Index
Archive
115 published assessments. Filter in the browser; no account required.
2026-09-12Daily TopGitLab’s CVSS 10 file-read is on KEV. Patching without hunting the commits API is not remediation.
2026-09-11Daily TopAn AI-agent campaign compromised 440 PaperCut servers. Patching without hunting the print server is not remediation.
2026-09-11OT IntelligenceICS Patch Tuesday hit M580 Safety and Reyrolle. The exploited device this week is a MikroTik, not a PLC.
2026-09-10Daily TopCisco FMC is under active root-level exploitation. The hotfix does not clean a box that already ran license.tmp.
2026-09-09Daily TopTwo Windows EoP zero-days landed in CISA KEV on Patch Tuesday. The 974-CVE count is not the story.
2026-09-08Daily TopAdobe ships a CVSS 10 Magento hotfix. Patching without key rotation is not remediation.
2026-09-07IT IntelligenceThe IT week was RMM, session theft, and a sixth Chrome 0-day — not a quiet Labor Day
2026-09-07OT IntelligenceOT this week was a CISA ICS stack, not a new wiper — internet-facing controllers are still the incident
2026-09-07Daily TopASCII smuggling left the LLM paper and showed up as invisible Unicode in 2.3 million phish mails
2026-09-07Daily TopFake IT on Teams was not vishing-for-a-stealer — it was hands-on-keyboard to the domain controller
2026-09-07Daily TopThe fake Razer/Edge/Kaspersky installer was a regenerated ZIP, not a one-hash IOC
2026-09-07IT IntelligenceLate August closed with TerminalFix, fake installers, and ASCII that mail filters could not see
2026-09-07OT IntelligenceLate August OT — a small UK generator went dark four days; S7 hunts do not pause for that
2026-09-07Daily TopTerminalFix was ClickFix that kept going — stego PNGs, AD recon, then a Python reverse tunnel
2026-09-07IT IntelligenceThe week after Patch Tuesday was stolen tax files, Zimbra, and a VPN that was Sandworm
2026-09-07Daily TopA small UK generator went dark four days — the grid barely noticed, the operator class did
2026-09-07OT IntelligenceAA26-231A — five U.S. agencies on Siemens S7, snap7, and AI-written S7comm scripts
2026-09-07Daily TopSPECTRE is UAT-10147's cross-platform implant — RTCore64, DBUtil, and a fake acpi_pad.ko
2026-09-07IT IntelligenceAugust Patch Tuesday was Lazarus on AFD.sys — and Storm-1175 was already on N-central
2026-09-07OT IntelligenceMid-August OT was ICS Patch Tuesday, fifteen CISA notes, then a hospital HVAC — not Stage 2
2026-09-07IT IntelligenceEarly August was npm worms, ClickFix on Mac, and N-central measured in hours
2026-09-07Daily TopDeadLock's encryptor is Rust; the negotiation desk is a Polygon contract and an HTML chat
2026-09-07Daily TopDragos Q2 2026 — 1,140 industrial ransomware claims and still zero Stage 2 ICS kill-chain cases
2026-09-07OT IntelligenceOT this week was still internet PLCs — FBI/EPA water, then firmware you extract with the vendor tool
2026-09-07Daily TopFirmware walk-off through the programming interface — Nozomi's PLC extraction note is a trust-boundary problem
2026-09-07Daily TopNozomi's "zero-days at AI speed" is a disclosure-capacity warning — not a new ICS 0-day dump
2026-09-07Daily TopChainDrop was an npm worm with a postinstall — Unit 42 and Microsoft both treated it as self-propagating supply chain
2026-09-07Daily TopCaptiveCrunch put Midnight Blizzard on hotel sign-in pages — the traveler was the payload path
2026-09-07Daily TopFBI/EPA: seven states, internet-facing MicroLogix, changed IPs — some pressure loss and flooding
2026-09-07Daily TopDutch intel found APT28 on cameras along the NATO logistics tail — not just the front
2026-09-07Daily TopShinyHunters is a brand over OAuth — Salesforce connected apps, not a new VPN 0-day
2026-09-07Daily TopADFS token-signing keys live in Machine DPAPI — a “rotated” cert in the database can be a ghost
2026-09-07Daily TopCyberAv3ngers aimed at sirens and Barix — the technical bar was legacy audio-over-IP, the goal was trust
2026-09-07Daily TopStealC rode Amadey — Microsoft and Europol cut 200 C2s, not the infostealer economy
2026-09-07Daily TopHandala's Cal Water dump was billing and RTKBase — Cal Water said OT did not move
2026-09-07Daily TopSapphire Sleet poisoned @mastra in 45 minutes — easy-day-js was the dropper, npm was the plant
2026-09-07Daily TopUNC6508 spent a year in North American medical research — REDCap was the door, defense intel was the take
2026-09-07Daily TopTrane Tracer SC+ had a diagnostic service that was pre-auth root on the cooling controller
2026-09-07Daily TopChatGPT Plus billing mail was a carder page — AI brands are the new Microsoft logo
2026-09-07Daily TopData-center OT is the cooling loop and the substation — NERC already rang the load alarm
