This website uses cookies
Read our Privacy policy and Terms of use for more information.
Fast, clear cybersecurity insights on threats, vulnerabilities, and industry news.
I consent to receive newsletters via email. Terms of use and Privacy policy.
Sep 8, 2026
This week’s strongest stories are all side-door failures. SonicWall confirmed exploitation of two SMA 1000 flaws, JFrog’s Artifactory authentication weakness moved into the exploited-vulnerability queue, and a Microsoft-observed campaign used Teams and legitimate remote-support workflows to reach deep into enterprise networks. The common problem is not missing controls; it is an alternate route that reaches the same privileged outcome. Defenders should map those routes explicitly and monitor when ordinary workflows begin behaving like administration.
Aug 31, 2026
Issue #153 connects PaperCut’s active exploitation, the QTFY disruption, and Boston Scientific’s global network outage through one operational problem: systems that look like supporting infrastructure can inherit outsized authority or business dependency. Defenders should map not only what is exposed, but what each control surface can make other systems do—and how far failure can travel when that trust is abused.
Aug 24, 2026
This week is best read as a clock. Malicious Rust crates were live on crates.io for roughly 86 to 107 minutes. CISA moved Zimbra’s command-injection flaw into the exploited catalog four days after CERT Polska reported attacks, and moved four already-patched Microsoft, VMware, and Apple flaws in on a single day. The gap between a fix existing and an exploit running is now measured in hours and days, and the defender question has shifted from whether to patch to how much of the window you can still account for.
Aug 17, 2026
This week’s highest-priority stories all start with attacker-controlled input crossing a trusted boundary: a job lure that ends in kernel access, a crafted request that can drop a VPN gateway, and a meeting message that can execute code on another participant’s device. The practical lesson is to rank exposure by what external users are allowed to make trusted software parse—not just by CVSS.
Aug 10, 2026
This week’s strongest signals came from platforms attackers can use to multiply a single foothold. N-able’s N-central incident exposed a path from remote management into managed endpoints; Metabase’s zero-day put connected data stores in reach; and UNC6671 used helpdesk vishing to steal cloud sessions before automating exfiltration. The recurring risk is what legitimate enterprise tooling can do at scale once control is lost.