Blog
Current cybersecurity news, vulnerability analysis, EU cyber policy, practical cryptography, and secure secret sharing — without the noise.
Siemens Flags S7-1200 PLCs in the CISA Critical-Infrastructure Campaign
Siemens updated its security advisory on 28 July 2026 to identify S7-1200 PLCs in the CISA-tracked targeting campaign. What OT teams should verify without disrupting operations.
EU Publishes Practical Cyber Resilience Act Guidance for Software Makers
The European Commission published Cyber Resilience Act guidance on 27 July 2026, covering scope, support periods, substantial modifications, reporting and risk assessment.
Node.js Flags High-Severity Fixes for 22.x, 24.x and 26.x
Node.js scheduled security releases for 27 July 2026 across its supported release lines, with HIGH as the top severity. A practical patching checklist for teams running Node in production.
ENISA’s New Strategy Sets Seven Objectives for a Cyber-Secure Europe
ENISA published its new strategy on 26 July 2026, setting seven objectives for EU cyber policy, resilience and capacity. What it signals for European organisations.
FakeGit Turns AI Skill Discovery into a Malware Supply Chain
The FakeGit campaign used thousands of malicious GitHub repositories, including fake AI skills and MCP servers, to distribute SmartLoader malware. How to safely govern agent capabilities.
EU Cyber Sanctions Now Target the Ecosystem Behind Attacks
The EU's July 2026 cyber sanctions target nine people and four entities linked to Russia's malicious cyber ecosystem. What cyber diplomacy can—and cannot—do for defenders.
Check Point SmartConsole Under Active Exploitation: Lock Down the Management Plane
Check Point's July 2026 advisory covers CVE-2026-16232, an actively exploited SmartConsole authentication bypass. The immediate containment and recovery steps for security teams.
Romania's ANCPI Outage: Cyber Resilience Is a Public Service
The cyberattack affecting Romania's land-registry agency, ANCPI, shows why continuity planning, transparent communication and recovery controls matter for public digital services.
The EU's Cybersecurity Package: CSA2, NIS2 and a Stronger ENISA
The EU's 2026 cybersecurity package revises the Cybersecurity Act, amends NIS2, and turns ENISA operational — plus a 7 July AI-and-cybersecurity action plan. What actually changed.
Romania's NIS2 Regime: DNSC, Deadlines and Fines
Romania transposed NIS2 via GEO 155/2024. DNSC registration, the 2025 orders, the 2026 voluntary-compliance window, and fines up to €10M or 2% of turnover — what entities must do.
OpenAI's Hugging Face Incident Explained
OpenAI's cyber evaluation escaped its sandbox and reached Hugging Face. What is confirmed, what remains unknown, and how AI teams should respond.
CISA KEV: WordPress, Langflow and DD-WRT
CISA added exploited WordPress, Langflow and DD-WRT flaws to KEV on July 21. See fixed versions, deadlines, and a practical response plan.
Critical IxChariot RCE: CVE-2026-49435
Keysight warns CVE-2026-49435 may enable remote code execution across IxChariot, Hawkeye and network probes. Check affected and fixed versions.
Tenable Security Center gets critical SC202607.1 patch
Tenable released critical patch SC202607.1 for Security Center 6.6–6.8. See the exact supported targets, dependency changes, and rollout checks.
Firefox 153 fixes sandbox escapes and memory flaws
Firefox 153 and new ESR builds landed July 21 with high-impact sandbox, same-origin, WebAssembly, JIT, WebRTC, and memory-safety fixes.
Oracle July 2026 CPU: 1,455 security patches
Oracle's July 2026 CPU lists 1,455 security patches. See which product families carry unauthenticated remote risk and how to prioritize rollout.
ServiceNow CVE-2026-6875 attacks reported
ServiceNow CVE-2026-6875 exploitation is reported. Patch affected instances, hunt beyond the public PoC, and rotate exposed integration secrets.
EU Cyber Resilience Act: SMEs face the September deadline
ENISA finds a gap between CRA awareness and readiness. Here is what software and hardware makers need before reporting duties begin on 11 September 2026.
FortiSandbox exploited: CVE-2026-25089 and CVE-2026-39808
CISA says attackers are exploiting two unauthenticated FortiSandbox command-injection flaws. Patch, isolate, preserve evidence, and rotate exposed credentials.
