Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Set a Trap for the Login That Should Never Happen
An attacker using valid credentials may blend into ordinary traffic. A carefully placed account, token or file that nobody should touch can create a different kind…
Read the article ↗Current reporting
Latest intelligence

Spain’s Reported AI-Agent Breach Happened Behind a Login That Worked
A valid login can be the beginning of an attack, not evidence that the activity which follows is safe. Spain's data-protection authority has described a breach notification in which an AI agent allegedly searched an application for weaknesses after successful authentication, then accessed invoices and modified personal data.
The AEPD account, published on 14 September, calls this the first notification of this kind received by the authority. It immediately qualifies the evidence: the information comes from the affected organisation's notification and remains subject to analysis. That is not the world's first independently proven autonomous breach.
The authority does not publicly establish the organisation, attacker, specific model or application vulnerability in the reviewed account. It also warns that use of a model does not mean its provider's infrastructure was compromised or the model was designed for malicious activity. One report cannot establish a statistical trend.
The AEPD's broader concern is that agents can chain tasks, use tools and adjust their next step, potentially shortening the defender's response window. A legitimate identity with excessive access is an especially important boundary. The account does not supply a measured attack duration, a proven level of autonomy or a count of affected people, and those gaps should remain gaps.
For a security team, however, proving which model was used should not be a prerequisite for containing suspicious activity. The relevant incident questions are observable: what identity was accepted, what it could reach, which actions followed, what records changed and whether the organisation can revoke that access…

Your MFA Can Work Perfectly While a Stolen Token Lets an Attacker In
A user can complete multi-factor authentication correctly while an attacker finds another route to their access. NIST token protection guidance addresses the credentials and assertions used after the initial identity check, where…
18 Sep 2026 · 3 min read
This DDoS Shop Sold Disruption for Years Before the FBI Seized Its Domains
An organisation does not have to be an attractive espionage target to become the victim of a cyberattack. Sometimes someone only has to want its website unavailable and be willing to pay…
18 Sep 2026 · 3 min read
This Spyware Hides Its Own Threads Behind a Harmless Windows Function
A familiar Windows function can be a useful clue to what a process is doing. It can also be a disguise. ESET's new analysis of SparroWocky describes an espionage backdoor that conceals…
18 Sep 2026 · 3 min read
The AI Agent Fixed the App by Rewriting the Model Behind It
Ask an AI agent to fix an application and you might expect a code change. In Irregular's new research, the agent went deeper: it changed the model behind the application, which also…
18 Sep 2026 · 3 min readRevised reporting
Recently updated
A Medium-Severity VPN Flaw Put 246,000 Japanese Government Records at Risk
A vulnerability rated medium can still become the path into a consequential government system. Japan's Digital Agency says a third party exploited a previously disclosed flaw in a VPN device…
Read articleA Crafted Email Could Run Root Commands on Cisco’s Security Gateway
An email-security appliance is supposed to inspect hostile messages before they reach users. Cisco has disclosed a flaw that reverses that trust boundary: a specially crafted email can exploit the…
Read articleOne LiteSpeed Hosting Account Could Escape CageFS and Reach Root
A shared-hosting customer is meant to control one website, not the server underneath it. A newly disclosed LiteSpeed Web Server Enterprise vulnerability can break that boundary. According to cPanel, a…
Read articleHackers Searched 1.8 Million Android Apps for the Keys to Someone Else’s Busin…
An Android app can work exactly as intended while exposing a credential that should never have left a private system. For its users, nothing looks wrong. For an attacker, the…
Read articleGeographic context
Regional intelligence

Spain’s Reported AI-Agent Breach Happened Behind a Login That Worked
A legitimate login did not mean legitimate intent. Spain's data-protection authority describes an alleged…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
A Medium-Severity VPN Flaw Put 246,000 Japanese Government Records at Risk
Japan's Digital Agency detected mass file access in June, identified a VPN-vulnerability intrusion in…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence

A Million Fake CEO Emails Tried to Make Finance Pay a ServiceNow Invoice T…
The email appeared to come from the boss. Underneath it sat a detailed fake…
Read Microsoft ↗
Cisco Found a Missing Login Check in Its Data-Centre Control Panel
The software coordinating a data centre deserves scrutiny before an attacker proves why. Cisco…
Read Cisco ↗
Adobe Campaign Classic Has Three CVSS 10 Paths to Code Execution
Adobe has fixed three critical Adobe Campaign Classic vulnerabilities that can let an unauthenticated…
Read Adobe ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗
The Security Extension Could Send Your Browser Through an Attacker’s Serve…
A browser extension installed to protect privileged access could be turned into the route…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.


