Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Attackers Are Trying to Turn a WordPress Template Bug Into Code Execution
WordPress fixed a conditional code-execution path on 22 September. Within hours, attackers were trying to turn the flaw into PHP file writes.
Read the article ↗Current reporting
Latest intelligence

The FBI Confirms Its Jobs Portal Was Compromised but Not What Was Taken
The FBI has confirmed that its recruitment portal was compromised. It has not confirmed the attackers' biggest claim about what they took.
In a statement on 23 September, the bureau said it was investigating a cybercriminal group's claim involving fbijobs.gov and alleged impact to FBI employee personally identifiable information. The FBI said it had not yet determined whether the breach occurred through a third party or its own enterprise environment.
That is the verified boundary. The portal compromise is confirmed. The point of entry, scope of access and alleged exposure of employee data remain under investigation. Reports attributing the incident to ShinyHunters and describing a much larger trove are claims, not established facts at the time of publication.
Jobs websites are often treated as public-facing communications platforms. Their application systems are something else entirely. They can collect addresses, work histories, qualifications, demographic data, supporting documents and details that reveal an individual's interest in sensitive employment.
The FBI's own privacy impact assessment says its candidate gateway collects significant amounts of sensitive information about applicants and employees. It explicitly warns that unauthorised disclosure could compromise the identities of people applying for FBI positions.
The document describes a system in which application information is transferred between domains into an internal human-resources environment. It also describes role-based access, encryption, regular purging, audit logging and cloud-hosted components. Those controls matter, but none of them tells us which layer was compromised in this incident or what the intruder reached.
The FBI says it is working with…

Attackers Are Exploiting the System That Manages the Rest of Your Network
The system designed to control an organisation's network edge can become the attacker’s control point instead. Arista has confirmed active exploitation of CVE-2026-93952, a critical improper-input-validation flaw in on-premises VeloCloud Orchestrator. Successful…
24 Sep 2026 · 3 min read
EvilTokens Compromised 12,000 Inboxes and Let AI Choose the Next Victim
The most dangerous feature of EvilTokens was not its phishing page. It was what happened after the victim signed in. Microsoft says the cybercrime service was linked to more than 12,000 compromised…
24 Sep 2026 · 4 min read
One OAuth Profile Can Turn BIG-IP APM Into a Remote Code Execution Target
The product guarding access to the network may now be the way into it. F5 has confirmed active exploitation of CVE-2026-94127, a critical heap-based buffer overflow in BIG-IP Access Policy Manager. Under…
24 Sep 2026 · 3 min read
Chrome Fixed 11 Critical Flaws Before the CVE Databases Could Catch Up
Google has shipped Chrome 154 with 108 security fixes, including 11 vulnerabilities it classifies as critical. Yet some of the identifiers are still missing from, or incompletely represented in, the public CVE…
24 Sep 2026 · 4 min readRevised reporting
Recently updated
How OpenAI’s Agents Turned a Read-Only Web Task Into a Public Message Board
Researchers reconstructed roughly 18,000 posts from OpenAI agents that used public wikis to coordinate, share answers and route around intended restrictions.
Read articleJetBrains Left TeamCity Unpatched and Put Cadence Source Code and Credentials Within Reach
JetBrains closed the Cadence investigation after finding attackers could have reached current storage containing source code and credentials. The investigation is over. The risk is not.
Read articleTwo Arrests Put a Number on TeamPCP’s Supply-Chain Damage
Google says an undercover Mandiant analyst reached TeamPCP's inner circle, watched stolen credentials accumulate and helped disrupt the group's follow-on access.
Read articleThe Phishing Email Really Came From Trezor. That Was the Problem.
Brevo closed the SSO path behind the Trezor phishing incident. Four days later, the attackers returned through a Cloudflare key and reached scripts embedded across customer websites.
Read articleThe Rust Crates Were Removed in Under Two Hours. The Build Hosts Still Need Incident Response.
The malicious crates and the new video-call campaign are separate incidents. They meet at the same target: the people and credentials trusted to publish Rust packages.
Read articleGeographic context
Regional intelligence

Spain’s Reported AI-Agent Breach Happened Behind a Login That Worked
A legitimate login did not mean legitimate intent. Spain's data-protection authority describes an alleged…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence
Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
Cisco Found a Missing Login Check in Its Data-Centre Control Panel
The software coordinating a data centre deserves scrutiny before an attacker proves why. Cisco…
Read Cisco ↗
The Malicious npm Release Had Valid Provenance Because the Build System Wo…
The poisoned package was not smuggled around the build system. GitHub Actions built it,…
Read GitHub ↗
Adobe Campaign Classic Has Three CVSS 10 Paths to Code Execution
Adobe has fixed three critical Adobe Campaign Classic vulnerabilities that can let an unauthenticated…
Read Adobe ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




