Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Cisco Changes IOS XE Fix Matrix for Seven CVEs
Cisco revised seven-CVE fix destinations.
Read the article ↗Current reporting
Latest intelligence

Do Not Stop at the First Host
Black Lotus Labs says PoeLLM has targeted exposed LiteLLM, Ollama, Gotenberg and Gitea since April 2026, with possible Ivanti Sentry targeting.
It reports mining, scanning and exploit delivery from compromised hosts. For defenders, that turns one service incident into a potential launch point for another.
PoeLLM converts four words in an attacker-controlled GitHub poem into a command-and-control address; the report recorded 11 changes after 13 April.
The linked IOC file marked three addresses active on 7 October, a dated status rather than an indefinite one.
Lumen's key takeaways say more than 3,400 victim servers and more than 800 active on a peak day, while two body passages retain almost 2,200. BleepingComputer records a correction from 2,100 to 3,400.
The 3,400 figure is cumulative, not simultaneous, and the source discrepancy remains unresolved. Use the figures to scope the hunt, not to manufacture a precise live total.
One reviewed sample targeted /mcp-rest/test/connection, which Black Lotus Labs calls the likely route and links to CVE-2026-42271. That finding does not establish the route for every victim or any other service.
The report does not establish that PoeLLM used the Starlette bypass. BlackTree's earlier LiteLLM analysis covers that bypass. It remains patching context, not proof the incidents share a campaign.
Lumen did not report observed data theft. That does not make credentials and tokens on a reachable host trustworthy.
BlackTree recommends the following operational checks:
Removing a miner is not enough when the host may also have become an exploitation relay. Recovery should answer how the service was exposed, what executed under…

Dell System Update patch closes a path to root
Dell has released System Update 2.3.0.0 to fix five vulnerabilities. The lead flaw, CVE-2026-86360, is a path traversal issue rated 9.6. Dell says an unauthenticated remote attacker could potentially gain filesystem access…
9 Oct 2026 · 1 min read
Chrome 155 Requires Build and Extension Policy Checks
Google released Chrome 155 on 6 October 2026. Its desktop rollout spans days or weeks, so verify the version loaded after restart. Four critical fixes set the minimum Desktop targets are 155.0.8059.39/.40…
9 Oct 2026 · 2 min read
Splunk Patches Command Path
Fix available. Splunk fixed CVE-2026-76268. An unauthenticated user with network access to the Patroni REST API on a search head cluster member can execute operating-system commands. The CVSS 9.8 interface lacks authentication…
9 Oct 2026 · 2 min read
Audit Who Writes Your Agent’s Rules
PackHallu preprint. Published 7 October 2026, PackHallu used a local PyPI mirror, harmless marker and disabled manual confirmations. The defensive question begins before installation. Who supplied the instructions that the agent treats…
9 Oct 2026 · 2 min readRevised reporting
Recently updated
KB5124010 Can Close Legacy AC-3 Apps
Successful installation is only the first check. Test the complete workflow, capture reproducible evidence and match the remedy to the actual failure.
Read articleMicrosoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
The fixes were real, but there was no update button for customers. The affected layer sat inside Microsoft's cloud control plane.
Read articleEight Atlassian Products Could Expose Known Files
Patch eight products.
Read articleSonicWall Patched Two Zero-Days. Then the Replacement Builds Were Exploited Too.
SonicWall confirmed exploitation of two SMA1000 vulnerabilities. If compromise indicators are present, defenders must rebuild the appliance and reset credentials, not merely install the hotfix.
Read articleSouth Korea orders security checks after bank attacks
South Korea warns bank customers about tailored scams.
Read articleGeographic context
Regional intelligence

Spain’s Election Call Puts Its NIS2 Delay Back in Focus
Spain has called a November election after the Commission documented incomplete NIS2 transposition in…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence

Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
Cisco Changes IOS XE Fix Matrix for Seven CVEs
Cisco revised its IOS XE fix matrix on 2 October. Recheck your destination; no…
Read Cisco ↗
Opening the Coding Test Was the Execution Step
Unit 42's Blinder Tunnel report traces an Iranian-nexus operation targeting one person in Iraqi…
Read GitHub ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
FortiMail Operators Face Active Exploitation While Fixes Remain Upcoming
FortiMail faces active exploitation. CVE-2026-104286 allows unauthenticated arbitrary-file writes through crafted HTTP or HTTPS…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.



