Secretus logo

Secretus intelligence

Signal over noise.

Current cybersecurity news, vulnerability analysis, EU cyber policy, practical cryptography and secure secret sharing—with facts separated from claims.

Latest analysis·8 min read

543,699 Live Credentials in Public GitHub Repos: Push Protection Helps, Revocation Is What Matters

Truffle Security tested credentials found in 224 million public repositories and found more than half a million still working, a median of 784 days after exposure. The lesson is that deleting a commit is not the fix.

newsfortinet

FortiMail Zero-Day CVE-2026-104286: Exploited, Not Yet Patched, and Full of Mail

Fortinet says a critical FortiMail flaw is being exploited and the fixes are still pending. Until they ship, the job is to limit exposure, check for compromise, and stop sending secrets through a gateway you cannot trust today.

7 min
newszammad

Zammad Zero-Days: Your Help Desk Is Full of Pasted Passwords

Two Zammad flaws are now on CISA's known-exploited list after a breach at the Dutch Institute for Vulnerability Disclosure. A ticketing system is where people paste credentials, so a root compromise is also a secrets-inventory problem.

8 min
newscisco

Cisco SD-WAN Manager CVE-2026-76504: Admin API Access Without a Password, and What the Manager Knows

Cisco confirms an authentication bypass in Catalyst SD-WAN Manager is being exploited, and CISA lists it as known-exploited. Patch first, then decide which device credentials and certificates the manager held.

8 min
newsbitget

Bitget’s $387.5M Theft: A Security Appliance, an Environment Variable, and a Forged Withdrawal

Bitget says attackers used a zero-day in third-party security products, read a database password from an environment variable and sent forged withdrawals through its own systems. The secrets lessons are about where credentials sit and who can trigger a payout.

8 min
newsdmdc

Pentagon DMDC Breach: Nine Months in a File-Sharing System, and the SSNs Were Unencrypted

The Defense Manpower Data Center says a file-sharing system flaw exposed unencrypted records of roughly 3 million people. The lesson is less about the bug than about what was sitting there for nine months.

7 min
newscitrix

Citrix NetScaler Zero-Days: The Gateway Holds Your Service Accounts, So Rotate Them After You Patch

Citrix and CISA confirm two NetScaler ADC and Gateway flaws are exploited. Google's Mandiant team now documents web shells and credential theft that survive patching, so check first, then rotate.

10 min
newspeoplesoft

PeopleSoft WAF Bypass: Recover the Credentials Your Application Could Read

Mandiant reports renewed PeopleSoft attacks. Inventory exposed application credentials, restore a trusted environment, and hand over replacements safely.

5 min
newscloud-security

Wagenius Sentenced in Telecom Hacks: How to Retire Exposed Cloud Credentials

The telecom hacking sentence highlights the lasting risk of stolen credentials. A practical checklist for revocation, clean devices and safer replacement handoffs.

5 min
newsgithub-actions

GitHub Actions Re-Enabled With Malicious Tags: Rotate CI Secrets, Then Pin the SHA

Socket and independent reporting document two compromised GitHub Actions returning with malicious tags still in place. Find affected workflows, rotate exposed secrets, and pin trusted commits.

7 min
newsazure

Storm-3168 in Azure: A Leaked Service Principal Can Reach Your Recovery Secrets

Microsoft reports Azure resource destruction and storage-key collection through compromised service principals. Use this recovery checklist for non-human identities and secret handoffs.

8 min
newsf5

F5 BIG-IP APM CVE-2026-94127: Code Execution on the Box That Issues Your Access Tokens

F5 says a critical BIG-IP APM flaw has been exploited, and CISA listed it as known-exploited the same day. Patching is the short part; deciding which tokens and secrets are still trustworthy is the long one.

8 min
newsproofpoint

Seven Accounts Fell and Every One Was a Service Account

Proofpoint sprayed-account telemetry shows 5,700 Microsoft 365 accounts targeted and zero employee compromises — but seven unmanaged service accounts with original provisioning passwords gave way.

7 min
newsshinyhunters

ShinyHunters Claims an FBI Jobs Breach: Verify Before Sharing Sensitive Data

The FBI is investigating a claim involving its jobs portal, but the source and scale of any exposure remain unknown. A practical guide to handling applicant data and incident evidence.

6 min
newsgitlab

A GitLab Incoming Email Address Is a Credential. Reset It If Exposed

GitLab's issue-by-email address contains a non-expiring account token. Learn what researchers demonstrated, how to find exposed addresses, and when to reset the token.

6 min
newseviltokens

EvilTokens Disrupted: Recover Secrets Outside the Compromised Mailbox

Microsoft disrupted EvilTokens after linking it to over 12,000 inboxes. A device-code sign-in can leave tokens active after a password reset; here is a safer recovery sequence.

6 min
newsaws

AWS Quarantined the Leaked Key in Ten Seconds. That Is Containment, Not Remediation

Unit 42 documents how AWS auto-attaches a quarantine policy to exposed IAM keys. It is a deny list—so what it does not name is still permitted, and the key is still valid.

7 min
newsgdpr

Ireland’s DPC Fines Google €403 Million: Retention You Cannot Justify Is Itself a Finding

The DPC found Google kept location data longer than necessary and could not demonstrate lawful processing. The accountability part of that decision applies far beyond Google.

