload Claims

The most dangerous tool in your office isn't the outdated server in the closet. It's the "productivity" extension your assistant installed last Tuesday to save ten minutes of formatting.

The CMS Is Patched. The Extensions Are Wide Open.

Your 3am page is a high-severity alert from the EDR. A public-facing web server just spawned a `whoami` process followed by a `curl` request to a known Cobalt Strike C2. You check the logs. The entry point was a POST request to a form upload directory. The file was `cmd.php`.

Ubiquiti and Joomla Zero-Days Push Tech Sector to Top of Weekly Target List

The technology sector has reclaimed its spot at the top of the targeting table this week, recording 113 separate stories. It's a crowded peak. For those of us who spend our afternoons tracking the gap between a vendor's "security-first" marketing and the actual filing dates of th

Which CVEs Actually Deserve Your Tuesday?

If you're staring at your dashboard and feeling a sense of vertigo, you're probably just experiencing the information entropy Claude Shannon warned us about. When the signal-to-noise ratio drops too low, the result isn't just confusion; it's paralysis. You see a list of twenty "c

Langflow Authorization Bypass Hits CISA KEV List Amid AI Ransomware Reports

CISA added CVE-2026-55255 to the Known Exploited Vulnerabilities catalog on 2026-07-07. The federal patch deadline followed quickly on 2026-07-10. This gave agencies just under 72 hours to secure their instances before they were officially out of compliance.

The cost of trusting the toolchain

There is a particular kind of irony in a tool designed for obfuscation becoming a window into a developer's soul. Jscrambler is built to hide code, to wrap logic in a layer of complexity that keeps prying eyes out. But when the npm package version 8.14.0 was released, it didn't h

Hardware is Cheap. The Cost is Systemic.

The paperwork for a data breach is usually a predictable, if tedious, affair. You have the initial discovery, the frantic internal audit, and then the mandatory notification window—usually 72 hours if you're under the gaze of Brussels—where the company tries to describe a catastr

The patches are ready. The attackers are faster.

Your 3am page is CVE-2026-8451. It's a pre-auth memory overread in Citrix NetScaler. If you're running this, you aren't just looking at a vulnerability; you're looking at a potential session hijacking event on a massive scale. This is the most serious story of the week. It mirror

Every edition runs in one of these standing sections. How stories are chosen.