Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Current reporting
Latest intelligence

Cerner Breach: 19.9m People Reported Affected
A newly reported scale for the Cerner breach, with evidence limits and practical guidance for affected people. A Texas regulator record BR-0005382, dated 2 October 2026, reports 19,929,149 affected people, including 2,992,244 Texans, in Cerner Corporation's 2025 legacy-system breach. That does not show a new October 2026 intrusion. What the evidence shows The Texas table lists address, Social Security number information and medical information. The larger total appears in the public response, not as a visible table column. Texas warns that record details can change, so this remains a reported figure tied to the 8 October retrieval, not an independently audited global count. Regulator-reported dates are not independently confirmed access times. The California notice adds context, not scale A California Attorney General Cerner record links a redacted provider sample dated 25 July 2025. It says an unauthorised party obtained data held by an electronic health record vendor and accessed personal health information on legacy Cerner systems; the provider's systems were not affected. The sample says information for a recipient may have included a name, Social Security number and medical-record information. That wording is provider- and recipient-specific. It does not establish one uniform field set for everyone in the reported population. The sample enrolment deadline was 31 January 2026. It is expired and cannot be presented as a current generic offer. Readers should use the terms and contact route in the notice addressed to them. Population and data type are different questions BlackTree analysis: population, incident categories and recipient-specific fields are…

Cisco License On-Prem Exposes Unauthenticated Password Reset
Vulnerable License On-Prem installations allow unauthenticated password reset, according to Cisco’s 7 October advisory. The operational priority is to identify the appliance, restrict unnecessary management access and choose a release that addresses…
8 Oct 2026 · 3 min read
Malicious Tensorlake npm Release
The malicious Tensorlake npm release requires containment first, followed by evidence-led cleanup and prompt credential rotation. Tensorlake’s project says malicious tensorlake@0.5.144 was published after a repository-administrator account committed the payload directly to…
8 Oct 2026 · 3 min read
Publica Leak Confirmed
Swiss Federal Pension Fund Publica says its unnamed software supplier identified a cyber attack at the end of September. Its 8 October notice confirms that data leaked and says Publica notified members…
8 Oct 2026 · 2 min read
FortiBleed Turns Access Into Ransomware Risk
US agencies describe FortiBleed as an active credential campaign against internet-facing FortiGate firewalls and SSL VPN gateways. Reported outcomes include administrator lockouts and brokered access for INC/Lynx and Payload ransomware affiliates. This…
8 Oct 2026 · 1 min readRevised reporting
Recently updated
KB5124010 Can Close Legacy AC-3 Apps
Successful installation is only the first check. Test the complete workflow, capture reproducible evidence and match the remedy to the actual failure.
Read articleMicrosoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
The fixes were real, but there was no update button for customers. The affected layer sat inside Microsoft's cloud control plane.
Read articleEight Atlassian Products Could Expose Known Files
Patch eight products.
Read articleSonicWall Patched Two Zero-Days. Then the Replacement Builds Were Exploited Too.
SonicWall confirmed exploitation of two SMA1000 vulnerabilities. If compromise indicators are present, defenders must rebuild the appliance and reset credentials, not merely install the hotfix.
Read articleSouth Korea orders security checks after bank attacks
South Korea warns bank customers about tailored scams.
Read articleGeographic context
Regional intelligence

Spain’s Election Call Puts Its NIS2 Delay Back in Focus
Spain has called a November election after the Commission documented incomplete NIS2 transposition in…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence

Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
Cisco License On-Prem Exposes Unauthenticated Password Reset
Vulnerable License On-Prem installations allow unauthenticated password reset, according to Cisco’s 7 October advisory.…
Read Cisco ↗
Opening the Coding Test Was the Execution Step
Unit 42's Blinder Tunnel report traces an Iranian-nexus operation targeting one person in Iraqi…
Read GitHub ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
FortiMail Operators Face Active Exploitation While Fixes Remain Upcoming
FortiMail faces active exploitation. CVE-2026-104286 allows unauthenticated arbitrary-file writes through crafted HTTP or HTTPS…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.



