Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Researchers Heard Headphone Audio From 30 Metres Away Without Hacking Bluetooth
InjectEave researchers recovered headphone audio through induced electromagnetic leakage from as far as 30 metres in a controlled test. What the experiment does and does not…
Read the article ↗Current reporting
Latest intelligence

This Android Ransomware Can Watch Your Screen While Demanding Payment
The ransom message is the most visible part of Mantax Otax, but it may not be the most damaging. Researchers say the Android malware can monitor a device's screen, read messages and collect other personal data while also trying to lock files and demand payment. That combination changes the response question from 'Can we restore the files?' to 'What did this phone reveal before anyone noticed?'
Zimperium's 9 September analysis describes two versions of Mantax Otax. The page provides no publication time. Some analysed samples were hosted as standalone APK files on a third-party sharing service, suggesting manual installation through a link rather than ordinary app-store delivery. The research does not establish how every infection began, how many people were affected or that the malware was distributed through Google Play. Language and recovered files point towards targets in Indonesia; they do not by themselves establish the nationality of an operator.
After installation, the app asks for device-administrator privileges and sensitive permissions, then requests Android accessibility access. If a person grants those requests, the malware can reach far beyond the files it aims to encrypt. BlackTree has documented similar abuse of Android Accessibility by ToxicPanda 2.0, though these are distinct malware families. Zimperium reports code and observed behaviour for collecting contacts, call logs, SMS messages, browser history, media and information about installed apps. It also describes interception of lock-screen PIN entry and access to messaging content through accessibility features.
Screen capture is a separate path. The malware uses Android's MediaProjection interface…

AVEVA’s Patch Cannot Secure the Files You Forgot
A patch can close a software flaw without making the files it used to protect safe. That is the uncomfortable detail in the new AVEVA Pipeline Integrity Monitor bulletin. The vendor has…
16 Sep 2026 · 4 min read
Apple’s 273-CVE Security Release Includes a Flaw Attackers Have Already Exploi…
The Apple security updates released on 14 September are bigger than a single operating-system update. Ten separate advisories cover iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari and Xcode. Across…
16 Sep 2026 · 7 min read
A $4 Lost-Phone Report Could Silence Your Home Alarm
The phone was still sealed in its box. Yet after researchers reported its identifier as lost, it could not connect to the mobile network. That demonstration exposes a larger problem: the anti-theft…
16 Sep 2026 · 4 min read
Six Mistral Vibe Flaws Let an AI Agent Act Without Your Approval
A Mistral Vibe permission bypass begins where a coding assistant is supposed to pause before a risky command. It asks for permission, and the developer decides whether the command may run. Six…
15 Sep 2026 · 4 min readRevised reporting
Recently updated
Hackers Searched 1.8 Million Android Apps for the Keys to Someone Else’s Busin…
An Android app can work exactly as intended while exposing a credential that should never have left a private system. For its users, nothing looks wrong. For an attacker, the…
Read articleThe Firewall Manager Shipped With a Password Attackers Already Knew.
Cisco has confirmed active exploitation of static credentials in Secure Firewall Management Center. The embedded account is low privilege, but the management platform's position and the possibility of exploit chaining…
Read articleAttackers Used PaperCut to Hunt for Passwords Inside Schools and Universities
Update, 5 September 2026: Arctic Wolf told The Hacker News that it observed attackers using the PaperCut vulnerability chain against vulnerable servers at education organisations ranging from K-12 schools to…
Read articleThe CRA Reporting Clock Starts on 11 September 2026
On 11 September 2026, the Cyber Resilience Act becomes operational in a very specific way. Manufacturers will need to report actively exploited vulnerabilities and severe product-security incidents through ENISA's Single…
Read articleGoogle Fixed 230 Chrome Bugs. One Was Already in Attackers’ Hands.
Google fixed 230 security issues in Chrome 153. One sentence in the release notes matters more than the size of that list: an exploit for CVE-2026-87491 exists in the wild.…
Read articleGeographic context
Regional intelligence

Six Mistral Vibe Flaws Let an AI Agent Act Without Your Approval
Six Mistral Vibe flaws expose a gap between the command an AI coding agent…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
One Click in Sogou’s Keyboard Opened a Six-Year-Old Browser to a Spy…
Gen Digital traced a GRAYRABBIT intrusion to a crafted Sogou Input Method link. The…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence

A Million Fake CEO Emails Tried to Make Finance Pay a ServiceNow Invoice T…
The email appeared to come from the boss. Underneath it sat a detailed fake…
Read Microsoft ↗
A Network Packet Could Give Attackers Root on Cisco Nexus 9000 Switches
Cisco has disclosed a critical Nexus 9000 flaw where a network packet can become…
Read Cisco ↗
Adobe Campaign Classic Has Three CVSS 10 Paths to Code Execution
Adobe has fixed three critical Adobe Campaign Classic vulnerabilities that can let an unauthenticated…
Read Adobe ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗
The Security Extension Could Send Your Browser Through an Attacker’s Serve…
A browser extension installed to protect privileged access could be turned into the route…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




