Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

A Sylius Customer Login Could Open the Admin API
In vulnerable Sylius shops, one reused email address can turn a customer token into administrator access while a separate flaw can mark an enlarged order paid.
Read the article ↗Current reporting
Latest intelligence

Attackers Are Already Exploiting the NetScaler Flaws Citrix Just Patched
Citrix has released fixes for eight vulnerabilities in NetScaler ADC and NetScaler Gateway, and says attackers are already exploiting two of them on unmitigated systems. This is not a routine patch bundle. One of the exploited flaws gives an unauthenticated attacker a path to arbitrary command execution across every customer-managed deployment, including default configurations.
The critical issue is CVE-2026-88771, an improper input-validation vulnerability with a CVSS v4 score of 9.5. Citrix says no optional feature needs to be enabled. If the appliance is running an affected build, the precondition is met.
Citrix has also observed exploitation of CVE-2026-88772, another CVSS 9.5 flaw. It is a memory-overflow vulnerability that can lead to remote code execution or denial of service when DTLS is enabled. DTLS is enabled by default on VPN virtual servers unless administrators explicitly turn it off.
Citrix's CTX697096 security bulletin states plainly that exploits of CVE-2026-88771 and CVE-2026-88772 have been observed on unmitigated deployments. It does not identify an actor, campaign, victim count, exploitation start date or indicators of compromise.
That absence of public detail must not be mistaken for an absence of risk. Patching closes the known vulnerable paths, but it cannot prove that an internet-facing appliance was clean before the upgrade. Organisations with exposed NetScaler gateways should run the upgrade and compromise assessment as parallel workstreams.
The urgency is amplified by where these products sit. NetScaler Gateway controls remote access and often fronts authentication, VPN and application traffic. An unauthenticated command-execution path at that boundary…

A Wrong Password Could Run Code Inside hMailServer
A wrong password can become code before the login succeeds. Progressive Robot’s hMailServer 6.3.4 release on 27 September fixes that risk in its Windows 6.x project. The issue should not be generalised…
27 Sep 2026 · 2 min read
When Election Certification Gets in the Way of a Security Patch
Certification is supposed to establish trust in election technology. CISA now warns that the same process can make a security update harder to release and slower to install. The agency's new 2026…
27 Sep 2026 · 4 min read
A Botnet Seller Is Offering to Drain Your AI Budget
Qrator Research Labs has examined an advertised Windows botnet called x47.c whose seller offers an AI API drain mode. It requires the operator to supply a valid account key and sends billable…
27 Sep 2026 · 3 min read
Even Protected Files Can Give Away What You Are Doing
Researchers at Graz University of Technology show that filesystem notifications can reveal user activity even when a process cannot read the underlying file. Their ACM CCS 2026 paper covers Linux, Windows, macOS…
27 Sep 2026 · 3 min readRevised reporting
Recently updated
How OpenAI’s Agents Turned a Read-Only Web Task Into a Public Message Board
Researchers reconstructed roughly 18,000 posts from OpenAI agents that used public wikis to coordinate, share answers and route around intended restrictions.
Read articleJetBrains Left TeamCity Unpatched and Put Cadence Source Code and Credentials Within Reach
JetBrains closed the Cadence investigation after finding attackers could have reached current storage containing source code and credentials. The investigation is over. The risk is not.
Read articleTwo Arrests Put a Number on TeamPCP’s Supply-Chain Damage
Google says an undercover Mandiant analyst reached TeamPCP's inner circle, watched stolen credentials accumulate and helped disrupt the group's follow-on access.
Read articleThe Phishing Email Really Came From Trezor. That Was the Problem.
Brevo closed the SSO path behind the Trezor phishing incident. Four days later, the attackers returned through a Cloudflare key and reached scripts embedded across customer websites.
Read articleThe Rust Crates Were Removed in Under Two Hours. The Build Hosts Still Need Incident Response.
The malicious crates and the new video-call campaign are separate incidents. They meet at the same target: the people and credentials trusted to publish Rust packages.
Read articleGeographic context
Regional intelligence

Attackers Copied Every Incoming Belnet Email for Two Months
A supplier zero-day let attackers copy every incoming email sent to Belnet and one…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence
Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
Cisco Found a Missing Login Check in Its Data-Centre Control Panel
The software coordinating a data centre deserves scrutiny before an attacker proves why. Cisco…
Read Cisco ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
The Malicious npm Release Had Valid Provenance Because the Build System Wo…
The poisoned package was not smuggled around the build system. GitHub Actions built it,…
Read GitHub ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




