Cybersecurity

When the internet’s plumbing catches fire

Cisco Secure Workload Gets Two Perfect-Ten Vulnerabilities — The Segmentation Butler Has Misplaced the Velvet Rope

Cisco has disclosed a small marble staircase of vulnerabilities in Cisco Secure Workload Software, the micro-segmentation product formerly known as Tetration. According to The Register,…

Read more

Hackers Poison Popular Rust Crates to Steal Developer Credentials — The Build Script Has Entered Its Infostealer Sommelier Phase

Rust developers received another elegant reminder this week that software supply chains are not chains so much as necklaces made of tiny loaded mousetraps. Attackers…

Read more

Leaked AWS Keys Remain Active for Years — The Cloud Has Misplaced Its Root Badge in the Champagne Bucket

Cloud security has produced another exquisite reminder that “publicly exposed credential” is not a vibe, a growth experiment, or an unfortunate branding choice. It is…

Read more

Russian Spies Add OAuth Abuse to Phishing Campaigns — The Meeting Invite Has Entered Its Espionage Era

Google’s Threat Intelligence Group says three suspected Russian cyber-espionage groups are targeting people in academia, aerospace, defense, government, and think tanks across Europe and the…

Read more

Federal Agencies Warn AI-Made Code Is Hitting Siemens PLCs — Critical Infrastructure Has Found a Script Kiddie in the Pump Room

🤚 The Open-Palm Controller Incident Five U.S. federal agencies warned this week that attackers are using AI-generated exploitation scripts against internet-exposed Siemens S7 Series programmable…

Read more

CISA Gives Agencies Three Days to Patch Ray RCE — The Machine Learning Cluster Has Accepted a Browser-Scented Knife

🤚 The Open-Palm Patch Siren CISA has added an actively exploited Ray vulnerability to its Known Exploited Vulnerabilities catalog and given U.S. federal civilian agencies…

Read more

Millions of Alleged Azure Employee Records Go on Sale — The Cloud Directory Has Misplaced the Corporate Seating Chart

A cybercriminal calling themselves TheHatman is reportedly advertising millions of employee records allegedly siphoned from Microsoft Azure environments belonging to major companies, according to The…

Read more

Zhipu Claims GLM-5.3 Can Hunt Bugs Better Than Western Rivals — The Vulnerability Sommelier Has Gone International

🤚 The Open-Palm Vulnerability Parade Zhipu, a Chinese AI company, has launched GLM-5.3, a model it claims can compete with leading Western systems at finding…

Read more

ChainDrop Worm Poisons 444 npm Packages — The JavaScript Supply Chain Has Discovered Tarball-Based Ambience

There are supply-chain incidents, and then there are moments when the software ecosystem looks down at its velvet slippers and realizes the floor is, technically,…

Read more

RingCentral Customer Data Lands Online After ShinyHunters Extortion — The Collaboration Suite Has Misplaced 1.6 Million Calling Cards

RingCentral has joined the increasingly crowded banquet table of companies discovering that “limited portion of customers” still sounds quite large when the internet starts counting.…

Read more