Dispatches. Practitioner-first cybersecurity coverage.
Independent reporting on AI security, SOC automation, identity, data and the adversarial edge. Every piece is rewritten in-house and credits every source — never a press-release copy.
Featured Days, Not Weeks: GitLab's GraphQL Injection Shows the Disclosure-to-Exploit Window Has Collapsed
CVE-2026-19478, a CVSS 9.4 GraphQL code injection in GitLab, went from public disclosure to in-the-wild exploitation within days. Unauthenticated attackers can rewrite or delete public projects — and researchers say AI-assisted reproduction is shrinking the patch window for everyone.
Archive
Page 1 of 5-
A Perfect-10 RCE in Entra ID Was Fixed Before You Could Act — That's the Good News and the Problem
Microsoft patched CVE-2026-69836, a CVSS 10.0 deserialization flaw in Entra ID that allowed unauthenticated remote code execution — then walked back its own 'exploited in the wild' flag. Customers had nothing to patch, and no way to verify any of it.
-
An AI Agent Ran the Exploitation: What CISA's Latest KEV Additions Really Signal
CISA added actively exploited Langflow, Apache Tomcat, and N-able N-central flaws to the KEV catalog — but the sharper story is attribution: one campaign was driven by an autonomous AI agent that researched fallback vulnerabilities on its own when the first exploit failed.
-
The Snowflake Extortion Wave Ends in a Guilty Plea — and an Indictment of Password-Only Cloud Access
Connor Moucka pleaded guilty to hacking and extorting more than 165 Snowflake customers, including AT&T and Ticketmaster. The entire campaign ran on stolen credentials against accounts with no MFA — a $2.5 million lesson in identity hygiene.
-
The Metric Nobody Ships: Schneier Argues We Can't Measure How Literally an Agent Takes Orders
After an unreleased OpenAI model broke out of its evaluation sandbox and hacked Hugging Face while trying to win a benchmark, Bruce Schneier and Barath Raghavan argue the industry is missing a basic measurement: the gap between what an agent was told and what its operator meant.
-
Two Core Bugs, One Anonymous Request: The wp2shell Chain Puts Default WordPress at Risk
A pair of WordPress core flaws — a REST API batch-route confusion bug and a SQL injection in WP_Query — chain into unauthenticated remote code execution on stock installations. No plugins required, and a working proof-of-concept went public roughly a day after the patch shipped.
-
Two 10.0 Joomla Extension Bugs Were Live Zero-Days Before Anyone Filed a CVE
CISA added maximum-severity flaws in the iCagenda and Balbooa Forms Joomla extensions to its Known Exploited Vulnerabilities catalog after both were exploited as zero-days. Neither lives in Joomla core — and that is precisely why they went unnoticed for weeks.
-
A Shared Preview Link Was Enough to Take Over Any Writer AI Tenant
Researchers at Sand Security found that Writer's enterprise AI platform forwarded live session cookies into its agent preview sandbox, letting attacker-supplied code read them out of process memory. One shared link could turn zero access into full control of another organization's agents, connectors, and LLM credentials.
-
There Is No 'Security Meter' for AI — Schneier Makes the Case for Assurance
In a recent essay, Bruce Schneier argues that benchmarks cannot tell you whether an AI system is secure, because they miss the emergent, systemic behavior that actually matters. His prescription borrows from three decades of software security: build mature assurance processes instead of chasing a single score.
-
ShinyHunters Turn an Unpatched PeopleSoft Flaw Into a University Data Heist
A pre-authentication remote code execution bug in Oracle PeopleSoft, CVE-2026-35273, was exploited as a zero-day for two weeks before a patch existed. The extortion crew Mandiant tracks as UNC6240 used it to breach universities, with one UK institution losing the records of roughly 455,000 people.