Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.
A Departed Employee’s Token Quietly Opened 170 Private Security Repositories
The employee had left. The token had not. GitHub traced the access path back to the wider TanStack supply-chain incident.
Read the article ↗Current reporting
Latest intelligence
How Plugin4Shell Made Reviewed AI Coding Plugins Run Different Code
A commit hash is supposed to answer a simple question: exactly which code will run? Plugin4Shell shows that four popular AI coding agents recorded the right-looking pin but failed to verify that Git had actually placed that commit in the working directory.
AIR Security's research covers Claude Code, OpenAI Codex, GitHub Copilot and Gemini CLI. A malicious plugin repository owner could create a branch whose name resembled the pinned commit. On Git hosts that permit the ambiguous reference, checkout could resolve to the branch instead. The agent then loaded the resulting plugin without checking that the working tree matched the reviewed commit object.
A marketplace could correctly store a reviewed hash and still lose control at installation time. The vulnerable agent delegated reference resolution to Git and treated a successful checkout as proof that the pin had been honoured. Background plugin updates made the path zero-click in products where automatic updates were enabled.
Git-host behaviour changes exposure. GitHub rejects some branch names that look like full commit hashes, limiting the demonstrated technique there. Bitbucket and self-hosted Git services may allow the conflicting name. That is why a safe conclusion cannot be based only on which marketplace a company uses.
No malicious exploitation has been established. AIR produced a working proof of concept against the four agents during coordinated research. The absence of an observed campaign does not remove the supply-chain consequence, but it must not be presented as an active breach.
The wider lesson is that a pin is…
The Fake GitHub Download Arrived With a Microsoft-Signed EDR Killer
The download page looked like GitHub. The driver carried Microsoft's attestation. Neither fact made the software safe. Rapuncel combines search-optimised repositories impersonating more than 40 brands with a kernel driver designed to…
21 Sep 2026 · 3 min readThe Login Screen on Your Security Manager Could Hand an Attacker Root
The management server decides how the firewalls behave. The log server holds the evidence used to understand what they saw. A critical Check Point flaw reaches both systems through the login process,…
21 Sep 2026 · 3 min readAttackers Found a Workflow Engine That Would Run Their Code as Root
A workflow platform is designed to turn instructions into actions. That becomes a serious security problem when an unauthenticated internet user can supply the instructions and the engine runs them with root…
21 Sep 2026 · 3 min read
CISA Gave Three Linux Kernel Bugs a Three-Day Deadline
Three Linux kernel vulnerabilities entered CISA's Known Exploited Vulnerabilities catalogue on 18 September with a remediation date of 21 September. The three-day deadline is unusually short. It is also easy to misread:…
21 Sep 2026 · 3 min readRevised reporting
Recently updated
A Medium-Severity VPN Flaw Put 246,000 Japanese Government Records at Risk
A vulnerability rated medium can still become the path into a consequential government system. Japan's Digital Agency says a third party exploited a previously disclosed flaw in a VPN device…
Read articleA Crafted Email Could Run Root Commands on Cisco’s Security Gateway
An email-security appliance is supposed to inspect hostile messages before they reach users. Cisco has disclosed a flaw that reverses that trust boundary: a specially crafted email can exploit the…
Read articleOne LiteSpeed Hosting Account Could Escape CageFS and Reach Root
A shared-hosting customer is meant to control one website, not the server underneath it. A newly disclosed LiteSpeed Web Server Enterprise vulnerability can break that boundary. According to cPanel, a…
Read articleHackers Searched 1.8 Million Android Apps for the Keys to Someone Else’s Busin…
An Android app can work exactly as intended while exposing a credential that should never have left a private system. For its users, nothing looks wrong. For an attacker, the…
Read articleGeographic context
Regional intelligence

Spain’s Reported AI-Agent Breach Happened Behind a Login That Worked
A legitimate login did not mean legitimate intent. Spain's data-protection authority describes an alleged…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
A Medium-Severity VPN Flaw Put 246,000 Japanese Government Records at Risk
Japan's Digital Agency detected mass file access in June, identified a VPN-vulnerability intrusion in…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence

A Million Fake CEO Emails Tried to Make Finance Pay a ServiceNow Invoice T…
The email appeared to come from the boss. Underneath it sat a detailed fake…
Read Microsoft ↗
Cisco Found a Missing Login Check in Its Data-Centre Control Panel
The software coordinating a data centre deserves scrutiny before an attacker proves why. Cisco…
Read Cisco ↗
Adobe Campaign Classic Has Three CVSS 10 Paths to Code Execution
Adobe has fixed three critical Adobe Campaign Classic vulnerabilities that can let an unauthenticated…
Read Adobe ↗A Departed Employee’s Token Quietly Opened 170 Private Security Repo…
An employee can leave while their machine identity remains alive. CrowdSec says an OAuth…
Read GitHub ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.


