Cybersecurity
When the internet’s plumbing catches fire
Cisco Secure Workload Gets Two Perfect-Ten Vulnerabilities — The Segmentation Butler Has Misplaced the Velvet Rope
Cisco has disclosed a small marble staircase of vulnerabilities in Cisco Secure Workload Software, the micro-segmentation product formerly known as Tetration. According to The Register,…
Read moreHackers Poison Popular Rust Crates to Steal Developer Credentials — The Build Script Has Entered Its Infostealer Sommelier Phase
Rust developers received another elegant reminder this week that software supply chains are not chains so much as necklaces made of tiny loaded mousetraps. Attackers…
Read moreLeaked AWS Keys Remain Active for Years — The Cloud Has Misplaced Its Root Badge in the Champagne Bucket
Cloud security has produced another exquisite reminder that “publicly exposed credential” is not a vibe, a growth experiment, or an unfortunate branding choice. It is…
Read moreRussian Spies Add OAuth Abuse to Phishing Campaigns — The Meeting Invite Has Entered Its Espionage Era
Google’s Threat Intelligence Group says three suspected Russian cyber-espionage groups are targeting people in academia, aerospace, defense, government, and think tanks across Europe and the…
Read moreFederal Agencies Warn AI-Made Code Is Hitting Siemens PLCs — Critical Infrastructure Has Found a Script Kiddie in the Pump Room
🤚 The Open-Palm Controller Incident Five U.S. federal agencies warned this week that attackers are using AI-generated exploitation scripts against internet-exposed Siemens S7 Series programmable…
Read moreCISA Gives Agencies Three Days to Patch Ray RCE — The Machine Learning Cluster Has Accepted a Browser-Scented Knife
🤚 The Open-Palm Patch Siren CISA has added an actively exploited Ray vulnerability to its Known Exploited Vulnerabilities catalog and given U.S. federal civilian agencies…
Read moreMillions of Alleged Azure Employee Records Go on Sale — The Cloud Directory Has Misplaced the Corporate Seating Chart
A cybercriminal calling themselves TheHatman is reportedly advertising millions of employee records allegedly siphoned from Microsoft Azure environments belonging to major companies, according to The…
Read moreZhipu Claims GLM-5.3 Can Hunt Bugs Better Than Western Rivals — The Vulnerability Sommelier Has Gone International
🤚 The Open-Palm Vulnerability Parade Zhipu, a Chinese AI company, has launched GLM-5.3, a model it claims can compete with leading Western systems at finding…
Read moreChainDrop Worm Poisons 444 npm Packages — The JavaScript Supply Chain Has Discovered Tarball-Based Ambience
There are supply-chain incidents, and then there are moments when the software ecosystem looks down at its velvet slippers and realizes the floor is, technically,…
Read moreRingCentral Customer Data Lands Online After ShinyHunters Extortion — The Collaboration Suite Has Misplaced 1.6 Million Calling Cards
RingCentral has joined the increasingly crowded banquet table of companies discovering that “limited portion of customers” still sounds quite large when the internet starts counting.…
Read more