Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

This Android Ransomware Can Watch Your Screen While Demanding Payment
Mantax Otax combines ransom demands with screen monitoring and message theft. Newer Android limits broad file encryption, but not every other risk.
Read the article ↗Current reporting
Latest intelligence

AVEVA’s Patch Cannot Secure the Files You Forgot
A patch can close a software flaw without making the files it used to protect safe. That is the uncomfortable detail in the new AVEVA Pipeline Integrity Monitor bulletin. The vendor has fixed four vulnerabilities in its PIMBoards component, but it also tells customers to migrate old project files, protect copies they cannot migrate and require users to change passwords. Teams that stop at the software installer may leave the most durable part of the exposure behind.
AVEVA's 8 September security bulletin covers Pipeline Integrity Monitor 2025 SP1 P1, build 7.1.9580.8513, and earlier versions. The bulletin gives a date but no publication time. It directs users to the 2025 SP1 P2 security update or later. The affected component is PIMBoards. The bulletin reports no known exploitation or victims. It also makes no claim of disrupted pipeline operations.
Two findings concern the project files themselves. CVE-2026-81821 is a hardcoded encryption key: someone who can read an affected PIMBoards project file may be able to decrypt sensitive information inside it. CVE-2026-81822 concerns passwords hashed with MD5. A person with read access to an affected project file could try to recover a PIMBoards user's application password by offline guessing, potentially gaining that user's privileges. AVEVA rates both 8.3 under CVSS 4.0. The bulletin does not describe either as a standalone remote break-in. The attacker first needs a project file.
The other two findings involve the application interface. CVE-2026-81823 is missing authorisation on a subset of read-only API methods. AVEVA says an unauthenticated requester could perform reads intended…

Apple’s 273-CVE Security Release Includes a Flaw Attackers Have Already Exploi…
The Apple security updates released on 14 September are bigger than a single operating-system update. Ten separate advisories cover iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari and Xcode. Across…
16 Sep 2026 · 7 min read
A $4 Lost-Phone Report Could Silence Your Home Alarm
The phone was still sealed in its box. Yet after researchers reported its identifier as lost, it could not connect to the mobile network. That demonstration exposes a larger problem: the anti-theft…
16 Sep 2026 · 4 min read
Six Mistral Vibe Flaws Let an AI Agent Act Without Your Approval
A Mistral Vibe permission bypass begins where a coding assistant is supposed to pause before a risky command. It asks for permission, and the developer decides whether the command may run. Six…
15 Sep 2026 · 4 min read
GoAnywhere MFT’s ‘Secure Folder’ Had a Hidden Exit
A managed file-transfer service is supposed to be unusually clear about who can reach which files. Fortra has disclosed a flaw in GoAnywhere MFT that breaks that expectation for a specific class…
15 Sep 2026 · 4 min readRevised reporting
Recently updated
Hackers Searched 1.8 Million Android Apps for the Keys to Someone Else’s Busin…
An Android app can work exactly as intended while exposing a credential that should never have left a private system. For its users, nothing looks wrong. For an attacker, the…
Read articleThe Firewall Manager Shipped With a Password Attackers Already Knew.
Cisco has confirmed active exploitation of static credentials in Secure Firewall Management Center. The embedded account is low privilege, but the management platform's position and the possibility of exploit chaining…
Read articleAttackers Used PaperCut to Hunt for Passwords Inside Schools and Universities
Update, 5 September 2026: Arctic Wolf told The Hacker News that it observed attackers using the PaperCut vulnerability chain against vulnerable servers at education organisations ranging from K-12 schools to…
Read articleThe CRA Reporting Clock Starts on 11 September 2026
On 11 September 2026, the Cyber Resilience Act becomes operational in a very specific way. Manufacturers will need to report actively exploited vulnerabilities and severe product-security incidents through ENISA's Single…
Read articleGoogle Fixed 230 Chrome Bugs. One Was Already in Attackers’ Hands.
Google fixed 230 security issues in Chrome 153. One sentence in the release notes matters more than the size of that list: an exploit for CVE-2026-87491 exists in the wild.…
Read articleGeographic context
Regional intelligence

Six Mistral Vibe Flaws Let an AI Agent Act Without Your Approval
Six Mistral Vibe flaws expose a gap between the command an AI coding agent…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
One Click in Sogou’s Keyboard Opened a Six-Year-Old Browser to a Spy…
Gen Digital traced a GRAYRABBIT intrusion to a crafted Sogou Input Method link. The…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence

A Million Fake CEO Emails Tried to Make Finance Pay a ServiceNow Invoice T…
The email appeared to come from the boss. Underneath it sat a detailed fake…
Read Microsoft ↗
A Network Packet Could Give Attackers Root on Cisco Nexus 9000 Switches
Cisco has disclosed a critical Nexus 9000 flaw where a network packet can become…
Read Cisco ↗
Adobe Campaign Classic Has Three CVSS 10 Paths to Code Execution
Adobe has fixed three critical Adobe Campaign Classic vulnerabilities that can let an unauthenticated…
Read Adobe ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗
The Security Extension Could Send Your Browser Through an Attacker’s Serve…
A browser extension installed to protect privileged access could be turned into the route…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