2026-09-07Daily TopDragos Q1 2026 held the high baseline — 1,020 industrial ransomware claims, Qilin and Akira still on top
2026-09-07Daily TopTeam82 ran Claude Opus on a video intercom they already owned — the LLM found bugs, not a new ICS weapon
2026-09-07Daily TopThe Gentlemen encryptor was a Go worm with a password — Storm-2697 sold the rest as RaaS
2026-09-07Daily TopThe stealthy intrusion was a signed HPE agent under a third-party IT contract, not a 0-day
2026-09-07Daily TopGTIG's first AI-written zero-day was a 2FA logic bug — and they killed the mass run
2026-09-07Daily TopQ1 2026 email was 8.3 billion phish attempts and a 146% QR spike — then Tycoon2FA got hit
2026-09-07Daily TopEnOcean SmartServer turned a timezone IP-852 packet into pre-auth root on the BMS gateway
2026-09-07Daily TopCODESYS Service credentials were enough to swap the boot application for a root backdoor
2026-09-07Daily TopSapphire Sleet's macOS heist was a fake Zoom SDK in Script Editor, not a Gatekeeper bypass 0-day
2026-09-07Daily TopStorm-2755 stole Canadian paychecks through search-bar Microsoft 365, not a university phishing wave
2026-09-07Daily TopLucidRook only runs if the box looks like Taiwan — Lua stager, fake AV, printers' FTP as C2
2026-09-07Daily TopForest Blizzard did not need malware on the laptop — it needed your home router's DNS
2026-09-07Daily TopStorm-1175's Medusa business was the patch gap on the internet, measured in hours
2026-09-07Daily TopThe Axios npm hijack was a three-hour window on a 70-million-download library — Microsoft says Sapphire Sleet
2026-09-07Daily TopDragos's 2026 landscape brief is the defender translation of the Year in Review — same groups, sharper access-path advice
2026-09-07Daily Top2026 tax-season phishing was an accountant-targeting RMM problem, not just refund-QR spam
2026-09-07Daily TopStorm-2561's fake VPN clients turned "Pulse Secure download" into a credential form
2026-09-07Daily TopDragos Q4 2025 industrial ransomware — 1,211 claimed hits, Qilin still the volume leader
2026-09-07Daily TopMicrosoft's AI-as-tradecraft brief is mostly a productivity story — with DPRK IT-worker fraud as the serious case
2026-09-07Daily TopGTIG's 2025 zero-day tally was enterprise-heavy: 90 exploited bugs, almost half in business tech
2026-09-07Daily TopTycoon2FA was MFA-bypass as a monthly subscription — Microsoft's March disruption moved the volume, not the motive
2026-09-07Daily TopLonTalk is still on the internet — Claroty counted a thousand exposed Echelon controllers
2026-09-07Daily TopDragos's 2026 Year in Review is control-loop mapping — ransomware counted as OT by consequence
2026-09-07Daily TopUNC1549 still hires aerospace — fake job portals, resume malware, not a new fighter-jet wiper
2026-09-07Daily TopHanwha Wisenet: five mediums, a hard-coded WDM password, and a camera fleet that sits on the OT VLAN anyway
2026-09-07Daily TopUAT-8837 is an access team on North American critical infrastructure — Sitecore 0-day, then SharpHound
2026-09-07Daily TopRedVDS sold $24 Windows boxes with one cloned hostname — and Microsoft took the storefront to court
2026-09-07Daily TopInternal-looking mail was often a routing and spoof-protection failure, not a Microsoft "Direct Send bug"
2026-09-07Daily TopReact2Shell was a CVSS 10 that China-nexus actors and ransomware both used before most shops patched
2026-09-07Daily TopLANDFALL was a year of Samsung zero-click — WhatsApp image, CVE-2025-21042, Middle East targeting
2026-09-07Daily TopPROMPTFLUX and PROMPTSTEAL call the LLM at runtime — malware that writes the next stage
2026-09-07Daily TopSesameOp did not hack OpenAI — it used Assistants API as a dead-drop the proxy would allow
2026-09-07Daily TopThe engineering laptop was the OT perimeter — AutomationDirect Productivity Suite had nine ways in
2026-09-07Daily TopAzure Blob Storage is being used as phishing host, malware CDN, and quiet C2 — under a Microsoft hostname
2026-09-07Daily TopCL0P's Oracle EBS emails were the bill — the 0-day had been in the suite since August
2026-09-07Daily TopStorm-2657 stole university paychecks through mailbox rules and Workday SSO, not a payroll CVE
2026-09-07Daily TopMicrosoft Teams is an authentication and remote-support channel that attackers already treat as one
2026-09-07Daily TopGoAnywhere CVE-2025-10035 was already a Medusa door when Fortra still sounded like a patch note
2026-09-07Daily TopXCSSET's 2025 turn made shared Xcode projects a developer-to-developer supply chain
2026-09-07Daily TopBRICKSTORM lived 393 days on appliances with no EDR — legal and SaaS were the point