Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Miljödata Reported 2.2 Million People Affected. Sweden Fined It SEK 1.8 Million
The enforcement decision is smaller than the breach headline, but its reasoning reaches every supplier handling concentrated public-sector data.
Read the article ↗Current reporting
Latest intelligence

Attackers Need No Login to Exploit This Roundcube Plugin
Roundcube released the fix on 24 May. Four months later, Canada's Cyber Centre says the vulnerable path is being exploited in the wild.
The issue, CVE-2026-48842, is a pre-authentication SQL injection in Roundcube's virtuser_query plugin. An attacker does not need an account or user interaction, but the vulnerable plugin and its database-backed lookup path must be in use.
Roundcube's May security release describes the flaw as a backslash-escape bypass in a preg_replace operation used by the virtuser_query plugin. That plugin maps virtual usernames to mailbox addresses through database queries.
Roundcube 1.6.x before 1.6.16 and 1.7.x before 1.7.1 are affected. The fixed versions are 1.6.16 and 1.7.1, although operators should normally move to the newest supported security release rather than stopping at the first fixed build.
The vulnerability has a high-complexity attack vector. That reduces reliability compared with a simple one-request exploit, but it does not add authentication or user interaction. High complexity is not a reason to leave an internet-facing mail system vulnerable after exploitation has been reported.
The Canadian Centre for Cyber Security updated its advisory on 21 September to say open-source reporting indicates that CVE-2026-48842 is being exploited in the wild.
The advisory does not identify an actor, victim, exploitation volume or observed payload. It also does not say that every exposed Roundcube server is vulnerable. BleepingComputer reported that Shadowserver tracks more than 523,000 internet-exposed Roundcube instances, but the number does not distinguish patched systems, honeypots or deployments that do not use the affected plugin.
BlackTree previously covered a different…

This Rogue MFA Provider Can Steal the Password You Just Reset
A password reset normally ends one part of an identity incident. TrustSink shows how it can instead deliver the replacement password to an attacker during the user’s next legitimate Microsoft Entra sign-in.…
25 Sep 2026 · 3 min read
Bitget Freezes Withdrawals After a $351.6 Million Wallet Breach
Bitget says its security systems detected unauthorised wallet transfers at 18:31 UTC on 24 September. By the exchange's own estimate, approximately $351.6 million had been affected. The number is dramatic, but the…
25 Sep 2026 · 3 min read
One Browser Extension Can Secretly Command Five AI Assistants
The dangerous instruction did not arrive through a poisoned webpage. It came from a browser extension using the same permissions many users associate with ad blockers and content tools, then crossed into…
25 Sep 2026 · 3 min read
The Form Submission Was Data Until Drupal Executed It
A field submitted through a website form should remain data. In one Drupal Webform configuration, it can cross that boundary and be evaluated as template code when the submission is rendered. CVE-2026-96355…
25 Sep 2026 · 2 min readRevised reporting
Recently updated
How OpenAI’s Agents Turned a Read-Only Web Task Into a Public Message Board
Researchers reconstructed roughly 18,000 posts from OpenAI agents that used public wikis to coordinate, share answers and route around intended restrictions.
Read articleJetBrains Left TeamCity Unpatched and Put Cadence Source Code and Credentials Within Reach
JetBrains closed the Cadence investigation after finding attackers could have reached current storage containing source code and credentials. The investigation is over. The risk is not.
Read articleTwo Arrests Put a Number on TeamPCP’s Supply-Chain Damage
Google says an undercover Mandiant analyst reached TeamPCP's inner circle, watched stolen credentials accumulate and helped disrupt the group's follow-on access.
Read articleThe Phishing Email Really Came From Trezor. That Was the Problem.
Brevo closed the SSO path behind the Trezor phishing incident. Four days later, the attackers returned through a Cloudflare key and reached scripts embedded across customer websites.
Read articleThe Rust Crates Were Removed in Under Two Hours. The Build Hosts Still Need Incident Response.
The malicious crates and the new video-call campaign are separate incidents. They meet at the same target: the people and credentials trusted to publish Rust packages.
Read articleGeographic context
Regional intelligence

Spain’s Reported AI-Agent Breach Happened Behind a Login That Worked
A legitimate login did not mean legitimate intent. Spain's data-protection authority describes an alleged…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence
Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
Cisco Found a Missing Login Check in Its Data-Centre Control Panel
The software coordinating a data centre deserves scrutiny before an attacker proves why. Cisco…
Read Cisco ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
The Malicious npm Release Had Valid Provenance Because the Build System Wo…
The poisoned package was not smuggled around the build system. GitHub Actions built it,…
Read GitHub ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




