Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

Denmark CPR Breach Misused Company Access
Company access exposed data on about 8.8 million registered people.
Read the article ↗Current reporting
Latest intelligence

South Korea orders security checks after bank attacks
South Korea's Financial Services Commission says a 30 September Shinhan Bank information leak was followed by further attacks at KB Kookmin Bank and other financial firms. It opened on-site investigations, shared threat information with KISA and convened an emergency meeting on 2 October. Check exposed systems now Financial firms must inspect every internet-accessible system, remove unnecessary exposure and review authentication and access controls. They should share attack indicators and report internal-check results. Defenders should validate inventories and access paths, then preserve evidence for regulators. This is editorial guidance. The notice does not identify an actor, establish AI use, give customer counts or set a deadline. Source: FSC notice, 2 October 2026.

DigitalOcean VPC operations recovered while connectivity stayed up
DigitalOcean says a global VPC management disruption began at about 08:48 UTC on 5 October. Creating or deleting VPC peerings, VPC Native DOKS clusters and Private Network Connections could be delayed or…
5 Oct 2026 · 1 min read
GitHub plans macOS 14 runner brownout for 5 October
GitHub says hosted Actions jobs using macos-14, macos-14-large or macos-14-xlarge will temporarily fail from 5 October 14:00 UTC to 6 October 00:00 UTC. Its 1 October notice sets image retirement for 2…
5 Oct 2026 · 1 min read
Confluence 9.1 Support Ended on 3 October
Atlassian lists 3 October 2026 as the end-of-support date for Confluence Data Center 9.1. Its support policy, last modified 22 September, says it does not support releases after their end-of-support date. The…
5 Oct 2026 · 1 min read
GitHub App Tokens Grew. Check the Whole Path.
GitHub's 2 October notice says its stateless installation-token rollout is complete. New eligible ghs_ tokens vary around 520 characters, up from 40. Permissions, repository scope, one-hour expiry and the issuance endpoint are…
4 Oct 2026 · 1 min readRevised reporting
Recently updated
Attackers Are Already Exploiting the NetScaler Flaws Citrix Just Patched
Citrix has patched eight NetScaler vulnerabilities and confirms attackers are already exploiting two critical flaws. One unauthenticated command-execution bug affects every customer-managed deployment.
Read articleThe Identity Checks Meant to Stop Fraud May Have Created a 153-Million-Record Fraud Kit
The documents collected to stop fraud may now enable it. IDScan confirmed possible unauthorised access, while a vanished dark-web service claimed 153 million driver's licence records.
Read articleDIVD Says Its Intruder’s AI Agent Left a Trail Investigators Could Follow
An intruder's automated decisions left DIVD investigators useful clues. That does not establish how much damage was done.
Read articlePatching the Mail Server Is the First Step. Now Check Whether You Were Already Hit.
CISA has added actively exploited Zimbra CVE-2026-73570 to its KEV catalogue with a 24 August deadline. Patch to 10.1.20, then check for prior compromise.
Read articleBitget’s $388 Million Breach Now Points to a Third-Party Security Product
Bitget says its $388 million breach may have begun in a third-party security product, exposing credentials used to send fraudulent withdrawal commands.
Read articleGeographic context
Regional intelligence

The EU’s New Data-Centre Labels Won’t Tell You the Whole Energy Story
The EU plans public energy and water grades for individual data centres from 2027.…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence
Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
One Encoded URL Can Hand Attackers Cisco SD-WAN Admin Access
A crafted HTTP request can give attackers administrator-level API access to Cisco Catalyst SD-WAN…
Read Cisco ↗
GitHub’s Confidential Advisory Comments Follow Repository Write Acce…
On 2 October 2026, GitHub added confidential comments to repository security advisories. Reporters and…
Read GitHub ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
FortiMail Operators Face Active Exploitation While Fixes Remain Upcoming
FortiMail faces active exploitation. CVE-2026-104286 allows unauthenticated arbitrary-file writes through crafted HTTP or HTTPS…
Read Fortinet ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




