Secretus logoSecretus

Blog

Current cybersecurity news, vulnerability analysis, EU cyber policy, practical cryptography, and secure secret sharing — without the noise.

Siemens Flags S7-1200 PLCs in the CISA Critical-Infrastructure Campaign

Siemens updated its security advisory on 28 July 2026 to identify S7-1200 PLCs in the CISA-tracked targeting campaign. What OT teams should verify without disrupting operations.

·5 min read·news, ot-security, industrial-control-systems, siemens, plc, critical-infrastructure, cisa

EU Publishes Practical Cyber Resilience Act Guidance for Software Makers

The European Commission published Cyber Resilience Act guidance on 27 July 2026, covering scope, support periods, substantial modifications, reporting and risk assessment.

·6 min read·news, eu-policy, cyber-resilience-act, product-security, software-security, compliance, open-source

Node.js Flags High-Severity Fixes for 22.x, 24.x and 26.x

Node.js scheduled security releases for 27 July 2026 across its supported release lines, with HIGH as the top severity. A practical patching checklist for teams running Node in production.

·5 min read·news, nodejs, vulnerability-management, patch-management, software-supply-chain, devsecops

ENISA’s New Strategy Sets Seven Objectives for a Cyber-Secure Europe

ENISA published its new strategy on 26 July 2026, setting seven objectives for EU cyber policy, resilience and capacity. What it signals for European organisations.

·5 min read·news, eu-policy, enisa, nis2, cyber-resilience, governance

FakeGit Turns AI Skill Discovery into a Malware Supply Chain

The FakeGit campaign used thousands of malicious GitHub repositories, including fake AI skills and MCP servers, to distribute SmartLoader malware. How to safely govern agent capabilities.

·6 min read·news, ai-security, mcp, software-supply-chain, github, malware, agent-security

EU Cyber Sanctions Now Target the Ecosystem Behind Attacks

The EU's July 2026 cyber sanctions target nine people and four entities linked to Russia's malicious cyber ecosystem. What cyber diplomacy can—and cannot—do for defenders.

·6 min read·news, eu-policy, cyber-diplomacy, sanctions, threat-intelligence, critical-infrastructure

Check Point SmartConsole Under Active Exploitation: Lock Down the Management Plane

Check Point's July 2026 advisory covers CVE-2026-16232, an actively exploited SmartConsole authentication bypass. The immediate containment and recovery steps for security teams.

·7 min read·news, checkpoint, smartconsole, cve-2026-16232, active-exploitation, management-plane, vulnerability-management

Romania's ANCPI Outage: Cyber Resilience Is a Public Service

The cyberattack affecting Romania's land-registry agency, ANCPI, shows why continuity planning, transparent communication and recovery controls matter for public digital services.

·7 min read·news, romania, ancpi, dnsc, ransomware, public-sector, resilience, incident-response

The EU's Cybersecurity Package: CSA2, NIS2 and a Stronger ENISA

The EU's 2026 cybersecurity package revises the Cybersecurity Act, amends NIS2, and turns ENISA operational — plus a 7 July AI-and-cybersecurity action plan. What actually changed.

·8 min read·news, eu-policy, nis2, cyber-resilience-act, enisa, cybersecurity-act, ai-security

Romania's NIS2 Regime: DNSC, Deadlines and Fines

Romania transposed NIS2 via GEO 155/2024. DNSC registration, the 2025 orders, the 2026 voluntary-compliance window, and fines up to €10M or 2% of turnover — what entities must do.

·7 min read·news, romania, nis2, dnsc, eu-policy, compliance

OpenAI's Hugging Face Incident Explained

OpenAI's cyber evaluation escaped its sandbox and reached Hugging Face. What is confirmed, what remains unknown, and how AI teams should respond.

·9 min read·news, openai, hugging-face, ai-security, model-evaluation, sandboxing

CISA KEV: WordPress, Langflow and DD-WRT

CISA added exploited WordPress, Langflow and DD-WRT flaws to KEV on July 21. See fixed versions, deadlines, and a practical response plan.

·8 min read·news, cisa-kev, wordpress, langflow, dd-wrt, active-exploitation

Critical IxChariot RCE: CVE-2026-49435

Keysight warns CVE-2026-49435 may enable remote code execution across IxChariot, Hawkeye and network probes. Check affected and fixed versions.

·7 min read·news, keysight, ixchariot, cve-2026-49435, network-security

Tenable Security Center gets critical SC202607.1 patch

Tenable released critical patch SC202607.1 for Security Center 6.6–6.8. See the exact supported targets, dependency changes, and rollout checks.

·7 min read·news, tenable, vulnerability-management, patch-management

Firefox 153 fixes sandbox escapes and memory flaws

Firefox 153 and new ESR builds landed July 21 with high-impact sandbox, same-origin, WebAssembly, JIT, WebRTC, and memory-safety fixes.

·8 min read·news, firefox, browser-security, patch-management

Oracle July 2026 CPU: 1,455 security patches

Oracle's July 2026 CPU lists 1,455 security patches. See which product families carry unauthenticated remote risk and how to prioritize rollout.

·8 min read·news, vulnerabilities, patch-management

ServiceNow CVE-2026-6875 attacks reported

ServiceNow CVE-2026-6875 exploitation is reported. Patch affected instances, hunt beyond the public PoC, and rotate exposed integration secrets.

·8 min read·news, vulnerabilities, incident-response

EU Cyber Resilience Act: SMEs face the September deadline

ENISA finds a gap between CRA awareness and readiness. Here is what software and hardware makers need before reporting duties begin on 11 September 2026.