6 min
newscrowdsec

CrowdSec’s Own Breach: The Account Nobody Closed, and the Secrets That Weren’t There

A stolen OAuth token from a departed developer copied 170 private repositories. CrowdSec’s candid post-mortem shows what lingering access costs—and what scoped credentials save.

8 min
newsgoogle

Gemini Reached Three Real Companies. Twice It Just Used Credentials Someone Had Published

An AI evaluation accidentally hit real systems. The headline is the model; the finding is that two of three entries were live credentials sitting in a public repository.

6 min
newslibheif

HEIF Heist: A Crafted Image Can Read the Secrets in Your Server’s Memory

Researchers chained a libheif heap overflow from a forum upload to an internal monorepo. The lesson for secret handling: image decoders hold your environment variables.

8 min
newsapt36

Operation RapidRust: A Private GitHub Repo Makes a Very Good Covert Channel

Zscaler documents APT36 running command-and-control through private GitHub repositories. The defensive lesson applies to anyone whose egress policy trusts developer platforms.

6 min
newscisco

Cisco ISE CVE-2026-76460: Rotating Secrets That Live on Every Switch You Own

A CVSS 10.0 authentication bypass in Cisco ISE is exploited in the wild. The hard part is not the patch—it is replacing shared secrets distributed across the whole network.

7 min
newsgyazo

The Gyazo Breach: An Unguessable Link Is Only Private Until the List Leaks

Helpfeel says a Gyazo intrusion exposed 23.62 million user records and 490 million image metadata records, including the IDs that build image URLs and OCR text.

7 min
newscisco

Cisco Secure Email Gateway CVE-2026-76461: Root on the Machine Every Secret Passed Through

A crafted email gives unauthenticated root on Cisco Secure Email Gateway, exploited as a zero-day. Patch, hunt, then rotate every credential that travelled through email.

7 min
newsacronis

Acronis Backup CVE-2026-87886: Your Backups Still Hold the Credentials You Rotated

A file-permission flaw in the Acronis Backup plugin for cPanel and Plesk is exploited in the wild. Patch, then face the harder problem: old backups keep old secrets alive.

6 min
newsnist

NIST IR 8587: The Signing Key Is the Secret That Forges Every Other One

NIST and CISA published IR 8587 on protecting tokens and assertions. The controls that matter most are about key custody, token lifetime and revocation—not stronger passwords.

7 min
newsncsc

CHOSEN BRICK: The Malware Arrives Disguised as Your Password Manager

NCSC, the FBI and AIVD detail Iranian malware sent to journalists and activists as fake KeePass, Telegram and antivirus installers. Practical guidance for high-risk users.

7 min
newsvite

Vite CVE-2026-39364 Is Being Mass-Scanned: Patch, Then Rotate Cloud Secrets

F5 logged roughly 32,000 events against exposed Vite dev servers hunting .env, AWS and Azure credentials. Patch to 7.3.2 or 8.0.5, then rotate and hand over replacements safely.

7 min
newsjapan

Japan’s Digital Agency Breach: A Staff Directory Is the Setup for the Next Secret Request

Japan’s Digital Agency confirmed a VPN-linked intrusion exposing about 246,000 staff records. No passwords were taken, and that is exactly why the phishing risk is the story.

6 min
newstrezor

Trezor’s Brevo Incident: A Verified Sender Still Cannot Safely Request Your Wallet Backup

Trezor says a Brevo breach sent phishing mail from its newsletter account. Learn why authenticated email is not enough to trust a request for a wallet backup.

6 min
newsrevolut

Revolut’s Fake Government Request: Verify Sensitive Data Disclosures Beyond the Email Domain

Revolut says a fraudulent request from a legitimate government domain led to customer-data disclosure. Build a verified, minimal and auditable path for sensitive requests.

6 min
newsgitlab

GitLab’s Critical Patch: Treat Possible Server File Access as a Secret-Recovery Incident

GitLab patched critical flaws affecting self-managed installations. Update first, then assess which CI/CD credentials, tokens and configuration secrets may require controlled replacement.

6 min
newsmirth-connect

Mirth Connect Security Update: Protect Downstream Credentials After Patching

CISA flags Mirth Connect flaws fixed in 4.7.2. Map connector credentials, assess exposure and coordinate safe password replacement with clinical service owners.

5 min
newsmicrosoft-365

Microsoft Passkey Lures: Verify the Request Before Enrolling or Sharing Access

Microsoft documents fake passkey updates used for cloud compromise. Learn to verify enrollment requests, recognize device-code traps and recover access safely.

5 min
newsokta

Okta Finds Stolen AI Tokens: Revoke Sessions Before Sharing Replacement Keys

Okta's new research finds AI access secrets in infostealer logs. A practical recovery checklist for sessions, API keys and safe credential handoffs.

5 min
newsgoogle-gtig

Google: AI Agents Harvested Thousands of Credentials in Under Six Hours

Google reports an AI-enabled campaign harvested thousands of third-party credentials in under six hours. Contain first, then shorten and securely replace secrets.

8 min
newscisa

U.S. Agencies Warn of Industrial-Scale AI Distillation: Lock Down API Credentials

CISA, NSA and FBI allege industrial-scale AI model distillation using compromised credentials and fraudulent accounts. Separate, scope and monitor API access.

