Dispatches. Practitioner-first cybersecurity coverage.
Independent reporting on AI security, SOC automation, identity, data and the adversarial edge. Every piece is rewritten in-house and credits every source — never a press-release copy.
Archive
Page 3 of 5-
AI Security An 'Expected' MCP Behavior Is Now an RCE Vector Across 7,000 AI Servers
OX Security disclosed a design-level flaw in Anthropic's Model Context Protocol that turns the STDIO transport's default configuration into remote code execution. Anthropic says the behavior is expected; the open-source agent ecosystem now has dozens of CVEs to triage.
-
Threat Intel Germany Names the Architect Behind GandCrab and REvil's Double-Extortion Era
After years of operating behind the handle 'UNKN,' the alleged head of GandCrab and REvil now has a face. Germany's BKA named 31-year-old Daniil Maksimovich Shchukin, tying him to 130 attacks and €35 million in damage.
-
Supply Chain Vercel's Context.ai Breach Pins the Real Cost of an 'Allow All' OAuth Click
A Vercel employee gave a small AI productivity tool full Google Workspace permissions. Months later, that tool was breached — and the attacker walked the OAuth scope straight into Vercel's environment.
-
Threat Intel FortiClient EMS Falls to a Second Pre-Auth Bypass in Weeks — and Lands on the KEV in 24 Hours
CVE-2026-35616 lets unauthenticated attackers pivot through a Fortinet endpoint management console that thousands of enterprises use to push policy to laptops. Honeypot data shows exploitation began over a holiday weekend, and CISA gave federal agencies three days to patch.
-
AI Security OpenAI Opens GPT-5.4-Cyber to Thousands of Defenders as the SOC-Copilot Race Tightens
OpenAI's Trusted Access for Cyber program now extends a defender-tuned model to thousands of vetted individuals and hundreds of teams. Anthropic's Glasswing rollout a week earlier sets up a head-to-head between the two frontier vendors over which AI gets first look at the SOC.
-
Threat Intel Criminals Are Still Skeptical About AI — And That's the Real Story
A new forum-analysis study finds cybercriminals are curious about AI but full of doubts about effectiveness and operational security. The diffusion-of-innovation framing reframes the 2026 threat story from 'AI arms race' to 'early adoption, slow uptake.'
-
Code Security A Python Notebook RCE Was Weaponized in Under Ten Hours — What the Marimo Flaw Tells Us About Dev-Tool Exposure
Attackers exploited a pre-auth RCE in the Marimo notebook platform nine hours and forty-one minutes after disclosure, harvesting credentials and deploying malware routed through Hugging Face. The speed collapses the patch window for developer tooling that security teams rarely inventory.
-
Threat Intel GRU's Forest Blizzard Turned 18,000 Home Routers Into a Silent OAuth Interception Layer
A GRU-linked campaign scaled OAuth token theft against government ministries by quietly rewriting DNS on thousands of end-of-life SOHO routers — no endpoint malware required. The technique bypasses MFA because it harvests tokens issued after login.
-
Policy CSA Spins Out CSAI as a Standalone Nonprofit for Agentic AI Governance
The Cloud Security Alliance carved its AI work out into a separate 501(c)(3) foundation at RSAC 2026. The mission statement — 'Securing the Agentic Control Plane' — reframes AI security from defending models to governing the identity, authorization, and runtime of autonomous agents.