·8 min read·news, eu-policy, compliance

FortiSandbox exploited: CVE-2026-25089 and CVE-2026-39808

CISA says attackers are exploiting two unauthenticated FortiSandbox command-injection flaws. Patch, isolate, preserve evidence, and rotate exposed credentials.

·7 min read·news, vulnerabilities, incident-response

SharePoint CVE-2026-58644: active exploitation turns patching into incident response

CISA added a SharePoint deserialization flaw to its Known Exploited Vulnerabilities catalog on July 16. For internet-facing on-premises servers, the right response is patch, hunt, and rotate — not patch and forget.

·7 min read·news, vulnerabilities, incident-response

ENISA's frontier-AI warning: the attacker's speed is becoming the vulnerability

ENISA's July 2026 analysis says AI is compressing the path from discovery to weaponisation and forcing defenders to rethink disclosure, software supply chains, patching, and incident response.

·7 min read·news, ai-security, europe

EY's breach came through a help-desk ticket system — the archive nobody guards

Ernst & Young is notifying clients after attackers spent two weeks inside a third-party IT ticketing platform whose support tickets routinely carried tax documents as attachments. The lesson isn't about EY — it's about what quietly accumulates in every ticketing system.

·6 min read·news, breaches, credentials

wp2shell: WordPress force-updates the web over a pre-auth RCE in core

A REST-API route confusion chained with a SQL injection gives anonymous attackers code execution on default WordPress installs — no plugins needed. WordPress shipped 6.9.5/7.0.2 on July 17 and switched on forced auto-updates. Patch now, before the public details become a working exploit.

·6 min read·news, threats, engineering

How one-time secret links actually work: the URL fragment trick, explained

The entire security model of a one-time secret link hangs on one old browser rule: everything after the # in a URL never leaves your device. Here's how that becomes a link the server that hosts it cannot read — and what the model does and doesn't protect against.

·6 min read·encryption, engineering, explainers

The five places secrets go to leak: .env files, CI logs, chat, tickets, and code

Almost every credential breach starts in one of five mundane places. A field guide to where secrets actually escape from — with the accumulation mechanics behind each one, and the habits that keep them empty.

·7 min read·credentials, engineering, explainers

£29 million and 27,000 in-person password resets: the TfL hack's bill came due

Two Scattered Spider members were sentenced on July 16 for the 2024 Transport for London attack. The intrusion chain was pure credential work — bought logins, a 2FA reset, one persuaded help desk — and the recovery bill shows what re-establishing trust in credentials at scale really costs.

·7 min read·news, breaches, credentials

Stolen TOTP seeds and a CVSS 10: the week your MFA became the loot

SonicWall SMA1000 zero-days are being exploited to steal credentials, session databases — and TOTP seed configurations, the secrets your MFA is made of. Add a 9.8 in Zoom, a record 570-flaw Patch Tuesday, and actively exploited SharePoint bugs: July's perimeter fire drill, and what it says about where secrets live.

·6 min read·news, threats, credentials

This week in security: Turla hits Romania, 35 GB walks out of Accenture, and 12 million KDDI logins

A regional tour of the week of July 8–15, 2026: Russia's FSB-linked Turla targeting Romania and the EU, the D1R ransomware campaign against Arm and Bosch, Accenture's alleged 35 GB source-code theft, and Japan's biggest telecom breach of the year.

·8 min read·news, breaches, threats

The Accenture claim: when the loot is 35 GB of source code — and the keys inside it

An attacker claims 35 GB of Accenture source code, SSH keys, and Azure tokens. Whatever the final numbers turn out to be, it's the perfect case study in why a code leak is really a credential leak — and what to do about the keys living in your own repos.

·7 min read·breaches, credentials, engineering

The biggest hacks and breaches of 2025–2026

Nation-state telecom espionage, SaaS supply-chain token theft, help-desk social engineering, and record-breaking extortion. A field guide to the landmark cyber incidents of 2025 and early 2026 — and the common thread running through them.

·9 min read·news, breaches, threats

What's new in Secretus: Teams, annual plans, and self-serve checkout

A product update: share one Business plan across your team via single-use invite links, pay yearly for two months free, and upgrade instantly with self-serve checkout — no more emailing sales.

·4 min read·product-update, teams, billing

The credential-leak playbook: how attackers find secrets in Slack and email

Post-breach, the first move is often a search box. Here's how leaked passwords, API keys and tokens actually get discovered in chat and inboxes — and the workflow that removes them from the archive entirely.

·6 min read·threats, credentials, practical

Post-quantum migration in 2026: what NIST, Apple, and Chrome already shipped

Post-quantum cryptography stopped being a research topic and started being deployed code. A field guide to what's already live in browsers and messengers — and why long-lived secrets can't wait for the timeline.

·6 min read·post-quantum, ML-KEM, news

Shamir's Secret Sharing, explained without the math degree

How a 1979 algorithm lets a team hold a secret that no single member can read — and why fewer than k shares reveal mathematically nothing. With practical k-of-n setups for real teams.

·7 min read·cryptography, shamir, teams

Harvest now, decrypt later: the attack that's already happening

Encrypted traffic recorded today can be decrypted once quantum computers mature. What HNDL means for secrets with long lifetimes, what ML-KEM-768 changes, and how hybrid key agreement works.

·6 min read·post-quantum, ML-KEM, threat-model

How to share credentials with clients (without leaking them)

Email and Slack keep credentials forever, in plaintext, on servers you don't control. A practical guide for agencies, freelancers and consultants: one-time links, P2P transfer, and a checklist.

·6 min read·practical, credentials, agencies