Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Snowflake Ends Broad Gen1 Advice; SPCS Remains Constrained
Warehouses improved. SPCS remains constrained.
Read the article ↗Current reporting
Latest intelligence

A Patient Code Did Not Make IQVIA’s Health Database Anonymous
Italy's privacy regulator focused on linkability, detailed records and the controller's real role. On 23 September, the Italian Garante ordered a €7 million fine against IQVIA Solutions Italy. It found that a stable patient code, combined with detailed health and location records, did not make the database anonymous. The project covered about one million patients of 800 GPs. IQVIA argued that the data was anonymous and its role narrower. The regulator rejected those positions and treated the company as controller from collection. A separate free-text issue included direct identifiers for about 3,370 patients, around 3,080 with health information. That is not evidence that all one million records were directly exposed or that an external attacker was involved. Before relying on anonymity, test the actual attributes, linkability, extraction path, controller role, lawful basis and DPIA evidence. This is an editorial inference from the case, not a new universal checklist. The 120-day compliance clock begins on notification, whose date is unknown. The fine was imposed; payment and judicial finality are unverified. For wider context, read our European Health Data Space guide. Source: Italian Garante order No. 710, decided 23 September 2026; announcement, dated 2 October 2026.

AhsayCBS 10.3.4 Was Still Affected
Apply 10.3.4.45, restrict management access and investigate earlier exposure. Ahsay's 10 October critical alert says 10.3.4.0 did not fully address CVE-2026-105133 and CVE-2026-105134. Version 10 partners should install the partner-only 10.3.4.45 hotfix…
10 Oct 2026 · 2 min read
Advantest Confirms Personal Data Extraction
Advantest's 6 October notice says attackers extracted data, including the recipient's personal information, during its February ransomware incident. It does not describe a new October attack or give an affected total. The…
10 Oct 2026 · 2 min read
Check the Certificates, Not Just DNS
Audit certificates after DNS recovery. Attackers hijacked .gh, .sl and .as third-party registry infrastructure, obtaining unauthorised certificates; Google systems were unaffected. A registry compromise sits above an individual registrar account. Recovering DNS…
10 Oct 2026 · 1 min read
Validate GitHub Advisory Provenance
GitHub added five nullable SecurityAdvisory GraphQL fields on 2 October, according to the current reference. That nullability is the decision boundary. Schema availability alone is not enough to retire a retrieval path.…
10 Oct 2026 · 2 min readRevised reporting
Recently updated
ASOS Says Contact Details May Be Affected
Check official channels.
Read articleAttackers Are Already Exploiting the NetScaler Flaws Citrix Just Patched
Citrix has patched eight NetScaler vulnerabilities and confirms attackers are already exploiting two critical flaws. One unauthenticated command-execution bug affects every customer-managed deployment.
Read articleKB5124010 Can Close Legacy AC-3 Apps
Successful installation is only the first check. Test the complete workflow, capture reproducible evidence and match the remedy to the actual failure.
Read articleMicrosoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
The fixes were real, but there was no update button for customers. The affected layer sat inside Microsoft's cloud control plane.
Read articleEight Atlassian Products Could Expose Known Files
Patch eight products.
Read articleGeographic context
Regional intelligence

Spain’s Election Call Puts Its NIS2 Delay Back in Focus
Spain has called a November election after the Commission documented incomplete NIS2 transposition in…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Map AI Data for Malaysia’s Consultation
Turn each AI use into one inspectable data route with an owner.
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence

Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
Cisco Changes IOS XE Fix Matrix for Seven CVEs
Cisco revised its IOS XE fix matrix on 2 October. Recheck your destination; no…
Read Cisco ↗
Validate GitHub Advisory Provenance
GitHub added five nullable SecurityAdvisory GraphQL fields on 2 October, according to the current…
Read GitHub ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
FortiMail Operators Face Active Exploitation While Fixes Remain Upcoming
FortiMail faces active exploitation. CVE-2026-104286 allows unauthenticated arbitrary-file writes through crafted HTTP or HTTPS…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.



