Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Apple’s 273-CVE Security Release Includes a Flaw Attackers Have Already Exploited
Apple’s 14 September security rollout spans 273 unique CVEs across ten advisories. The headline number is real, but one familiar flaw in CISA’s exploited catalogue changes…
Read the article ↗Current reporting
Latest intelligence

A $4 Lost-Phone Report Could Silence Your Home Alarm
The phone was still sealed in its box. Yet after researchers reported its identifier as lost, it could not connect to the mobile network. That demonstration exposes a larger problem: the anti-theft system intended to protect devices can become a cheap way to disconnect someone else's phone or a home alarm's cellular backup.
Michigan State University and collaborators described six weaknesses spanning devices, mobile operators and the cross-carrier system that shares lost-device records. Their MobiSys 2026 paper won a Best Paper Award. The university published its account on 9 September 2026; its page supplies no publication time. The paper itself dates from June, so this is new reporting and explanation of published research, not a newly discovered zero-day.
Every cellular device has an IMEI, an identifier separate from its phone number and SIM. When an owner reports a device lost or stolen, an operator can place that IMEI on a block list so the device cannot register on the network. The defense makes a stolen handset less useful. But it also creates an availability decision with consequences beyond the reporting customer.
The researchers tested the reporting practices of three major US carriers and associated resellers. They found weaknesses in how a reporter's identity and ownership were checked, what kinds of devices could be reported, and what trust information followed a block-list entry to other operators. A brief prior network attachment could be treated as evidence that a device belonged to a reporting account. That is not the same as proving ownership.
In the…

Six Mistral Vibe Flaws Let an AI Agent Act Without Your Approval
A Mistral Vibe permission bypass begins where a coding assistant is supposed to pause before a risky command. It asks for permission, and the developer decides whether the command may run. Six…
15 Sep 2026 · 4 min read
GoAnywhere MFT’s ‘Secure Folder’ Had a Hidden Exit
A managed file-transfer service is supposed to be unusually clear about who can reach which files. Fortra has disclosed a flaw in GoAnywhere MFT that breaks that expectation for a specific class…
15 Sep 2026 · 4 min read
A Traefik Shortcut Could Let a Stranger Inherit Your Login
A Traefik HTTP/3 proxy should keep two visitors' identities separate, even when it reuses connections to make their requests faster. A Traefik advisory published on 7 September 2026 shows a narrow but…
15 Sep 2026 · 4 min read
Why None of 12 AI Models Passed AWS’s Code-Review Trust Test
The most expensive security alert may be the one everybody eventually learns to ignore. AI code review tools promise to find bugs faster, but a tool that calls safe code vulnerable creates…
15 Sep 2026 · 4 min readRevised reporting
Recently updated
Hackers Searched 1.8 Million Android Apps for the Keys to Someone Else’s Busin…
An Android app can work exactly as intended while exposing a credential that should never have left a private system. For its users, nothing looks wrong. For an attacker, the…
Read articleThe Firewall Manager Shipped With a Password Attackers Already Knew.
Cisco has confirmed active exploitation of static credentials in Secure Firewall Management Center. The embedded account is low privilege, but the management platform's position and the possibility of exploit chaining…
Read articleAttackers Used PaperCut to Hunt for Passwords Inside Schools and Universities
Update, 5 September 2026: Arctic Wolf told The Hacker News that it observed attackers using the PaperCut vulnerability chain against vulnerable servers at education organisations ranging from K-12 schools to…
Read articleThe CRA Reporting Clock Starts on 11 September 2026
On 11 September 2026, the Cyber Resilience Act becomes operational in a very specific way. Manufacturers will need to report actively exploited vulnerabilities and severe product-security incidents through ENISA's Single…
Read articleGoogle Fixed 230 Chrome Bugs. One Was Already in Attackers’ Hands.
Google fixed 230 security issues in Chrome 153. One sentence in the release notes matters more than the size of that list: an exploit for CVE-2026-87491 exists in the wild.…
Read articleGeographic context
Regional intelligence

Six Mistral Vibe Flaws Let an AI Agent Act Without Your Approval
Six Mistral Vibe flaws expose a gap between the command an AI coding agent…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
One Click in Sogou’s Keyboard Opened a Six-Year-Old Browser to a Spy…
Gen Digital traced a GRAYRABBIT intrusion to a crafted Sogou Input Method link. The…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence

A Million Fake CEO Emails Tried to Make Finance Pay a ServiceNow Invoice T…
The email appeared to come from the boss. Underneath it sat a detailed fake…
Read Microsoft ↗
A Network Packet Could Give Attackers Root on Cisco Nexus 9000 Switches
Cisco has disclosed a critical Nexus 9000 flaw where a network packet can become…
Read Cisco ↗
Adobe Campaign Classic Has Three CVSS 10 Paths to Code Execution
Adobe has fixed three critical Adobe Campaign Classic vulnerabilities that can let an unauthenticated…
Read Adobe ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗
The Security Extension Could Send Your Browser Through an Attacker’s Serve…
A browser extension installed to protect privileged access could be turned into the route…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




