Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Securing the Alert Box Is No Longer Enough Under the FCC’s New Cyber Rules
The FCC's EAS cybersecurity rule reaches beyond alert encoders to studio transmitter links and remotely managed equipment in the programming path. Three targeted controls apply from…
Read the article ↗Current reporting
Latest intelligence

A Real ChatGPT Page Led Users Into a Fake Verification Trap
An attacker-built Custom GPT called “Plus 5.6” appeared at a real chatgpt.com address and presented a false service notice. It pointed users to a Google Sites “backup”, where a fake Cloudflare check told them to run PowerShell. Huntress confirmed two infections that began at a Custom GPT. Its security operations centre handled at least 40 incidents tied to that Sites domain; it did not establish a GPT entry point for the rest.In some cases, a sponsored search result led to the GPT. Huntress traced the copied command to a malicious MSI, a signed Canon application loading a modified DLL, persistence and a remote access trojan. A later version used a signed Stardock host. Huntress says the first GPT was removed by 25 September; a linked replacement was active when its 28 September report appeared. That is a dated observation, not a claim of current availability or a platform breach.Does a real ChatGPT address make the instruction safe?No. OpenAI's documentation describes Custom GPTs as configurable with builder-supplied instructions. Huntress says this page identified its author as a community builder while borrowing a model-like name. The hostname showed where the page lived, not whether its “service availability” message was official.BlackTree analysis: The decisive point was the handoff from a hosted conversation to an unrelated “backup” site, then from a web check to Windows Terminal. Each change of context needs its own trust decision. A user can leave that flow and reach the service through a saved, independently obtained route. A CAPTCHA or…

DIVD Says Its Intruder’s AI Agent Left a Trail Investigators Could Follow
An intruder's mistakes can be useful evidence. They are not a reason to assume the damage was small. In a public update reviewed on 29 September, the Dutch Institute for Vulnerability Disclosure…
29 Sep 2026 · 3 min read
A Patched MCP Client Can Still Send Its Secret to the Wrong Server
A completed package upgrade does not prove that an OAuth client has stopped trusting the wrong party. For an MCP client, the practical question is which authorisation server the running application will…
29 Sep 2026 · 3 min read
DC’s Public Health Reports Carried Hidden Data on Nearly 400,000 People
Two reports on the District of Columbia's Department of Health Care Finance website displayed summary figures, yet contained hidden personal information that may have been reachable by people without permission. The agency…
29 Sep 2026 · 4 min read
A Nexus Upgrade Can Corrupt the Configuration a Reboot Will Not Restore
An NX-OS change can corrupt a Cisco Nexus 3000 or 9000 switch's configuration. Cisco field notice FN74371 identifies upgrades from 10.4(6)M or later 10.4(x)M to 10.5(1)F, 10.5(2)F or 10.5(3)F and downgrades from…
29 Sep 2026 · 5 min readRevised reporting
Recently updated
Attackers Are Already Exploiting the NetScaler Flaws Citrix Just Patched
Citrix has patched eight NetScaler vulnerabilities and confirms attackers are already exploiting two critical flaws. One unauthenticated command-execution bug affects every customer-managed deployment.
Read articleBitget’s $388 Million Breach Now Points to a Third-Party Security Product
Bitget says its $388 million breach may have begun in a third-party security product, exposing credentials used to send fraudulent withdrawal commands.
Read articleKiteworks Pulled the Plug and Found a Critical Flaw
Kiteworks says its shutdown uncovered a critical flaw in a capability enabled for fewer than 1% of customers. Service can resume, with separate support guidance for self-hosted Advanced Forms.
Read articleThe PeopleSoft Extortion Campaign Turns a Legacy ERP into an Internet-Facing Risk
The WAF Blocked the Name. The Attacker Changed the Spelling. Update, 29 September 2026: Google's 25 September report describes renewed ShinyHunters exploitation of CVE-2026-35273 across sectors. The group changed its…
Read articlePatching StyleSmuggler Will Not Evict an Attacker From Your Magento Store
Adobe has patched the exploited StyleSmuggler flaw. Magento and Commerce operators still need to check for compromise, verify the right hotfix and rotate exposed credentials.
Read articleGeographic context
Regional intelligence

The EU’s New Data-Centre Labels Won’t Tell You the Whole Energy Story
The EU plans public energy and water grades for individual data centres from 2027.…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence
Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
Cisco Found a Missing Login Check in Its Data-Centre Control Panel
The software coordinating a data centre deserves scrutiny before an attacker proves why. Cisco…
Read Cisco ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
The Malicious npm Release Had Valid Provenance Because the Build System Wo…
The poisoned package was not smuggled around the build system. GitHub Actions built it,…
Read GitHub ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




