Topics
Browse posts by category and tag — every topic we cover, with the latest pieces under each.
Tags
- #threat-intel 9
- #ai-security 7
- #prompt-injection 5
- #vulnerability 4
- #agentic-ai 3
- #cisa-kev 3
- #malware 3
- #patch-management 3
- #vulnerability-management 3
- #bulletproof-hosting 2
- #chatgpt 2
- #edge-devices 2
- #enterprise-security 2
- #generative-ai 2
- #law-enforcement 2
- #llm-security 2
- #machine-learning 2
- #netherlands 2
- #russia 2
- #supply-chain 2
- #adversarial-ml 1
- #ai 1
- #ai-risks 1
- #ai-threats 1
- #anomaly-detection 1
- #apt 1
- #artificial-intelligence 1
- #banking 1
- #behavioral-analytics 1
- #bug-bounty 1
- #burnout 1
- #cisco 1
- #ciso 1
- #clickfix 1
- #credential-theft 1
- #cve 1
- #cybersecurity 1
- #cybersecurity-workforce 1
- #data-leakage 1
- #data-poisoning 1
- #ddos 1
- #deep-dive 1
- #deepfake 1
- #editorial-policy 1
- #emergency-directive 1
- #epss 1
- #eu-sanctions 1
- #exposure-management 1
- #financial-sector 1
- #financial-security 1
- #fraud 1
- #fraud-detection 1
- #graph-neural-networks 1
- #hub 1
- #model-security 1
- #model-supply-chain 1
- #newsroom 1
- #nist-ai-rmf 1
- #nvd 1
- #open-source 1
- #openai 1
- #owasp 1
- #package-registry 1
- #patch-tuesday 1
- #powershell 1
- #ransomware 1
- #remediation 1
- #roundup 1
- #rubygems 1
- #sanctions 1
- #sandworm 1
- #sd-wan 1
- #social-engineering 1
- #ukraine 1
- #voice-cloning 1
- #vulnerability-disclosure 1
Categories
threat-intel 12 posts
- Bulletproof Hosting: Why Takedowns Keep FailingSanctions and server seizures hit bulletproof hosting through 2025 and 2026, yet the infrastructure keeps returning. What actually degrades it.
- OpenAI Security: Bug Bounty Programs and Documented IncidentsOpenAI security in practice: two public bug bounty programs, a coordinated disclosure policy, and the documented incidents recorded from 2023 through 2026.
- Hotel Wi-Fi Hijacked for Spyware in Midnight Blizzard CampaignMicrosoft attributes the CaptiveCrunch campaign to Storm-2945, a Midnight Blizzard sub-cluster using compromised hotel captive portals to push fake updates.
- UAC-0145 Uses ClickFix CAPTCHAs to Deploy Malware in UkraineUAC-0145 ran ClickFix CAPTCHA lures on 10 or more compromised sites in mid-2026, tricking Ukrainian targets into running PowerShell that stages malware.
- Netherlands Seizes 800 Servers Over Russian-Linked HostingDutch FIOD agents seized more than 800 servers and arrested two hosting co-owners over EU sanctions tied to the Stark Industries Solutions network.
- This Month in Security: May 2026's Edge-Device ReckoningMay 2026 in review: a CVSS 10.0 Cisco SD-WAN bypass under active exploitation, an exploited Exchange XSS flaw, a critical Exim bug, and a quiet Patch Tuesday.
vulnerability 4 posts
- CVE Tracking in 2026: Prioritize When NVD Stops ScoringNIST moved the NVD to a triage model in April 2026. Here is what CVE tracking and patch prioritization look like when most records never get scored.
- CVSS 10.0 SD-WAN Bypass: What Emergency Directive 26-03 SignalsCVE-2026-20182 is a maximum-severity authentication bypass in Cisco Catalyst SD-WAN, added to CISA's KEV catalog on May 14 amid active exploitation.
- Most Remediation Programs Never Confirm the Fix Actually WorkedMandiant M-Trends 2026 puts mean time to exploit at negative seven days while Verizon's 2025 DBIR finds edge devices take 32 days to remediate.
- LLM Security Risks: The OWASP Top 10 and How to DefendA practitioner breakdown of the OWASP Top 10 for LLM applications, from prompt injection to excessive agency, and the controls that reduce real exposure.
industry 2 posts
- Standard Chartered's Group CISO on AI's Dual Role in Banking SecurityCezary Piekarski, group CISO at Standard Chartered, says AI is reshaping defensive operations and adversarial tactics simultaneously -- and that banking security leaders must think like business executives to keep pace.
- Cybersecurity Burnout Is a Structural Problem, Not a Personal OneA Sophos survey of 5,000 practitioners found 76% burnt out, and AI-accelerated vulnerability discovery is stretching an operating model already at its limit.