Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Current reporting
Latest intelligence

Eight Atlassian Products Could Expose Known Files
Atlassian's 5 October advisory for CVE-2026-21589 affects eight self-managed products. An unauthenticated attacker knowing a file's exact path and name can read it within the web-application root. Directories cannot be listed. The advisory describes file access, not code execution. Cloud is patched; Atlassian found no exploitation evidence. Inventory installations; use the fix matrix. Patch precisely Until patched, restrict internet access or use the all-product WAF/proxy rule. Tomcat RewriteValve covers only Confluence, Jira Service Management, Jira Software, Bamboo and Crowd. Bitbucket uses urlrewrite.xml; Crucible and Fisheye use the all-product option.

Salesforce MCE User Domain Change Affects Some New Senders
A 4 October change narrows sender verification. Salesforce's Marketing Cloud Engagement User Domain notice applies to organisations that created User Domains since 1 February 2026 without a domain verified for their account.…
6 Oct 2026 · 1 min read
Dental Images Instruct AI
Controlled tests expose answer flips and limits. A study published 3 October 2026 embedded text in 270 dental X-rays and tested four vision-language models across 58,320 calls. In a repeat benchmark, pooled…
6 Oct 2026 · 1 min read
Fiddler Classic Could Elevate the Wrong Signed Helper
Progress's advisory fixes CVE-2026-77805, a Windows privilege-escalation flaw in Fiddler Classic before 6.0.20262.10021. Fiddler accepted an allowed publisher signature without verifying the exact helper. A low-privileged local attacker must replace a helper…
6 Oct 2026 · 1 min read
Two Jira 10.1 Products Reach Support End on 9 October
Check both products before 9 October. Atlassian's end-of-support policy lists 9 October 2026 for Jira Software 10.1 and Jira Service Management 10.1. It is a support deadline, not a service outage. Check…
6 Oct 2026 · 1 min readRevised reporting
Recently updated
South Korea orders security checks after bank attacks
South Korea warns bank customers about tailored scams.
Read articleThe FBI Confirms Its Jobs Portal Was Compromised but Not What Was Taken
FBI cyber chief says a contractor missed an issued patch. His statement does not establish the platform or data impact.
Read articleAttackers Are Already Exploiting the NetScaler Flaws Citrix Just Patched
Citrix has patched eight NetScaler vulnerabilities and confirms attackers are already exploiting two critical flaws. One unauthenticated command-execution bug affects every customer-managed deployment.
Read articleThe Identity Checks Meant to Stop Fraud May Have Created a 153-Million-Record Fraud Kit
The documents collected to stop fraud may now enable it. IDScan confirmed possible unauthorised access, while a vanished dark-web service claimed 153 million driver's licence records.
Read articleDIVD Says Its Intruder’s AI Agent Left a Trail Investigators Could Follow
An intruder's automated decisions left DIVD investigators useful clues. That does not establish how much damage was done.
Read articleGeographic context
Regional intelligence

Spain’s Election Call Puts Its NIS2 Delay Back in Focus
Spain has called a November election after the Commission documented incomplete NIS2 transposition in…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence
Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
One Encoded URL Can Hand Attackers Cisco SD-WAN Admin Access
A crafted HTTP request can give attackers administrator-level API access to Cisco Catalyst SD-WAN…
Read Cisco ↗
GitHub’s Confidential Advisory Comments Follow Repository Write Acce…
On 2 October 2026, GitHub added confidential comments to repository security advisories. Reporters and…
Read GitHub ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
FortiMail Operators Face Active Exploitation While Fixes Remain Upcoming
FortiMail faces active exploitation. CVE-2026-104286 allows unauthenticated arbitrary-file writes through crafted HTTP or HTTPS…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




