Threats and Incidents AnySign4PC watering holes infected visitors on page view
Compromised Korean sites exploited AnySign4PC to install SIGNBT or COPPERHEDGE without another click. We analyse the chain and detection.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Threats and Incidents Compromised Korean sites exploited AnySign4PC to install SIGNBT or COPPERHEDGE without another click. We analyse the chain and detection.
Vulnerabilities and CVEs Cisco confirms active exploitation of static FMC credentials. We explain the 5.3 CVSS score, possible chaining, indicators and response.
AI Security A hidden instruction could alter figures and pass into later files created by Copilot. We examine the propagation mechanism and practical controls.
Supply Chain Security Amazon attributes the debug, chalk, axios and typo-crypto incidents to a DPRK-linked actor with medium confidence. We assess the evidence.
Supply Chain Security The FCC added foreign-produced robots and connected inverters to its Covered List. We explain the scope, exceptions and technical risk.
Human Security A new Polish guide addresses grooming, sextortion and AI-generated abuse. We add a technical model for account protection, evidence and response.
Threats and Incidents TA488 exploits CVE-2026-42897 and OWAReaper for durable mailbox access. We analyse half-click delivery, OAuth, localStorage and response.
Threats and Incidents SilverFox combined three vulnerable drivers, DLL side-loading and dual watchdogs to sustain ValleyRAT. We analyse the chain and detection.
Human Security A campaign cloned Russian corporate websites to steal B2B advance payments. Learn its tradecraft, warning signs and payment controls.
Vulnerabilities and CVEs Public CVE-2026-10702 analysis explains a SpiderMonkey JIT flaw and Firefox-to-kernel chain. Review scope, patches and defensive priorities.
Threats and Incidents Researchers found Flying Eagle Android RAT infrastructure fingerprints on 170 servers. We analyse scope, capabilities, detection and response.
Vulnerabilities and CVEs Gitea before 1.27.1 let repository writers create a live Git hook and execute server commands. Review preconditions, impact and remediation.
Supply Chain Security Two Joyfill prereleases contained a RAT loaded on module import. We explain the blockchain C2 resolver, exposure evidence and response plan.
Threats and Incidents A real LinkedIn recruitment incident led to a DMG, LaunchAgent and in-memory JXA. We explain the chain, impact, detection and response.
Penetration Testing and AppSec MOL Move field-level authorization flaws allowed role, email and loyalty data changes. We examine the facts, root cause and disclosure failure.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.