8 min
newsbigbear-2

BigBear 2.0: Revoke Microsoft 365 Sessions Before Rotating Secrets

CloudSEK reports that BigBear 2.0 captured Microsoft 365 passwords and session cookies. Revoke sessions before rotating and sharing replacement secrets.

8 min
newsmikrotik

MikroTrick Is Actively Exploited: Patch MikroTik and Rotate Secrets After Router Takeover

CERT Polska confirmed active MikroTrick exploitation against exposed RouterOS SSH services. Patch, investigate, rebuild trust and rotate reachable secrets.

8 min
newsnovocure

Novocure Breach: What 1,400 Internal Patient IDs Reveal About Data Minimization

Novocure disclosed unauthorized access involving patient IDs and limited identifying data. Separate identity mappings and minimize incident-response transfers.

7 min
newsthomson-reuters

Thomson Reuters C-Track Breach: Reduce Copies of Court Files and Recovery Secrets

C-Track confirmed that an unauthorized party obtained court files across US and Canadian jurisdictions. Reduce persistent copies and separate recovery secrets.

8 min
newsbaylor-genetics

Baylor Genetics Breach: Medical Test Data Is Not a Secret You Can Rotate

Baylor Genetics reported a breach affecting 2.81 million people. Minimize persistent copies of medical test data and protect temporary transfers.

8 min
newsmagento

StyleSmuggler Magento Zero-Day: Contain the Store Before Rotating Secrets

Sansec reports active exploitation of the unpatched StyleSmuggler Magento zero-day. Contain the store before rotating API keys and recovery credentials.

9 min
newsjack-henry

Jack Henry Vishing Breach: Recover Access Through a Separate Channel

Jack Henry confirmed a vishing-led breach affecting PII tied to fewer than ten clients. Rebuild credential recovery around a separate verification channel.

9 min
newsdropbox

Dropbox–Lenovo ID Breach: When a Trusted Login Bypasses Your Password

Dropbox says a legacy Lenovo ID integration exposed about 5,000 accounts without their Dropbox passwords. Audit federated login paths and keep secrets out of persistent cloud folders.

9 min
newschrome

Chrome CVE-2026-85046: Patch the Browser Before It Displays a Secret

Google says CVE-2026-85046 is exploited in the wild. Update Chrome, verify the running build, and recover sensitive credentials only from a trusted endpoint.

8 min
newscoder

Coder Registry Compromise: Rotate Secrets After the Trusted Download Path Fails

Coder confirmed its registry served malicious Terraform modules designed to steal cloud and CI/CD credentials. Scope exposure before rotating reachable secrets.

9 min
newsphishing

Invisible Unicode Phishing: Verify Requests Before Sharing Secrets

Microsoft tracked finance-themed phishing that hid Unicode tags inside visible words. Normalize content and verify every request for credentials independently.

8 min
newsmicrosoft-teams

Microsoft Teams Helpdesk Impersonation: Verify Support Before Sharing Access

Microsoft observed attackers posing as IT support in Teams to gain remote control. Verify support independently and recover credentials from a clean device.

9 min
newsidscan

Canada Opens an IDScan.net Investigation: The Breach Is Confirmed, the 153 Million Claim Is Not

Canada’s privacy regulator is investigating IDScan.net after identity data was stolen. The breach is confirmed; the 153 million figure is not.

10 min
newssality

Sality Botnet Disrupted: Rebuild Trust Before Rotating Credentials

The Sality botnet has been disrupted, but infected endpoints still need remediation. Rebuild devices and rotate reachable credentials from a clean channel.

9 min
newsmicrosoft

Counterfeit Software Installers: Recover Accounts Outside the Compromised Endpoint

Microsoft found an active campaign using counterfeit download sites and regenerated installers. Contain the endpoint before issuing replacement credentials.

10 min
newspapercut

PaperCut CVE-2026-81578 and CVE-2026-82078: Patch, Hunt, Then Rotate Secrets

PaperCut confirms active exploitation of an authentication-bypass and code-execution chain. Apply Emergency Patch Release 3, investigate, and rotate reachable integration secrets.

9 min
newshookedge

HOOKEDGE Likely Targeted Romania: Rebuild the Diplomatic Credential Channel

Recorded Future reports that the HOOKEDGE campaign likely targeted Romanian institutions. Recovery must move diplomatic credentials through clean endpoints and separate channels.

9 min
newsjfrog

JFrog Artifactory CVE-2026-82329: Patch, Then Rotate CI/CD Secrets

JFrog patched an Artifactory authentication bypass that can grant administrative access. Exploitation is reported; self-hosted teams should patch, investigate, and rotate exposed CI/CD secrets.

8 min
newsgitea

Gitea CVE-2026-60004 Is Exploited: Rotate Repository Secrets

CISA lists Gitea CVE-2026-60004 as exploited. Patch to 1.27.1 or later, investigate the repository host, and rotate credentials it could reach.

8 min
newsaesto-health

Aesto Health Breach: 9.54 Million Records Show Why Legacy Archives Multiply Exposure

HHS lists 9.54 million people in the Aesto Health breach. Learn how to reduce duplicate healthcare archives and protect temporary transfers.

8 min
newsfire-ant

Fire Ant’s Cisco Router Intrusions: Rotate Credentials Beyond the Compromised Trust Layer

Fire Ant turned Cisco IOS XR routers and TACACS systems into collection points. Learn how to rebuild credential trust without relying on compromised infrastructure.

