Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

DriveWealth Breach Notice May Name the Broker Behind the App
Verify the broker relationship through the investing service you already use.
Read the article ↗Current reporting
Latest intelligence

The SonicWall Gateway Can Proxy Requests Before Login
SonicWall has fixed four vulnerabilities in SMA1000 models 6210, 7210 and 8200v. The most urgent, CVE-2026-102255, is a pre-authentication server-side request forgery flaw in Appliance WorkPlace. A remote unauthenticated attacker could make the appliance issue requests, reach internal functionality and perform unauthorised operations. SonicWall assigns it a CVSS score of 10.0. The vendor provides no workaround and says there is currently no evidence that the October vulnerabilities are being exploited. This is an urgent patch advisory, not confirmation of a breach or campaign. The appliance becomes a confused deputy The risk is not simply that an outside request reaches the gateway. The gateway can become the intermediary that sends another request from a more trusted position. Controls that assume the appliance is a legitimate source may therefore see the request differently from one arriving directly from the internet. SonicWall has not published the internal functions or destinations that can be reached in every deployment. The advisory also does not say that the unauthenticated path produces code execution. Defenders should not turn a maximum score into a broader claim than the evidence supports. Four flaws share one fixed release CVE-2026-102255 is the unauthenticated forward-proxy SSRF. CVE-2026-102256 is operating-system command injection. Under specific conditions, an authenticated administrator can execute arbitrary operating-system commands. CVE-2026-102257 is a post-authentication Zip Slip flaw in the Appliance Management Console that can result in remote code execution. CVE-2026-102258 is stored cross-site scripting. Under specific conditions, an authenticated administrator can store and potentially execute JavaScript in the Appliance Management…

Opening the Coding Test Was the Execution Step
Unit 42's Blinder Tunnel report traces an Iranian-nexus operation targeting one person in Iraqi critical infrastructure. Infrastructure staging began in November 2025, recruitment in March 2026 and a fake Dubai Airports coding…
7 Oct 2026 · 1 min read
Arizona Court Cyberattack
Arizona Courts says that on 24 September 2026 attackers copied backup files holding information on approximately 1.3 million people in its Fines/Fees and Restitution Enforcement (FARE) programme. The dataset includes names, case…
7 Oct 2026 · 1 min read
KB5124010 Can Close Legacy AC-3 Apps
Microsoft added an AC-3 issue to KB5124010 on 3 October. Some apps may refuse to start or shut unexpectedly when using Windows' built-in Dolby Digital decoder. Windows 11 24H2, 25H2 and 26H2…
7 Oct 2026 · 1 min read
WordPress XSS Leaves Backdoors
Two WordPress flaws are being exploited. Patchstack links one payload to WPC Product Bundles and Ninja Forms. The WPC flaw is CVE-2026-93836; the Ninja Forms flaw is CVE-2026-94504. The administrator view is…
7 Oct 2026 · 2 min readRevised reporting
Recently updated
SonicWall Patched Two Zero-Days. Then the Replacement Builds Were Exploited Too.
SonicWall confirmed exploitation of two SMA1000 vulnerabilities. If compromise indicators are present, defenders must rebuild the appliance and reset credentials, not merely install the hotfix.
Read articleSouth Korea orders security checks after bank attacks
South Korea warns bank customers about tailored scams.
Read articleThe FBI Confirms Its Jobs Portal Was Compromised but Not What Was Taken
FBI cyber chief says a contractor missed an issued patch. His statement does not establish the platform or data impact.
Read articleAttackers Are Already Exploiting the NetScaler Flaws Citrix Just Patched
Citrix has patched eight NetScaler vulnerabilities and confirms attackers are already exploiting two critical flaws. One unauthenticated command-execution bug affects every customer-managed deployment.
Read articleThe Identity Checks Meant to Stop Fraud May Have Created a 153-Million-Record Fraud Kit
The documents collected to stop fraud may now enable it. IDScan confirmed possible unauthorised access, while a vanished dark-web service claimed 153 million driver's licence records.
Read articleGeographic context
Regional intelligence

Spain’s Election Call Puts Its NIS2 Delay Back in Focus
Spain has called a November election after the Commission documented incomplete NIS2 transposition in…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence
Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
One Encoded URL Can Hand Attackers Cisco SD-WAN Admin Access
A crafted HTTP request can give attackers administrator-level API access to Cisco Catalyst SD-WAN…
Read Cisco ↗
Opening the Coding Test Was the Execution Step
Unit 42's Blinder Tunnel report traces an Iranian-nexus operation targeting one person in Iraqi…
Read GitHub ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
FortiMail Operators Face Active Exploitation While Fixes Remain Upcoming
FortiMail faces active exploitation. CVE-2026-104286 allows unauthenticated arbitrary-file writes through crafted HTTP or HTTPS…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




