Cybersecurity
Vulnerabilities, ransomware, CVEs, pentesting, OSINT and the latest in information security.
38 published articles
Offensive Hacking Under Federal Oversight
The US is outsourcing offensive hacking. Knowing who to hit is the catch
A new presidential memorandum lets private cybersecurity firms conduct international attacks on foreign criminals under DOJ and DHS oversight, with a $1 million bond as the backstop. Researchers say the rule banning strikes on state-run groups is nearly impossible to apply.
2026-08-22
Cybersecurity
Microsoft's AI bug hunters are about to make Patch Tuesday bigger
The July 2026 Secure Future Initiative report shows MDASH, Microsoft's agentic scanner, moving from benchmarks into Windows, Azure, and identity workflows, with AI-found fixes set to make each Patch Tuesday heavier.
2026-08-15
Ransomware & Cybercrime
DeadLock ransomware puts its leak site on Polygon to dodge takedowns
Microsoft's teardown of DeadLock shows victim chats routed over Session and leak posts stored in Polygon smart contracts. The design resists the domain seizures that normally disrupt extortion operations, and it is already working: 80+ organizations published since July 2025.
2026-08-14
Data Breach
Valve warns European Steam buyers: scammers may quote your address
Valve warns European Steam hardware buyers to expect phishing after a breach at shipping partner CEVA Logistics likely exposed names, addresses, phone numbers, and emails. Fake messages may quote your real address to sound genuine.
2026-08-14
Offensive AI compresses the exploit timeline
An AI agent cracked Zoom in a day. The patch can't fix what changed.
A critical Zoom vulnerability allowing full device takeover was exploited in a single day using fewer than 20 AI prompts. Security researchers call it a shift: exploit development that once took nation-state teams months can now be done by anyone with access to public models.
2026-08-13
Known Exploited Vulnerabilities
Active exploits push Progress LoadMaster flaw onto CISA's must-patch list
CISA's KEV catalog now includes CVE-2026-8037, an actively exploited command injection flaw in Progress LoadMaster. Under BOD 26-04, the entry turns a one-line advisory into a federal patch priority, and CISA urges every organization to treat the list the same way.
2026-08-10
AI security
Security isn't slowing ai down. It's what makes AI work at scale.
How security teams can turn trust into a competitive advantage in the age of AI by asking better questions, not gathering more data.
2026-08-06
Cybersecurity
Why Microsoft thinks one AI model isn't enough to stop the next attack
Microsoft's Project Perception is an agentic security system that uses red, blue, and green AI agents to perceive, reason, and act at machine speed. It enters public preview on August 3 with a multi-model architecture that includes the specialized MAI-Cyber-1-Flash model.
2026-08-05
Phishing & Social Engineering
Tycoon2fa's 92% collapse and the quiet rise of teams vishing
Microsoft's Q2 2026 threat data shows the Tycoon2FA disruption cut its phishing volume by 92%, while Teams vishing grew to 10x the 2025 baseline, signaling a shift toward trusted workplace channels.
2026-08-04
CISA
CISA adds two actively exploited flaws to its must-patch catalog
CISA added CVE-2026-16232 (Check Point SmartConsole) and CVE-2026-50522 (Microsoft SharePoint) to its KEV catalog, requiring rapid remediation for federal agencies. The advisory definitions behind these listings clarify how industrial control and medical device vulnerabilities are disclosed and mitigated.
2026-08-02
CISA KEV
Cisco flaw on CISA's KEV list: patching is not enough anymore
CISA adds a Cisco firewall password flaw to its KEV catalog. Under BOD 26-04, federal agencies must now investigate for pre-patch exploitation, not just apply the patch. The same expectation applies to recent Check Point and Microsoft SharePoint vulnerabilities.
2026-08-02
Digital Rights
The duress password trap: when wiping your phone becomes a crime
Sam Tunick faces federal charges after using a GrapheneOS duress password to wipe his phone during a border detention. The case tests whether encryption features can be criminalized and challenges the reach of warrantless border searches.
2026-07-31