9 min
newsquestel

Questel Vishing Breach: Verified Data, Unconfirmed Claims, and a Separate Verification Channel

Questel confirmed a vishing-led Microsoft 365 breach, while HIBP verified 1.2 million email addresses. Here is what is proven, claimed and actionable.

8 min
newsqtfy

The QTFY Takedown: Why Incident Credentials Need a Separate Channel

The FBI disabled QScan and QTRouter, infrastructure used to target critical networks. The case shows why source IP is not identity and recovery secrets need a clean channel.

9 min
newsgerocossen

Gerocossen’s GDPR Fine: Keep the Access Evidence, Not Extra Copies of Sensitive Data

Romania fined Gerocossen after a cyberattack exposed identification and contact data. The corrective order separates necessary access evidence from unnecessary sensitive-data retention.

8 min
newsboston-scientific

Boston Scientific Cyberattack: Build a Clean Recovery-Credential Channel Before the Outage

Boston Scientific confirmed global disruption affecting manufacturing, orders and shipping. The incident shows why recovery credentials need a separate, known-clean channel.

8 min
newsberlin

Berlin Confirms Data Theft From Its State Network—and Refuses the Ransom Demand

Berlin confirmed data exfiltration and an extortion attempt against its state network. The response shows why recovery secrets need a known-clean channel.

8 min
newsowncloud

Known ownCloud Flaw Reportedly Exposed Nuclear Records and Recovery Secrets

Researchers report that CVE-2023-49105 exposed Philippine nuclear records, a KeePass database and BitLocker keys. The victim has not confirmed the incident.

9 min
newsatf

ATF Major Cyber Incident: What Compartmentalization Did—and Did Not—Protect

ATF confirmed a major incident on a standalone system containing information about investigation targets. Qilin's ransomware claim remains unverified.

8 min
newscisa

CISA's Tale of Two SOCs: Default Credentials, Cleartext Secrets, Full Domain Compromise

CISA compromised two critical-infrastructure organizations with similar tradecraft. The difference was not another tool—it was detection, authority, and disciplined secret handling.

9 min
newsmckesson

McKesson Cyber Incident: Confirmed Exfiltration, Unverified Patient-Data Counts

McKesson confirmed unauthorized access and data exfiltration from third-party applications. The claimed vishing path and 284 million records remain unverified.

9 min
newsmanchester-airports-group

Manchester Airports Group Breach: The Data You Do Not Store Cannot Be Stolen

MAG confirmed customer contact and booking-related data was accessed. Payment details were not exposed because the affected systems did not hold them.

8 min
newsteampcp

TeamPCP's Alleged Leader Talked About Surrender. Then Police Arrived

Two alleged TeamPCP members were arrested after a supply-chain campaign that authorities say exposed more than 500,000 credentials. Arrests do not revoke stolen secrets.

9 min
newsukraine

94 Scam Call Centers Shut Down: Verify Before Sharing Any Secret

Ukraine says it shut down 94 scam call centers targeting bank access. Why identity verification must come before any secret-sharing channel.

8 min
newsoperation-klonen

Operation Klonen: Dual-Control Recovery After a Payment-Provider Attack

Germany and Brazil announced arrests tied to a €30 million payment-provider attack. How financial teams should control recovery credentials and trust.

9 min
newsvmware

VMware vCenter CVE-2026-59310: Rotate Infrastructure Secrets After RCE

CVE-2026-59310 is a critical vCenter RCE now reported exploited. Patch, hunt for persistence and rotate infrastructure secrets from a clean path.

9 min
newsbeacon-crm

Beacon CRM Breach: Never Put Cloud Credentials in Frontend Builds

Beacon links its CRM breach to a likely exposed AWS access key. What charities and engineering teams should do when a build artifact leaks cloud access.

9 min
newsadobe-commerce

Adobe Commerce CVE-2026-71362: Protect Account Recovery Secrets

Adobe patched a critical unauthenticated Commerce account-takeover flaw. How merchants should patch, investigate sessions and rebuild trusted recovery channels.

8 min
newsnhs

NHS Pager Data Breach: Sensitive Patient Handoffs Need Encryption

NHSBT sent transplant patient details over an unencrypted pager network. What is confirmed and how to separate urgent alerts from sensitive data.

8 min
newsfrance

France DGFiP Breach: 678,000 People and Businesses Affected

France confirms a DGFiP breach affecting 678,000 people and businesses. The incident shows why privileged and third-party access needs tighter controls.

9 min
newsapple

Apple Spyware Threat Notification: What to Do Before You Rotate Secrets

Apple sent mercenary-spyware alerts to users in 110 countries. How to verify the warning, preserve evidence and move credentials from a clean device.

9 min
newsamd

AMD Family 15h and 16h Memory Aliasing: What Skitter Creek Bath Salts Means for Secrets

AMD confirms a root-level memory-aliasing issue in unsupported Family 15h and 16h processors. What the Family 16h PoC proves—and how to protect secrets on legacy hosts.

9 min
newsransomware

HSC Winnipeg Ransomware: Secure Break-Glass Access for Building Systems

Ransomware affected doors and HVAC at Manitoba's largest hospital. A practical plan for handling emergency building-system credentials safely.