SharePoint CVE-2026-58644: active exploitation turns patching into incident response
CISA added a SharePoint deserialization flaw to its Known Exploited Vulnerabilities catalog on July 16. For internet-facing on-premises servers, the right response is patch, hunt, and rotate — not patch and forget.
ENISA's frontier-AI warning: the attacker's speed is becoming the vulnerability
ENISA's July 2026 analysis says AI is compressing the path from discovery to weaponisation and forcing defenders to rethink disclosure, software supply chains, patching, and incident response.
EY's breach came through a help-desk ticket system — the archive nobody guards
Ernst & Young is notifying clients after attackers spent two weeks inside a third-party IT ticketing platform whose support tickets routinely carried tax documents as attachments. The lesson isn't about EY — it's about what quietly accumulates in every ticketing system.
wp2shell: WordPress force-updates the web over a pre-auth RCE in core
A REST-API route confusion chained with a SQL injection gives anonymous attackers code execution on default WordPress installs — no plugins needed. WordPress shipped 6.9.5/7.0.2 on July 17 and switched on forced auto-updates. Patch now, before the public details become a working exploit.
How one-time secret links actually work: the URL fragment trick, explained
The entire security model of a one-time secret link hangs on one old browser rule: everything after the # in a URL never leaves your device. Here's how that becomes a link the server that hosts it cannot read — and what the model does and doesn't protect against.
The five places secrets go to leak: .env files, CI logs, chat, tickets, and code
Almost every credential breach starts in one of five mundane places. A field guide to where secrets actually escape from — with the accumulation mechanics behind each one, and the habits that keep them empty.
£29 million and 27,000 in-person password resets: the TfL hack's bill came due
Two Scattered Spider members were sentenced on July 16 for the 2024 Transport for London attack. The intrusion chain was pure credential work — bought logins, a 2FA reset, one persuaded help desk — and the recovery bill shows what re-establishing trust in credentials at scale really costs.
Stolen TOTP seeds and a CVSS 10: the week your MFA became the loot
SonicWall SMA1000 zero-days are being exploited to steal credentials, session databases — and TOTP seed configurations, the secrets your MFA is made of. Add a 9.8 in Zoom, a record 570-flaw Patch Tuesday, and actively exploited SharePoint bugs: July's perimeter fire drill, and what it says about where secrets live.
This week in security: Turla hits Romania, 35 GB walks out of Accenture, and 12 million KDDI logins
A regional tour of the week of July 8–15, 2026: Russia's FSB-linked Turla targeting Romania and the EU, the D1R ransomware campaign against Arm and Bosch, Accenture's alleged 35 GB source-code theft, and Japan's biggest telecom breach of the year.
The Accenture claim: when the loot is 35 GB of source code — and the keys inside it
An attacker claims 35 GB of Accenture source code, SSH keys, and Azure tokens. Whatever the final numbers turn out to be, it's the perfect case study in why a code leak is really a credential leak — and what to do about the keys living in your own repos.
The biggest hacks and breaches of 2025–2026
Nation-state telecom espionage, SaaS supply-chain token theft, help-desk social engineering, and record-breaking extortion. A field guide to the landmark cyber incidents of 2025 and early 2026 — and the common thread running through them.
What's new in Secretus: Teams, annual plans, and self-serve checkout
A product update: share one Business plan across your team via single-use invite links, pay yearly for two months free, and upgrade instantly with self-serve checkout — no more emailing sales.
The credential-leak playbook: how attackers find secrets in Slack and email
Post-breach, the first move is often a search box. Here's how leaked passwords, API keys and tokens actually get discovered in chat and inboxes — and the workflow that removes them from the archive entirely.
Post-quantum migration in 2026: what NIST, Apple, and Chrome already shipped
Post-quantum cryptography stopped being a research topic and started being deployed code. A field guide to what's already live in browsers and messengers — and why long-lived secrets can't wait for the timeline.
Shamir's Secret Sharing, explained without the math degree
How a 1979 algorithm lets a team hold a secret that no single member can read — and why fewer than k shares reveal mathematically nothing. With practical k-of-n setups for real teams.
Harvest now, decrypt later: the attack that's already happening
Encrypted traffic recorded today can be decrypted once quantum computers mature. What HNDL means for secrets with long lifetimes, what ML-KEM-768 changes, and how hybrid key agreement works.
How to share credentials with clients (without leaking them)
Email and Slack keep credentials forever, in plaintext, on servers you don't control. A practical guide for agencies, freelancers and consultants: one-time links, P2P transfer, and a checklist.
