Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

RedFlick Gives Star Blizzard a Shorter Route From Phishing to Persistence
Star Blizzard’s RedFlick campaigns turn an email reply into a path toward a protected archive. Defenders need to distinguish mail exposure from endpoint execution.
Read the article ↗Current reporting
Latest intelligence

wolfSSL 5.9.4 Puts Trust State on the Patch Checklist
wolfSSL 5.9.4 makes a simple “version updated” sign-off inadequate. Its vendor notes list 11 vulnerabilities: three High, four Medium and four Low. The release heading says 25 September; GitHub shows publication on 27 September. Exposure depends on the deployed application's build and behaviour. What does the release cover? The High group concerns trusted-peer key matching (CVE-2026-93302), multiple OCSP stapling (CVE-2026-89102) and non-default Raw Public Key support (CVE-2026-89136). Each has its own prerequisites; the first two also depend on particular API use. The OCSP case can leave a certificate in a reused context's trust store. The Medium entries cover a conditional handshake flaw (CVE-2026-93304), name constraints (CVE-2026-89133, CVE-2026-89134) and shared certificate-manager contamination (CVE-2026-89135). The Low group covers shutdown use-after-free (CVE-2026-15442), combined OCSP/CRL checks (CVE-2026-94417), small-certificate verification with a permissive date callback (CVE-2026-94418) and legacy session references (CVE-2026-94419). Several paths can retain trust state after a connection ends. Build an exposure decision around the application BlackTree analysis: Start with the product owner, not a vulnerability score. Identify services and devices that ship wolfSSL, including statically linked copies. Record the linked library version, build settings and certificate-verification APIs from the actual deployed artefact. A package manifest that says “wolfSSL present” cannot tell you whether a conditional feature was compiled or used. Split the review into three questions. Does the application authenticate a remote peer with the affected TLS or DTLS path? Does its build enable the relevant feature, such as trusted-peer certificates, multi-response OCSP, Raw Public Key, combined revocation checks or legacy session…

TeamViewer Fixed a Flaw That Could Override Your Session Permissions
TeamViewer's 29 September bulletin fixes five High-severity flaws in Full Client and Host, including a remote-session permission bypass. The current corrected version is 15.82; older branches need the platform-specific legacy fixes. The…
30 Sep 2026 · 3 min read
One Encoded URL Can Hand Attackers Cisco SD-WAN Admin Access
A crafted HTTP request can give attackers administrator-level API access to Cisco Catalyst SD-WAN Manager without a login. Cisco says the flaw is already being exploited. Cisco disclosed CVE-2026-76504 on 30 September…
30 Sep 2026 · 4 min read
Two LightLLM Helper Ports Expose Code Execution on Inference Nodes
The model API is the obvious place to put authentication and network controls. Two LightLLM flaws disclosed on 29 September concern different listeners on the same inference nodes. Researchers found that an…
30 Sep 2026 · 3 min read
The VPN Server Your Firebox Trusts Could Hand It Root Commands
WatchGuard has patched 15 vulnerabilities across supported Fireware OS branches. The most serious one turns an expected trust relationship inside out: a hostile remote VPN server can send configuration that a connecting…
30 Sep 2026 · 6 min readRevised reporting
Recently updated
DIVD Says Its Intruder’s AI Agent Left a Trail Investigators Could Follow
An intruder's automated decisions left DIVD investigators useful clues. That does not establish how much damage was done.
Read articlePatching the Mail Server Is the First Step. Now Check Whether You Were Already Hit.
CISA has added actively exploited Zimbra CVE-2026-73570 to its KEV catalogue with a 24 August deadline. Patch to 10.1.20, then check for prior compromise.
Read articleBitget’s $388 Million Breach Now Points to a Third-Party Security Product
Bitget says its $388 million breach may have begun in a third-party security product, exposing credentials used to send fraudulent withdrawal commands.
Read articleChrome Fixed 11 Critical Flaws Before the CVE Databases Could Catch Up
Chrome 154 fixes 11 critical flaws across graphics and browser components, but teams cannot wait for downstream vulnerability databases before deploying it.
Read articleAttackers Are Already Exploiting the NetScaler Flaws Citrix Just Patched
Citrix has patched eight NetScaler vulnerabilities and confirms attackers are already exploiting two critical flaws. One unauthenticated command-execution bug affects every customer-managed deployment.
Read articleGeographic context
Regional intelligence

The EU’s New Data-Centre Labels Won’t Tell You the Whole Energy Story
The EU plans public energy and water grades for individual data centres from 2027.…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence
Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
One Encoded URL Can Hand Attackers Cisco SD-WAN Admin Access
A crafted HTTP request can give attackers administrator-level API access to Cisco Catalyst SD-WAN…
Read Cisco ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
The Malicious npm Release Had Valid Provenance Because the Build System Wo…
The poisoned package was not smuggled around the build system. GitHub Actions built it,…
Read GitHub ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