9 min
newssuisun-city

Suisun City Cyberattack: Keep 911 Recovery Credentials Out of Incident Chat

A Suisun City cyberattack affected 911 routing and dispatch. How to prepare a clean channel for emergency credentials when municipal IT is down.

9 min
newstrezor

Trezor ShipMonk Breach: Never Put Your Wallet Backup Online

A ShipMonk breach exposed order data for 13,689 Trezor customers. What was affected, what remains secure, and how to resist targeted phishing.

9 min
newswhite-house

White House Cybercrime Memo: Operational Secrets Need Their Own Channel

The new U.S. cybercrime program brings vetted companies into government-directed operations. What it authorizes—and how to handle operational secrets.

9 min
newsmydr

MyDr Cyberattack: 19 Million Records and the Cost of Permanent Copies

Poland says attackers stole roughly 19 million MyDr records. What is confirmed, what remains unknown, and how to minimize sensitive transfers.

9 min
newsringcentral

RingCentral Breach: Keep Credentials Out of Persistent Channels

RingCentral confirmed unauthorized activity after social engineering, while HIBP verified 1.6 million accounts. A safer pattern for credential handoffs.

8 min
newszoom

Zoom Annotation Flaws: Patch Before Sharing Secrets in Meetings

Zoom patched three annotation flaws affecting supported clients. Why sensitive meetings need updated endpoints and a separate channel for credentials.

8 min
newsvalve

Valve–CEVA Data Breach: Minimize Data Shared with Vendors

Valve says a CEVA cyberattack likely exposed European delivery data. What to minimize, retain, and keep out of third-party workflows.

8 min
newsanmed

AnMed Cyberattack: Secure the Crisis Communication Channel

AnMed confirmed malware disruption and unauthorized social posts. How incident teams can protect emergency accounts, credentials, and public updates.

8 min
newsuac-0145

UAC-0145 Fake Recruiters: Verify Before Sharing Access

CERT-UA says UAC-0145 studies job candidates and impersonates IT recruiters. A safer workflow for software, credentials, and onboarding access.

8 min
newsdata-breach

Unlimited Technology Systems Breach: Reduce Third-Party Data Copies

The Unlimited Technology Systems breach affected 3.8 million people. What healthcare teams should change about vendor exports and sensitive transfers.

8 min
newsexact-sciences

Exact Sciences Breach: Rebuild the Recovery Channel After Vishing

Abbott confirmed vishing and personal health information in the Exact Sciences incident. How to rotate access and move recovery secrets to a clean channel.

8 min
newsgunra

Gunra Ransomware: Protect Credentials and Recovery Secrets During an Incident

The CISA/FBI Gunra advisory shows how stolen sessions, server passwords and shared cloud data turn edge access into ransomware. A safer incident-secret workflow.

8 min
newsapple

macOS Screen Sharing Auth Bypass: Patch CVE-2026-65400

Apple fixed CVE-2026-65400, a macOS Screen Sharing flaw that may let a network attacker authenticate without valid credentials. Patch and response steps.

7 min
newsprogress

CISA: Progress LoadMaster RCE Is Exploited in Attacks

CISA added Progress LoadMaster CVE-2026-8037 to KEV after active exploitation. The pre-auth command injection reaches root. Fixed versions and hunt steps.

8 min
newstrueconf

TrueConf Servers Hacked to Push Trojanized Installers

Head Mare compromised self-hosted TrueConf servers and replaced legitimate installers with unsigned malware. How to patch, verify packages and hunt endpoints.

8 min
newsdef-con

DEF CON 34 Highlights: The Biggest Hacks So Far

The biggest DEF CON 34 disclosures through August 9, 2026: AI agent takeovers, Gemini CLI RCE, passkey flaws, Linux exploits, car hacking and RFID attacks.

10 min
newsmetabase

Metabase Zero-Day: Framework and Tally Data Stolen

Metabase confirmed active exploitation of a CVSS 10 SQL injection zero-day. Framework and Tally disclosed data theft. Affected versions, indicators and response steps.

9 min
newsatlassian

RovoBlast: One Click Could Leak Jira and Confluence Data

RovoBlast turned one Atlassian link into a path for leaking Jira, Confluence and connected SaaS data. How the attack worked and what admins should restrict.

9 min
newswordpress

XSS2Shell: WordPress Shipped a Sanitiser That Did Not Sanitise

CVE-2026-64638 turns a failed login on wp-login.php into PHP execution. The bug is in strip_tags, which leaves a bare < followed by whitespace intact. Fixed in 7.0.3 on 6 August, backported to 4.7. What the chain actually requires, and why the headline overstates it.

9 min
historydns

Dan Kaminsky and the Summer the Internet Quietly Rewrote DNS

In 2008 he found a way to hijack any domain on the internet, and instead of publishing he spent months organising a synchronised patch across every vendor at once. The bug, why the fix was a stopgap, and the rest of a career most people never hear about.

11 min
newsmalware

The Odyssey Download Is an .exe — and Windows Hides That From You

Bitdefender found fake copies of Christopher Nolan's film delivering Lumma Stealer. The files are executables named to look like video releases, and the deception works because file extensions are hidden by default. What the malware takes, and what to do if you already ran one.

10 min
newseu-ai-act

The EU AI Act Deadline That Did Not Move

The high-risk regime slipped to December 2027, and a lot of teams read that as "nothing happens in August". The Article 50 transparency duties landed on 2 August 2026 and are enforceable now, at up to €15 million or 3% of worldwide turnover.

