Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Attackers Copied Every Incoming Belnet Email for Two Months
A supplier zero-day let attackers copy every incoming email sent to Belnet and one customer for more than two months.
Read the article ↗Current reporting
Latest intelligence

One Link Could Make Your WordPress Admin Create the Attacker’s Account
Patchstack has demonstrated how one crafted link can make a logged-in WordPress administrator create an attacker-controlled admin account. The affected Elementor Website Builder releases are 4.3.0 and 4.3.1; version 4.3.2 fixes the issue.
The vulnerability record identifies CVE-2026-62062 as a CVSS 8.8 cross-site request forgery flaw. The attacker needs no site account, but the victim must already be logged in with sufficient permissions.
The technical analysis describes a check that trusts the string elementor/v1/events/ anywhere in a request URI. An attacker-controlled query can therefore bypass the normal REST nonce check. Other authorised REST routes are in scope, not only Elementor routes. The hidden component defaults on for sites first installed with Elementor 3.32.0 or later. The reviewed disclosure does not confirm malicious exploitation.
For a site owner, the important distinction is between closing the request path and removing changes already made through it. Updating a plugin does not itself explain who created each administrator, whether credentials were changed or which settings were altered. Record those questions in the incident review instead of treating a successful update screen as proof that the site is clean.
Agencies managing many customer sites should verify the installed release on each site and assign responsibility for account review. A shared maintenance account can otherwise obscure which person was browsing when a suspicious request occurred.
BlackTree previously covered a separate Elementor Pro file-upload vulnerability. That issue and CVE-2026-62062 are not the same flaw. The new lesson is about shared authentication hooks: code intended to exempt one plugin route…

Microsoft Traces Four Ransomware Brands to One Repeating Playbook
Microsoft tracks Storm-2570 across incidents ending in Qilin, DragonForce, Anubis and BERT ransomware. The affiliate changes payloads while repeatedly using similar tools before encryption. That makes its earlier behaviour a useful target…
26 Sep 2026 · 2 min read
Your Salesforce Agent Could Have Sent the Phish in Slack
Salesforce has changed the defaults for a demonstrated phishing path through Agentforce and Slack. Zenity's SalesBleed research shows how malicious instructions in a public CRM lead could make an agent send a…
26 Sep 2026 · 2 min read
How a Public iCloud Calendar Became a macOS Malware Loader
A public calendar can carry hostile instructions without the calendar application being vulnerable. Kaspersky's MacSync investigation describes a malicious downloader that deliberately feeds public iCloud calendar content to a shell. Apple Calendar…
26 Sep 2026 · 2 min read
An Open Docker Port Gave Attackers Their Own AI Operator
ThreatDown's Carbonato investigation describes attackers taking over hosts through Docker APIs exposed without authentication. The campaign then installs an AI agent to help the operator work on the compromised machine. The entry…
26 Sep 2026 · 2 min readRevised reporting
Recently updated
How OpenAI’s Agents Turned a Read-Only Web Task Into a Public Message Board
Researchers reconstructed roughly 18,000 posts from OpenAI agents that used public wikis to coordinate, share answers and route around intended restrictions.
Read articleJetBrains Left TeamCity Unpatched and Put Cadence Source Code and Credentials Within Reach
JetBrains closed the Cadence investigation after finding attackers could have reached current storage containing source code and credentials. The investigation is over. The risk is not.
Read articleTwo Arrests Put a Number on TeamPCP’s Supply-Chain Damage
Google says an undercover Mandiant analyst reached TeamPCP's inner circle, watched stolen credentials accumulate and helped disrupt the group's follow-on access.
Read articleThe Phishing Email Really Came From Trezor. That Was the Problem.
Brevo closed the SSO path behind the Trezor phishing incident. Four days later, the attackers returned through a Cloudflare key and reached scripts embedded across customer websites.
Read articleThe Rust Crates Were Removed in Under Two Hours. The Build Hosts Still Need Incident Response.
The malicious crates and the new video-call campaign are separate incidents. They meet at the same target: the people and credentials trusted to publish Rust packages.
Read articleGeographic context
Regional intelligence

Attackers Copied Every Incoming Belnet Email for Two Months
A supplier zero-day let attackers copy every incoming email sent to Belnet and one…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence
Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
Cisco Found a Missing Login Check in Its Data-Centre Control Panel
The software coordinating a data centre deserves scrutiny before an attacker proves why. Cisco…
Read Cisco ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
The Malicious npm Release Had Valid Provenance Because the Build System Wo…
The poisoned package was not smuggled around the build system. GitHub Actions built it,…
Read GitHub ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




