This website uses cookies
Read our Privacy policy and Terms of use for more information.
Sep 14, 2026
This week’s strongest signals show why “patched” is not a single state. BlueMoon exploited Chromium fixes before stable browsers caught up, GitLab’s critical file-read flaw drew probing and a CISA KEV listing within a day of disclosure, and Cisco confirmed active exploitation of a flaw it had fixed months earlier. Defenders need to track where fixes exist—and where their own fleets actually are.
Sep 8, 2026
This week’s strongest stories are all side-door failures. SonicWall confirmed exploitation of two SMA 1000 flaws, JFrog’s Artifactory authentication weakness moved into the exploited-vulnerability queue, and a Microsoft-observed campaign used Teams and legitimate remote-support workflows to reach deep into enterprise networks. The common problem is not missing controls; it is an alternate route that reaches the same privileged outcome. Defenders should map those routes explicitly and monitor when ordinary workflows begin behaving like administration.
Aug 31, 2026
Issue #153 connects PaperCut’s active exploitation, the QTFY disruption, and Boston Scientific’s global network outage through one operational problem: systems that look like supporting infrastructure can inherit outsized authority or business dependency. Defenders should map not only what is exposed, but what each control surface can make other systems do—and how far failure can travel when that trust is abused.
Aug 24, 2026
This week is best read as a clock. Malicious Rust crates were live on crates.io for roughly 86 to 107 minutes. CISA moved Zimbra’s command-injection flaw into the exploited catalog four days after CERT Polska reported attacks, and moved four already-patched Microsoft, VMware, and Apple flaws in on a single day. The gap between a fix existing and an exploit running is now measured in hours and days, and the defender question has shifted from whether to patch to how much of the window you can still account for.
Aug 17, 2026
This week’s highest-priority stories all start with attacker-controlled input crossing a trusted boundary: a job lure that ends in kernel access, a crafted request that can drop a VPN gateway, and a meeting message that can execute code on another participant’s device. The practical lesson is to rank exposure by what external users are allowed to make trusted software parse—not just by CVSS.
Aug 10, 2026
This week’s strongest signals came from platforms attackers can use to multiply a single foothold. N-able’s N-central incident exposed a path from remote management into managed endpoints; Metabase’s zero-day put connected data stores in reach; and UNC6671 used helpdesk vishing to steal cloud sessions before automating exfiltration. The recurring risk is what legitimate enterprise tooling can do at scale once control is lost.
Aug 3, 2026
This week’s most consequential signals came from systems that sit between users and critical operations: water-sector PLCs, firewall management, image processing, and third-party cloud storage. Attacks degraded water operations in multiple states, Cisco confirmed exploitation of a static credential in FMC, Rails warned that image variants could expose application secrets, and Amgen disclosed material data theft. The common question for defenders is not only what is exposed, but how much authority each intermediary inherits.
Jul 27, 2026
This week exposed two different failure modes in the patch race: flaws exploited almost as soon as fixes landed, and older fixes that still had not reached the systems attackers wanted. WordPress, Zimbra, Check Point, and AI evaluation infrastructure all point to the same operational problem: defenders need proof of closure, not merely proof that a fix exists.
Jul 20, 2026
This week’s strongest signals came from a remote-access appliance under active exploitation, trusted package releases carrying malware, a ransomware event that stopped U.S. production, and alerts that were dismissed before a government breach was confirmed. The common problem was not a lack of controls. It was a lack of evidence that those controls had actually held.
Jul 13, 2026
This week's strongest signals came from software and infrastructure that defenders often trust by default: legacy web servers, build dependencies, edge routers, payment SDKs, and managed AI execution environments. The practical priority is to verify what executes automatically, what can reach secrets, and what remains exposed after a fix.