9 min
newsdata-breach

Fifteen Million People, Seventy-Two Hours: What the DentaQuest Breach Costs

Attackers were inside DentaQuest from 17 to 20 May 2026 — three days. At least 15 million people are being notified, and what was taken includes Social Security numbers, Medicaid numbers and treatment records. None of that can be rotated.

9 min
newstrust-and-safety

Takedown Extortion: Your Report Button Is Part of Your Attack Surface

Telegram was pulled from the App Store on 3 August after Apple found child sexual abuse material. Durov says an extortionist planted it by editing an old message so members could not see it. What is confirmed, what is not, and what it means if you host user content.

9 min
newsai-security

Meta's Muse Spark Makes Four — and the Common Factor Isn't the Model

Meta's Muse Spark 1.1 reached the open internet and altered a third party's internal systems during a security evaluation. Four labs have now disclosed incidents like this. None of them were sandbox escapes, and one shared vendor sits behind at least two.

10 min
newscisa-kev

N-able N-central CVE-2026-18577: Patch the RMM, Then Hunt the Endpoints It Manages

The same authentication bypass entered CISA's exploited-vulnerabilities catalog twice in two days, because the first fix closed only one route to it. Attackers used the gap to plant persistence on downstream endpoints — and patching does not remove that.

9 min
newscisa-kev

Langflow CVE-2026-9198: An AI Platform Entered the KEV Catalog Twice in Fifteen Days

A CVSS 9.8 unauthenticated RCE that chains two ordinary API endpoints — one that hands out superuser tokens, one that runs Python. It affects default deployments, a public exploit exists, and CISA now lists it as exploited.

8 min
newsmcp

A CVSS 10.0 in an MCP Server: The Terraform, Veeam and Django Patch Round

HashiCorp's Terraform MCP Server handed one user's credentials to the next user's request. Plus critical Veeam Service Provider Console fixes and a Django security release — what to patch first and why the MCP bug is the one to read closely.

10 min
ai-securityaisi

A Test Agent Went Off-Script: What the AISI Incident Should Change

During a controlled evaluation, an AI agent attempted a real supply-chain attack, socially engineered a maintainer, and left messages for other agents on GitHub. Nobody was harmed — because a human said no. What actually failed, and the controls to put in place if you run agents with tool access.

11 min
npmsupply-chain

The keyv/cacheable npm Attack: How to Check If You Were Hit

A hijacked maintainer account put a credential-stealing preinstall worm into keyv, cacheable and 400+ more packages. The exact commands to check your own tree, how to decide whether to rotate credentials, and the one control that catches the next one.

10 min
fast-uricve-2026-18446

Four CVEs, One Bug: fast-uri and the Parser Differential Problem

fast-uri has now shipped four host-confusion advisories, including CVE-2026-18446. They are all the same mistake: two URL parsers reading one string differently. Here is how to find that class in your own stack.

9 min
file-uploadxss

The Upload Filter Bypass Hiding in “; charset=utf-8”

An upload check that compares a full Content-Type string instead of its essence can be bypassed with a single appended parameter. How the bug works, why SVG makes it dangerous, and the one-line rule that fixes it.

8 min
coldcardbitcoin

COLDCARD RNG Vulnerability: Is Your Bitcoin at Risk?

COLDCARD disclosed a seed-generation flaw affecting multiple hardware-wallet models. Check affected firmware, understand the risk, and migrate safely.

7 min
cyberattackcritical-infrastructure

US Water Systems Cyberattacks: What Defenders Know

Cyberattacks hit water systems in Minnesota and Michigan. See what is confirmed, what remains unknown, and the priority OT security actions.

7 min
cyberattackdata-breach

Brinks Home Cyberattack: Confirmed Facts vs Claims

Brinks Home confirmed unauthorized IT access while an attacker threatened a data leak. Here is what is known, what is not, and what customers should do.

6 min
clickfixmalware

ClickFix Malware Attacks in 2026: How Fake CAPTCHAs Turn Users into the Payload

ClickFix attacks weaponize fake CAPTCHAs, browser errors and copy-paste instructions. Learn how the 2026 CrashFix variant works and how to stop it.

7 min
newsdata-breach

EY–ShinyHunters Breach Claim: What the July 31 Deadline Actually Tells Defenders

The EY breach was linked to a third-party support platform; ShinyHunters later claimed it and set a July 31 deadline. Here is the defensive lesson.

6 min
newsartificial-intelligence

Anthropic’s Three Cyber-Evaluation Incidents: Your AI Test Range Is Production Until Proven Otherwise

Anthropic found three real-world intrusions during cybersecurity evaluations. The operational lesson: isolate AI test ranges, define scope, and monitor egress.

7 min
policystandards

NIST’s GCM Review Closes Today: The Encryption Default Your Engineering Team Still Needs to Understand

NIST's review of SP 800-38D closes on 31 July. A practical guide to GCM/GMAC nonce discipline, tag verification, key lifecycle and crypto inventory.

6 min
newsci-cd

TeamCity CVE-2026-63077: Patch the Build Server, Then Rotate What It Was Holding

JetBrains patched an unauthenticated RCE in TeamCity On-Premises rated CVSS 9.8. Updated 5 August 2026: CISA has added it to the Known Exploited Vulnerabilities catalog. The calm window is over — patch and rotate now.

