Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Google’s Cloud Storage Failure Started Earlier
Reconcile writes before repeating work.
Read the article ↗Current reporting
Latest intelligence

Terraform’s Provider Trap
A convincing infrastructure task can carry an executable trust decision before any planned deployment. Zscaler published its analysis on 8 October after finding the campaign in July. Its researchers found a trojanised provider that ran when Terraform loaded it and still performed the expected provider work. Opening a folder is not proof of compromise. Identify what executed. The provider is part of the execution path Terraform providers are not passive configuration. HashiCorp describes them as plugins, while the dependency lock file records selected versions and checksums for later runs. Zscaler's sample contacted a HashiCorp-themed lookalike and delivered FLATROOF followed by ROOFDECK. Windows execution depended on a compatible Unix-like shell being present. For defenders, the practical boundary sits before the first run. Treat an unfamiliar provider source, a private registry, a changed lock file or an unexplained plugin binary as executable code review, not as routine project metadata. A separate investigation shows how the lure can look ordinary SentinelOne published a separate investigation on 18 September and revised it on 21 September. It described fake interview projects whose lock files directed terraform init towards attacker-controlled provider registries. That case involved an IT-services victim in India with no known cryptocurrency connection. SentinelOne did not prove the delivery route for that victim, so it should not be treated as proof that every infection began with the same interview lure. The two reports describe related abuse of the provider trust path, but they are not one continuous incident record. Zscaler does not establish how…

Verify the Bytes Your Agent Will Run
Controlled preprint research, not a reported live campaign. PyCache Trap pairs benign visible Python source with a different compiled cache that a compatible loader can select. Version 1 was submitted on 7…
11 Oct 2026 · 3 min read
Keep CodeQL Scanning When Your Runner Changes
A code-scanning policy can remain enabled while the analysis it depends on no longer completes. CodeQL 2.27.2 makes that risk immediate for teams upgrading Apple build runners or maintaining custom Go queries.…
11 Oct 2026 · 4 min read
Trusted Servers Can Still Send Fraudulent Payments
Network origin, credentials and transaction authority need separate checks. India's CERT-In and CSIRT-Fin report campaigns targeting financial businesses: attackers compromise applications or APIs, steal payment credentials and transfer funds from the victim's…
11 Oct 2026 · 2 min read
Put Python 3.15 Through Your Production Tests
Python 3.15.0 became stable on 9 October 2026. That closes the release-candidate wait, but it does not prove that your application stack is ready. Treat the new interpreter as a staged migration:…
11 Oct 2026 · 2 min readRevised reporting
Recently updated
ASOS Says Contact Details May Be Affected
Check official channels.
Read articleAttackers Are Already Exploiting the NetScaler Flaws Citrix Just Patched
Citrix has patched eight NetScaler vulnerabilities and confirms attackers are already exploiting two critical flaws. One unauthenticated command-execution bug affects every customer-managed deployment.
Read articleKB5124010 Can Close Legacy AC-3 Apps
Successful installation is only the first check. Test the complete workflow, capture reproducible evidence and match the remedy to the actual failure.
Read articleMicrosoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
The fixes were real, but there was no update button for customers. The affected layer sat inside Microsoft's cloud control plane.
Read articleEight Atlassian Products Could Expose Known Files
Patch eight products.
Read articleGeographic context
Regional intelligence

Spain’s Election Call Puts Its NIS2 Delay Back in Focus
Spain has called a November election after the Commission documented incomplete NIS2 transposition in…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Map AI Data for Malaysia’s Consultation
Turn each AI use into one inspectable data route with an owner.
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence

Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
Cisco Changes IOS XE Fix Matrix for Seven CVEs
Cisco revised its IOS XE fix matrix on 2 October. Recheck your destination; no…
Read Cisco ↗
Keep CodeQL Scanning When Your Runner Changes
A code-scanning policy can remain enabled while the analysis it depends on no longer…
Read GitHub ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
FortiMail Operators Face Active Exploitation While Fixes Remain Upcoming
FortiMail faces active exploitation. CVE-2026-104286 allows unauthenticated arbitrary-file writes through crafted HTTP or HTTPS…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.



