Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.
The Fake GitHub Download Arrived With a Microsoft-Signed EDR Killer
The repositories copied more than 40 brands. The payload then used a trusted driver to remove the tools most likely to stop it.
Read the article ↗Current reporting
Latest intelligence
The Login Screen on Your Security Manager Could Hand an Attacker Root
The management server decides how the firewalls behave. The log server holds the evidence used to understand what they saw. A critical Check Point flaw reaches both systems through the login process, before an attacker supplies valid credentials.
CVE-2026-91843 is a stack-based buffer overflow in Check Point Quantum Security Management. Check Point says a remote, unauthenticated attacker can execute arbitrary code as root. The CVSS 3.1 score is 9.8.
The affected roles include Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server. The Canadian Centre for Cyber Security lists the following supported release thresholds:
End-of-support releases are also affected according to Check Point's CVE record. CERT.LV lists patched target builds of R82.20 Take 29, R82.10 Take 28, R82 Take 28 and R81.20 Take 28. Administrators should reconcile those figures with Check Point's live support article because hotfix guidance can change.
Check Point says customers with automatic LivePatch updates enabled may already be protected. That should be verified rather than assumed. The vendor directs administrators to confirm the patch in the LivePatch inventory. If the fix cannot be applied immediately, restrict the management interface to trusted clients and networks.
No exploitation in the wild was known at the time of the advisory, and no verified public proof of concept was identified in the reviewed sources. Exposure remains consequential because the vulnerable service is the control plane for network policy and audit data.
Fixing CVE-2026-91843 closes the known login overflow. It does not prove that a previously exposed manager was untouched. The…
Attackers Found a Workflow Engine That Would Run Their Code as Root
A workflow platform is designed to turn instructions into actions. That becomes a serious security problem when an unauthenticated internet user can supply the instructions and the engine runs them with root…
21 Sep 2026 · 3 min read
CISA Gave Three Linux Kernel Bugs a Three-Day Deadline
Three Linux kernel vulnerabilities entered CISA's Known Exploited Vulnerabilities catalogue on 18 September with a remediation date of 21 September. The three-day deadline is unusually short. It is also easy to misread:…
21 Sep 2026 · 3 min read
Set a Trap for the Login That Should Never Happen
The login succeeds. The tool is legitimate. The connection looks ordinary. CISA cyber-decoys guidance addresses the difficult situation in which an intruder's activity resembles authorised work, by placing assets that legitimate business…
18 Sep 2026 · 3 min read
Spain’s Reported AI-Agent Breach Happened Behind a Login That Worked
A valid login can be the beginning of an attack, not evidence that the activity which follows is safe. Spain's data-protection authority has described a breach notification in which an AI agent…
18 Sep 2026 · 3 min readRevised reporting
Recently updated
A Medium-Severity VPN Flaw Put 246,000 Japanese Government Records at Risk
A vulnerability rated medium can still become the path into a consequential government system. Japan's Digital Agency says a third party exploited a previously disclosed flaw in a VPN device…
Read articleA Crafted Email Could Run Root Commands on Cisco’s Security Gateway
An email-security appliance is supposed to inspect hostile messages before they reach users. Cisco has disclosed a flaw that reverses that trust boundary: a specially crafted email can exploit the…
Read articleOne LiteSpeed Hosting Account Could Escape CageFS and Reach Root
A shared-hosting customer is meant to control one website, not the server underneath it. A newly disclosed LiteSpeed Web Server Enterprise vulnerability can break that boundary. According to cPanel, a…
Read articleHackers Searched 1.8 Million Android Apps for the Keys to Someone Else’s Busin…
An Android app can work exactly as intended while exposing a credential that should never have left a private system. For its users, nothing looks wrong. For an attacker, the…
Read articleGeographic context
Regional intelligence

Spain’s Reported AI-Agent Breach Happened Behind a Login That Worked
A legitimate login did not mean legitimate intent. Spain's data-protection authority describes an alleged…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
A Medium-Severity VPN Flaw Put 246,000 Japanese Government Records at Risk
Japan's Digital Agency detected mass file access in June, identified a VPN-vulnerability intrusion in…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence

A Million Fake CEO Emails Tried to Make Finance Pay a ServiceNow Invoice T…
The email appeared to come from the boss. Underneath it sat a detailed fake…
Read Microsoft ↗
Cisco Found a Missing Login Check in Its Data-Centre Control Panel
The software coordinating a data centre deserves scrutiny before an attacker proves why. Cisco…
Read Cisco ↗
Adobe Campaign Classic Has Three CVSS 10 Paths to Code Execution
Adobe has fixed three critical Adobe Campaign Classic vulnerabilities that can let an unauthenticated…
Read Adobe ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗The Fake GitHub Download Arrived With a Microsoft-Signed EDR Killer
The download page looked like GitHub. The driver carried Microsoft's attestation. Neither fact made…
Read GitHub ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.


