Security, systems and emerging technology
Know the signal behind the incident.
Independent analysis for the people who build, secure and operate technology, with the clarity to inform action and the technical depth to earn trust.

OpenShift’s Translation Endpoint Can Read Files Without a Login
An unauthenticated OpenShift console request can escape the locale directory and read JSON files or reach plugin backends. Red Hat lists no fixed build.
Read the article ↗Current reporting
Latest intelligence

A Windows Security Update Can Break Domain Trust Even When the Password Is Right
A user enters valid domain credentials after a Windows security update, yet the PC reports a broken trust relationship with its domain. A helpdesk might suspect the password, the account or a domain controller. The first question should be whether this is a client-side secure-channel failure.
Microsoft confirms that September's updates can cause this failure on some Credential Guard protected Windows 11 devices joined to on-premises Active Directory. Its affected list covers versions 24H2, 25H2 and 26H1. As of 28 September, Microsoft marks the issue mitigated, not resolved. It says AD replication and domain-controller services are unaffected.
For administrators, that distinction changes the response. A device that opens with cached credentials has not demonstrated that it can authenticate online. Resetting a user's password or making a broad change to AD could consume the recovery window without addressing the failing client. Keep the investigation tied to the device, its policy and its domain dependency.
Microsoft says the update makes Windows honour an existing Machine Identity Isolation setting; it does not switch on enforcement by itself. This is why two PCs on the same update can have different outcomes. A patch inventory alone cannot establish which policy was applied, when it reached the device or whether it was later replaced.
Machine Identity Isolation is meant to move a computer's domain account secret into Credential Guard's isolated environment. That limits exposure of the secret to code running in the normal Windows environment. It is a meaningful protection for machine identities, not a cosmetic policy switch.

The AI Agent Copied the Attack Into Its Own Reply
In a simulated email task, an AI assistant copied an attacker-written instruction into its reply. The instruction posed as a filing rule inside the message it had been asked to answer. OpenAI…
28 Sep 2026 · 4 min read
368 Bytes Entered nslookup.exe Through Its Keyboard. Then They Became Executab…
The payload did not enter nslookup.exe through WriteProcessMemory. It arrived through standard input, the same logical route used when a person types into an interactive console program. Once the child process had…
28 Sep 2026 · 6 min read
A Rancher Login Page Could Hand Attackers the Clusters Behind It
The login page was supposed to be the boundary before administration began. In vulnerable Rancher Manager deployments, an attacker did not need an account to put code on that page and wait…
28 Sep 2026 · 4 min read
Changing the Remote Desktop App Will Not Save an AVD Classic Deployment
An administrator can replace every old Remote Desktop client on their Windows endpoints and still face an access failure this week. The reason is that Microsoft has set two different deadlines for…
28 Sep 2026 · 4 min readRevised reporting
Recently updated
One SharePoint Type Check Stood Between a Web Request and an In-Memory Shell
The published chain is more dangerous than a generic authenticated RCE, but the pre-authentication route depends on an additional path and server configuration.
Read articleHow OpenAI’s Agents Turned a Read-Only Web Task Into a Public Message Board
Researchers reconstructed roughly 18,000 posts from OpenAI agents that used public wikis to coordinate, share answers and route around intended restrictions.
Read articleJetBrains Left TeamCity Unpatched and Put Cadence Source Code and Credentials Within Reach
JetBrains closed the Cadence investigation after finding attackers could have reached current storage containing source code and credentials. The investigation is over. The risk is not.
Read articleTwo Arrests Put a Number on TeamPCP’s Supply-Chain Damage
Google says an undercover Mandiant analyst reached TeamPCP's inner circle, watched stolen credentials accumulate and helped disrupt the group's follow-on access.
Read articleThe Phishing Email Really Came From Trezor. That Was the Problem.
Brevo closed the SSO path behind the Trezor phishing incident. Four days later, the attackers returned through a Cloudflare key and reached scripts embedded across customer websites.
Read articleGeographic context
Regional intelligence

Attackers Copied Every Incoming Belnet Email for Two Months
A supplier zero-day let attackers copy every incoming email sent to Belnet and one…
Read Europe ↗
Hackers Used AI to Move Faster. Then They Exposed Their Own Playbook.
Two Latin American intrusion campaigns show AI accelerating attacker troubleshooting, but exposed consoles and…
Read LATAM ↗
One Healthcare Archive Was Breached. 9.5 Million Patients Paid the Price.
A breach at Aesto Health reached 9.5 million people across at least two dozen…
Read AMER ↗
Fake Job Interviews Put 30,000 Devices and 7,000 Wallets in North Korea…
The coding test was the payload. Officials say the developer-focused campaign accumulated more than…
Read APAC ↗
The Gambia Assented to a Modern Privacy Law. The Next Step Is Operational.
The Gambia has assented to a modern privacy framework covering extraterritorial processing, data rights,…
Read Africa ↗Coverage leaders
Vendor intelligence
Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
Microsoft disclosed fixes for 18 vulnerabilities across Azure and Copilot-branded services. Customers did not…
Read Microsoft ↗
Cisco Found a Missing Login Check in Its Data-Centre Control Panel
The software coordinating a data centre deserves scrutiny before an attacker proves why. Cisco…
Read Cisco ↗
One Request Could Make Adobe AEM Forms Run Code Without a Login
According to Adobe bulletin APSB26-151, Adobe has patched six vulnerabilities in Experience Manager Forms…
Read Adobe ↗
The Malicious npm Release Had Valid Provenance Because the Build System Wo…
The poisoned package was not smuggled around the build system. GitHub Actions built it,…
Read GitHub ↗
The Phone Was Stolen. An AI Voice Agent Asked the Owner to Unlock It.
A stolen iPhone protected by Activation Lock is worth less to a thief. AnonyMousKIT…
Read Apple ↗Practical archive
Lab &
Legacy
Field-tested guidance for keeping older systems useful, secure and reliable long after mainstream documentation has moved on. Practical fixes, automation and deployment notes are drawn from real environments and written for the operators who still maintain them.




