Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

AVEVA’s Patch Cannot Secure the Files You Forgot
Four PIMBoards flaws have a vendor fix, but old project files, backups and passwords still need separate handling after the software update.
Read the article ↗Current reporting
Latest intelligence

Apple’s 273-CVE Security Release Includes a Flaw Attackers Have Already Exploited
The Apple security updates released on 14 September are bigger than a single operating-system update. Ten separate advisories cover iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari and Xcode. Across them, Apple lists 1,038 product-level CVE references. Remove the overlap created by shared components and the result is 273 unique vulnerability identifiers. That is an unusually large attack-surface reset. It is also a number that needs careful handling. Apple did not describe all 273 vulnerabilities as critical, and the total is not a count of 273 newly discovered zero-days. The advisories include everything from privacy and information-disclosure flaws to denial-of-service conditions, sandbox escapes, kernel-level code execution and remote attack paths. One entry makes the release more urgent than the headline alone suggests. CVE-2026-65400, an authentication bypass in the macOS Screen Sharing Server, is already in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue. It predates this release and was addressed in earlier Apple updates, but it appears again in Apple’s new macOS release advisories. That matters because a fresh operating-system rollout can contain both newly disclosed flaws and known attack paths that organisations may still not have remediated across their estates. The 273 figure is real, but it is not the whole story BlackTree independently counted the CVE identifiers in Apple’s ten official advisories. The per-advisory totals add up to 1,038 references, because the same vulnerability can affect several products built on shared frameworks. Deduplicating those references produces 273 unique CVEs. Apple advisoryUnique CVEs listed…

A $4 Lost-Phone Report Could Silence Your Home Alarm
The phone was still sealed in its box. Yet after researchers reported its identifier as lost, it could not connect to the mobile network. That demonstration exposes a larger problem: the anti-theft…
16 Sep 2026 · 4 min read
Six Mistral Vibe Flaws Let an AI Agent Act Without Your Approval
A Mistral Vibe permission bypass begins where a coding assistant is supposed to pause before a risky command. It asks for permission, and the developer decides whether the command may run. Six…
15 Sep 2026 · 4 min read
GoAnywhere MFT’s ‘Secure Folder’ Had a Hidden Exit
A managed file-transfer service is supposed to be unusually clear about who can reach which files. Fortra has disclosed a flaw in GoAnywhere MFT that breaks that expectation for a specific class…
15 Sep 2026 · 4 min read
A Traefik Shortcut Could Let a Stranger Inherit Your Login
A Traefik HTTP/3 proxy should keep two visitors' identities separate, even when it reuses connections to make their requests faster. A Traefik advisory published on 7 September 2026 shows a narrow but…
15 Sep 2026 · 4 min readRevised reporting
Recently updated
Hackers Searched 1.8 Million Android Apps for the Keys to Someone Else’s Busin…
An Android app can work exactly as intended while exposing a credential that should never have left a private system. For its users, nothing looks wrong. For an attacker, the…
Read articleThe Firewall Manager Shipped With a Password Attackers Already Knew.
Cisco has confirmed active exploitation of static credentials in Secure Firewall Management Center. The embedded account is low privilege, but the management platform's position and the possibility of exploit chaining…
Read articleAttackers Used PaperCut to Hunt for Passwords Inside Schools and Universities
Update, 5 September 2026: Arctic Wolf told The Hacker News that it observed attackers using the PaperCut vulnerability chain against vulnerable servers at education organisations ranging from K-12 schools to…
Read articleThe CRA Reporting Clock Starts on 11 September 2026
On 11 September 2026, the Cyber Resilience Act becomes operational in a very specific way. Manufacturers will need to report actively exploited vulnerabilities and severe product-security incidents through ENISA's Single…
Read articleGoogle Fixed 230 Chrome Bugs. One Was Already in Attackers’ Hands.
Google fixed 230 security issues in Chrome 153. One sentence in the release notes matters more than the size of that list: an exploit for CVE-2026-87491 exists in the wild.…
Read articleGeographic context
Regional intelligence

Six Mistral Vibe Flaws Let an AI Agent Act Without Your Approval
Six Mistral Vibe flaws expose a gap between the command an AI coding agent…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
One Click in Sogou’s Keyboard Opened a Six-Year-Old Browser to a Spy…
Gen Digital traced a GRAYRABBIT intrusion to a crafted Sogou Input Method link. The…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence

A Million Fake CEO Emails Tried to Make Finance Pay a ServiceNow Invoice T…
The email appeared to come from the boss. Underneath it sat a detailed fake…
Read Microsoft ↗
A Network Packet Could Give Attackers Root on Cisco Nexus 9000 Switches
Cisco has disclosed a critical Nexus 9000 flaw where a network packet can become…
Read Cisco ↗
Adobe Campaign Classic Has Three CVSS 10 Paths to Code Execution
Adobe has fixed three critical Adobe Campaign Classic vulnerabilities that can let an unauthenticated…
Read Adobe ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗
The Security Extension Could Send Your Browser Through an Attacker’s Serve…
A browser extension installed to protect privileged access could be turned into the route…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