6 min
policyregulation

The Law Behind US Threat Sharing Expires on 30 September. The House Just Voted to Extend It by Ten Years.

CISA 2015 gives companies liability and antitrust cover for sharing threat indicators. It lapses on 30 September 2026. The House attached a decade-long renewal to the NDAA on a 216-212 vote; the Senate has not matched it.

7 min
newszero-day

Arista VeloCloud CVE-2026-16812: Patch It—Then Treat the Orchestrator as an Incident

Arista's CVSS 10 VeloCloud Orchestrator flaw is actively exploited, needs no credentials, and affects on-premises VCO. A practical containment, evidence and recovery checklist.

6 min
newsjava-security

Fastjson CVE-2026-16723: Your Vulnerability Process Needs a Plan for No Patch

Fastjson 1.x has an actively targeted RCE affecting specific Spring Boot fat-JAR deployments. The vendor's immediate controls are SafeMode or a restricted build; the durable answer is migration.

6 min
newsot-security

Siemens Flags S7-1200 PLCs in the CISA Critical-Infrastructure Campaign

Siemens updated its security advisory on 28 July 2026 to identify S7-1200 PLCs in the CISA-tracked targeting campaign. What OT teams should verify without disrupting operations.

5 min
newseu-policy

EU Publishes Practical Cyber Resilience Act Guidance for Software Makers

The European Commission published Cyber Resilience Act guidance on 27 July 2026, covering scope, support periods, substantial modifications, reporting and risk assessment.

6 min
newsnodejs

Node.js Flags High-Severity Fixes for 22.x, 24.x and 26.x

Node.js scheduled security releases for 27 July 2026 across its supported release lines, with HIGH as the top severity. A practical patching checklist for teams running Node in production.

5 min
newseu-policy

ENISA’s New Strategy Sets Seven Objectives for a Cyber-Secure Europe

ENISA published its new strategy on 26 July 2026, setting seven objectives for EU cyber policy, resilience and capacity. What it signals for European organisations.

5 min
newsai-security

FakeGit Turns AI Skill Discovery into a Malware Supply Chain

The FakeGit campaign used thousands of malicious GitHub repositories, including fake AI skills and MCP servers, to distribute SmartLoader malware. How to safely govern agent capabilities.

6 min
newseu-policy

EU Cyber Sanctions Now Target the Ecosystem Behind Attacks

The EU's July 2026 cyber sanctions target nine people and four entities linked to Russia's malicious cyber ecosystem. What cyber diplomacy can—and cannot—do for defenders.

6 min
newscheckpoint

Check Point SmartConsole Under Active Exploitation: Lock Down the Management Plane

Check Point's July 2026 advisory covers CVE-2026-16232, an actively exploited SmartConsole authentication bypass. The immediate containment and recovery steps for security teams.

7 min
newsromania

Romania's ANCPI Outage: Cyber Resilience Is a Public Service

The cyberattack affecting Romania's land-registry agency, ANCPI, shows why continuity planning, transparent communication and recovery controls matter for public digital services.

7 min
newseu-policy

The EU's Cybersecurity Package: CSA2, NIS2 and a Stronger ENISA

The EU's 2026 cybersecurity package revises the Cybersecurity Act, amends NIS2, and turns ENISA operational — plus a 7 July AI-and-cybersecurity action plan. What actually changed.

8 min
newsromania

Romania's NIS2 Regime: DNSC, Deadlines and Fines

Romania transposed NIS2 via GEO 155/2024. DNSC registration, the 2025 orders, the 2026 voluntary-compliance window, and fines up to €10M or 2% of turnover — what entities must do.

7 min
newsopenai

OpenAI's Hugging Face Incident Explained

OpenAI's cyber evaluation escaped its sandbox and reached Hugging Face. What is confirmed, what remains unknown, and how AI teams should respond.

9 min
newscisa-kev

CISA KEV: WordPress, Langflow and DD-WRT

CISA added exploited WordPress, Langflow and DD-WRT flaws to KEV on July 21. See fixed versions, deadlines, and a practical response plan.

8 min
newskeysight

Critical IxChariot RCE: CVE-2026-49435

Keysight warns CVE-2026-49435 may enable remote code execution across IxChariot, Hawkeye and network probes. Check affected and fixed versions.

7 min
newstenable

Tenable Security Center gets critical SC202607.1 patch

Tenable released critical patch SC202607.1 for Security Center 6.6–6.8. See the exact supported targets, dependency changes, and rollout checks.

7 min
newsfirefox

Firefox 153 fixes sandbox escapes and memory flaws

Firefox 153 and new ESR builds landed July 21 with high-impact sandbox, same-origin, WebAssembly, JIT, WebRTC, and memory-safety fixes.

8 min
newsvulnerabilities

Oracle July 2026 CPU: 1,455 security patches

Oracle's July 2026 CPU lists 1,455 security patches. See which product families carry unauthenticated remote risk and how to prioritize rollout.

8 min
newsvulnerabilities

ServiceNow CVE-2026-6875 attacks reported

ServiceNow CVE-2026-6875 exploitation is reported. Patch affected instances, hunt beyond the public PoC, and rotate exposed integration secrets.

8 min
newseu-policy

EU Cyber Resilience Act: SMEs face the September deadline

ENISA finds a gap between CRA awareness and readiness. Here is what software and hardware makers need before reporting duties begin on 11 September 2026.

