This website uses cookies
Read our Privacy policy and Terms of use for more information.
Aug 17, 2026
This week’s highest-priority stories all start with attacker-controlled input crossing a trusted boundary: a job lure that ends in kernel access, a crafted request that can drop a VPN gateway, and a meeting message that can execute code on another participant’s device. The practical lesson is to rank exposure by what external users are allowed to make trusted software parse—not just by CVSS.
Aug 10, 2026
This week’s strongest signals came from platforms attackers can use to multiply a single foothold. N-able’s N-central incident exposed a path from remote management into managed endpoints; Metabase’s zero-day put connected data stores in reach; and UNC6671 used helpdesk vishing to steal cloud sessions before automating exfiltration. The recurring risk is what legitimate enterprise tooling can do at scale once control is lost.
Aug 3, 2026
This week’s most consequential signals came from systems that sit between users and critical operations: water-sector PLCs, firewall management, image processing, and third-party cloud storage. Attacks degraded water operations in multiple states, Cisco confirmed exploitation of a static credential in FMC, Rails warned that image variants could expose application secrets, and Amgen disclosed material data theft. The common question for defenders is not only what is exposed, but how much authority each intermediary inherits.
Jul 27, 2026
This week exposed two different failure modes in the patch race: flaws exploited almost as soon as fixes landed, and older fixes that still had not reached the systems attackers wanted. WordPress, Zimbra, Check Point, and AI evaluation infrastructure all point to the same operational problem: defenders need proof of closure, not merely proof that a fix exists.
Jul 20, 2026
This week’s strongest signals came from a remote-access appliance under active exploitation, trusted package releases carrying malware, a ransomware event that stopped U.S. production, and alerts that were dismissed before a government breach was confirmed. The common problem was not a lack of controls. It was a lack of evidence that those controls had actually held.
Jul 13, 2026
This week's strongest signals came from software and infrastructure that defenders often trust by default: legacy web servers, build dependencies, edge routers, payment SDKs, and managed AI execution environments. The practical priority is to verify what executes automatically, what can reach secrets, and what remains exposed after a fix.
Jul 6, 2026
This week’s security picture was defined by automation and compressed response time. JADEPUFFER used an AI agent to move from initial access through destructive database extortion, ARToken exposed how Microsoft 365 token theft is being productized, and Google disrupted a residential proxy network used by hundreds of threat clusters. At the same time, SharePoint, NetScaler, and Oracle E-Business Suite flaws moved rapidly into active exploitation.
Jun 29, 2026
This week’s incidents converged on recovery paths, third-party dependencies, and infrastructure that users implicitly trust. Polymarket’s website dependency became a transaction-draining path, a Texas licensing vendor exposed data on more than three million people, and Russian intelligence operators shifted from Signal verification codes to backup recovery keys. The defender priority is to validate every path that can restore access, inject trusted content, or administer network infrastructure.
Jun 22, 2026
Attackers are gaining leverage through systems that already hold trusted access—from SaaS integrations and SIEM infrastructure to network and security control planes. This week’s defender move is to reduce durable credentials and verify activity after every patch, revocation, or configuration change.
Jun 15, 2026
This week’s theme is speed. Attackers moved quickly against internet-facing access systems, enterprise applications, SaaS APIs, browsers, AI gateways, mobile gateways, and backup infrastructure. The defender move is to treat exposed high-leverage systems as emergency assets: patch fast, verify compromise, and preserve enough evidence to know whether the first fix was enough.