Dispatches. Practitioner-first cybersecurity coverage.
Independent reporting on AI security, SOC automation, identity, data and the adversarial edge. Every piece is rewritten in-house and credits every source — never a press-release copy.
Featured A Shared Preview Link Was Enough to Take Over Any Writer AI Tenant
Researchers at Sand Security found that Writer's enterprise AI platform forwarded live session cookies into its agent preview sandbox, letting attacker-supplied code read them out of process memory. One shared link could turn zero access into full control of another organization's agents, connectors, and LLM credentials.
Archive
Page 1 of 5-
Supply Chain Two 10.0 Joomla Extension Bugs Were Live Zero-Days Before Anyone Filed a CVE
CISA added maximum-severity flaws in the iCagenda and Balbooa Forms Joomla extensions to its Known Exploited Vulnerabilities catalog after both were exploited as zero-days. Neither lives in Joomla core — and that is precisely why they went unnoticed for weeks.
-
AI Security There Is No 'Security Meter' for AI — Schneier Makes the Case for Assurance
In a recent essay, Bruce Schneier argues that benchmarks cannot tell you whether an AI system is secure, because they miss the emergent, systemic behavior that actually matters. His prescription borrows from three decades of software security: build mature assurance processes instead of chasing a single score.
-
Threat Intel ShinyHunters Turn an Unpatched PeopleSoft Flaw Into a University Data Heist
A pre-authentication remote code execution bug in Oracle PeopleSoft, CVE-2026-35273, was exploited as a zero-day for two weeks before a patch existed. The extortion crew Mandiant tracks as UNC6240 used it to breach universities, with one UK institution losing the records of roughly 455,000 people.
-
AI Security Google Discloses First Confirmed AI-Authored Zero-Day, a 2FA Bypass Used for Mass Exploitation
Google's threat intel team says an unknown actor used a large language model to find and weaponise a zero-day 2FA bypass in a web admin tool. The Python exploit shipped with hallucinated CVSS scores and educational docstrings — the smoking gun that an LLM, not a human, wrote it.
-
Vulnerabilities On-Prem Exchange Hit: CVE-2026-42897 Lets a Crafted Email Run Code in OWA
Microsoft confirms active exploitation of an XSS spoofing flaw in on-prem Exchange Server. A crafted email opened in Outlook Web Access is enough to execute attacker-supplied JavaScript in the victim's browser context, and CISA has set a federal KEV deadline for May 29.
-
AI Security UK AI Security Institute Finds GPT-5.5 Matches Claude Mythos at Vulnerability Discovery
A new evaluation from the UK's AI Security Institute concludes that OpenAI's generally-available GPT-5.5 performs on par with Anthropic's restricted Claude Mythos at finding software vulnerabilities — and that a smaller model with the right prompting scaffolding gets close enough to matter.
-
Code Security An 18-Year-Old NGINX Bug Reopens One of the Internet's Most-Reached Code Paths
A heap buffer overflow in NGINX's rewrite module, undisclosed since 2008, can be triggered by a single crafted HTTP request and reaches unauthenticated RCE on hosts running with ASLR disabled. F5 has shipped patches for Open Source, Plus, and every derivative.
-
Vendor Cisco SD-WAN Controllers Hit by 10.0 Auth Bypass — Active Exploitation Confirmed
A maximum-severity authentication bypass in Cisco Catalyst SD-WAN Controller (CVE-2026-20182, CVSS 10.0) lets unauthenticated attackers gain administrative control over the SD-WAN fabric via UDP 12346. Cisco has confirmed limited in-the-wild exploitation; the vulnerable component has now produced two 10.0-rated bypasses in three years.
-
AI Security OpenAI's Daybreak Hands Defenders a Frontier Vulnerability Model
OpenAI launched Daybreak, a defensive cyber initiative pairing three GPT-5.5 variants with Codex Security to give vendors access to AI vulnerability discovery, threat modeling, and patch validation. The release confirms that frontier labs now treat vuln-finding capability as gated infrastructure rather than a public product.