Threats and Incidents OWAReaper survived password resets through OWA persistence
TA488 exploits CVE-2026-42897 and OWAReaper for durable mailbox access. We analyse half-click delivery, OAuth, localStorage and response.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Threats and Incidents TA488 exploits CVE-2026-42897 and OWAReaper for durable mailbox access. We analyse half-click delivery, OAuth, localStorage and response.
Threats and Incidents SilverFox combined three vulnerable drivers, DLL side-loading and dual watchdogs to sustain ValleyRAT. We analyse the chain and detection.
Human Security A campaign cloned Russian corporate websites to steal B2B advance payments. Learn its tradecraft, warning signs and payment controls.
Vulnerabilities and CVEs Public CVE-2026-10702 analysis explains a SpiderMonkey JIT flaw and Firefox-to-kernel chain. Review scope, patches and defensive priorities.
Threats and Incidents Researchers found Flying Eagle Android RAT infrastructure fingerprints on 170 servers. We analyse scope, capabilities, detection and response.
Vulnerabilities and CVEs Gitea before 1.27.1 let repository writers create a live Git hook and execute server commands. Review preconditions, impact and remediation.
Supply Chain Security Two Joyfill prereleases contained a RAT loaded on module import. We explain the blockchain C2 resolver, exposure evidence and response plan.
Threats and Incidents A real LinkedIn recruitment incident led to a DMG, LaunchAgent and in-memory JXA. We explain the chain, impact, detection and response.
Penetration Testing and AppSec MOL Move field-level authorization flaws allowed role, email and loyalty data changes. We examine the facts, root cause and disclosure failure.
Vulnerabilities and CVEs VMSA-2026-0006 fixes VM escape CVE-2026-47876 and two critical vCenter flaws. Review versions, priorities, detection and rollout.
Vulnerabilities and CVEs A critical Fastjson 1.x flaw enables remote code execution even with AutoType disabled. Learn the attack conditions, SafeMode mitigation and response plan.
AI Security Grafana has made gcx and its MCP server generally available, giving coding agents structured access to metrics, logs, alerts and dashboards.
Threats and Incidents A coordinated cyberattack reached technology at more than 30 Minnesota water systems. We separate confirmed impact from speculation and outline OT/SCADA priorities.
Threats and Incidents Kaspersky uncovered new Mirage Kitten tools: the NightLedger backdoor and ArcBridge and BridgeHead tunnelers. We analyse the techniques and detection.
AI Security Alibaba Cloud unveiled Agent Native Cloud — sandboxes, workload isolation and identity for agents. What it means for securing agentic deployments.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.