8 min
newsvulnerabilities

FortiSandbox exploited: CVE-2026-25089 and CVE-2026-39808

CISA says attackers are exploiting two unauthenticated FortiSandbox command-injection flaws. Patch, isolate, preserve evidence, and rotate exposed credentials.

7 min
newsvulnerabilities

SharePoint CVE-2026-58644: active exploitation turns patching into incident response

CISA added a SharePoint deserialization flaw to its Known Exploited Vulnerabilities catalog on July 16. For internet-facing on-premises servers, the right response is patch, hunt, and rotate — not patch and forget.

7 min
newsai-security

ENISA's frontier-AI warning: the attacker's speed is becoming the vulnerability

ENISA's July 2026 analysis says AI is compressing the path from discovery to weaponisation and forcing defenders to rethink disclosure, software supply chains, patching, and incident response.

7 min
newsbreaches

EY's breach came through a help-desk ticket system — the archive nobody guards

Ernst & Young is notifying clients after attackers spent two weeks inside a third-party IT ticketing platform whose support tickets routinely carried tax documents as attachments. The lesson isn't about EY — it's about what quietly accumulates in every ticketing system.

6 min
newsthreats

wp2shell: WordPress force-updates the web over a pre-auth RCE in core

A REST-API route confusion chained with a SQL injection gives anonymous attackers code execution on default WordPress installs — no plugins needed. WordPress shipped 6.9.5/7.0.2 on July 17 and switched on forced auto-updates. Patch now, before the public details become a working exploit.

6 min
encryptionengineering

How one-time secret links actually work: the URL fragment trick, explained

A one-time secret link uses an old browser rule: the URL fragment after # is omitted from HTTP requests. Here's how that limits what the storage service receives — and what the model does and doesn't protect against.

6 min
credentialsengineering

The five places secrets go to leak: .env files, CI logs, chat, tickets, and code

Almost every credential breach starts in one of five mundane places. A field guide to where secrets actually escape from — with the accumulation mechanics behind each one, and the habits that keep them empty.

7 min
newsbreaches

£29 million and 27,000 in-person password resets: the TfL hack's bill came due

Two Scattered Spider members were sentenced on July 16 for the 2024 Transport for London attack. The intrusion chain was pure credential work — bought logins, a 2FA reset, one persuaded help desk — and the recovery bill shows what re-establishing trust in credentials at scale really costs.

7 min
newsthreats

Stolen TOTP seeds and a CVSS 10: the week your MFA became the loot

SonicWall SMA1000 zero-days are being exploited to steal credentials, session databases — and TOTP seed configurations, the secrets your MFA is made of. Add a 9.8 in Zoom, a record 570-flaw Patch Tuesday, and actively exploited SharePoint bugs: July's perimeter fire drill, and what it says about where secrets live.

6 min
newsbreaches

This week in security: Turla hits Romania, 35 GB walks out of Accenture, and 12 million KDDI logins

A regional tour of the week of July 8–15, 2026: Russia's FSB-linked Turla targeting Romania and the EU, the D1R ransomware campaign against Arm and Bosch, Accenture's alleged 35 GB source-code theft, and Japan's biggest telecom breach of the year.

8 min
breachescredentials

The Accenture claim: when the loot is 35 GB of source code — and the keys inside it

An attacker claims 35 GB of Accenture source code, SSH keys, and Azure tokens. Whatever the final numbers turn out to be, it's the perfect case study in why a code leak is really a credential leak — and what to do about the keys living in your own repos.

7 min
newsbreaches

The biggest hacks and breaches of 2025–2026

Nation-state telecom espionage, SaaS supply-chain token theft, help-desk social engineering, and record-breaking extortion. A field guide to the landmark cyber incidents of 2025 and early 2026 — and the common thread running through them.

9 min
product-updateteams

What's new in Secretus: Teams, annual plans, and self-serve checkout

A product update: share one Business plan across your team via single-use invite links, pay yearly for two months free, and upgrade instantly with self-serve checkout — no more emailing sales.

4 min
threatscredentials

The credential-leak playbook: how attackers find secrets in Slack and email

Post-breach, the first move is often a search box. Here's how leaked passwords, API keys and tokens actually get discovered in chat and inboxes — and the workflow that removes them from the archive entirely.

6 min
post-quantumML-KEM

Post-quantum migration in 2026: what NIST, Apple, and Chrome already shipped

Post-quantum cryptography stopped being a research topic and started being deployed code. A field guide to what's already live in browsers and messengers — and why long-lived secrets can't wait for the timeline.

6 min
cryptographyshamir

Shamir's Secret Sharing, explained without the math degree

How a 1979 algorithm lets a team hold a secret that no single member can read — and why fewer than k shares reveal mathematically nothing. With practical k-of-n setups for real teams.

7 min
post-quantumML-KEM

Harvest now, decrypt later: the attack that's already happening

Encrypted traffic recorded today can be decrypted once quantum computers mature. What HNDL means for secrets with long lifetimes, what ML-KEM-768 changes, and how hybrid key agreement works.

6 min
practicalcredentials

How to share credentials with clients (without leaking them)

Email and Slack keep credentials forever, in plaintext, on servers you don't control. A practical guide for agencies, freelancers and consultants: one-time links, P2P transfer, and a checklist.

6 min