Dispatches. Practitioner-first cybersecurity coverage.
Independent reporting on AI security, SOC automation, identity, data and the adversarial edge. Every piece is rewritten in-house and credits every source — never a press-release copy.
Archive
Page 3 of 6-
Active Exploitation of Ivanti EPMM Forces a 72-Hour Federal Patch Window
A high-severity flaw in Ivanti's on-prem mobile device management platform, CVE-2026-6973, hit CISA's Known Exploited Vulnerabilities list with one of the tightest deadlines of the year. The exploitation requires admin authentication — which means previously compromised credentials are the live attack path.
-
Critical cPanel Auth Bypass CVE-2026-41940 Hits Asia-Pacific Governments and MSPs Within 24 Hours of Disclosure
A critical authentication-bypass in cPanel and WHM was weaponized within a day of public disclosure, with multiple operators using AdaptixC2, Mirai variants, and Sorry ransomware against government targets in Southeast Asia and managed service providers across five countries.
-
Scattered Spider's 'Tylerb' Pleads Guilty in California, Faces 22 Years for SIM-Swap Spree That Defined the Crew
A 24-year-old Scottish national admitted to wire-fraud conspiracy and aggravated identity theft tied to the 2022 phishing campaign that put Scattered Spider on the map, the second senior member to plead guilty in US federal court and a useful read on how durable the loose-knit crew remains a year after its first conviction.
-
CISA Drops Eight Live-Fire CVEs Into KEV With April–May Deadlines, Three of Them Cisco SD-WAN
Federal civilian agencies have less than two weeks to remediate eight newly weaponized CVEs added to CISA's Known Exploited Vulnerabilities catalog — three of them in Cisco Catalyst SD-WAN Manager, plus reactivated bugs in PaperCut, Zimbra, Quest KACE, JetBrains, and Kentico that are now tied to nation-state and ransomware operators.
-
Flowise's Third Live-Fire RCE: 12,000 AI-Agent Builders Exposed to a CVSS 10.0 Code-Injection Bug
A maximum-severity code-injection flaw in Flowise's CustomMCP node, CVE-2025-59528, is being exploited from a single Starlink IP across more than 12,000 internet-facing instances — the third in-the-wild Flowise vulnerability in seven months.
-
Stolen Session Cookies Now Outpace Stolen Passwords — and 31% of Them Walk Past MFA
Recorded Future's 2025 identity-threat data, surfaced this week by Dark Reading, indexed 276 million stolen credentials carrying active session cookies — about 31% of all malware-sourced creds, each one effectively pre-authenticated. Identity is the perimeter, and the multi-factor prompt is no longer the chokepoint defenders thought it was.
-
An AI Inference Server Bug Was Weaponized in Twelve Hours — LMDeploy Joins the Fast-Burn AI-Infra List
Twelve hours and thirty-one minutes after public disclosure, attackers were already pivoting through CVE-2026-33626, a server-side request forgery flaw in LMDeploy's vision-language module — probing AWS metadata, Redis, and MySQL from a tool most ML teams run with little operational telemetry.
-
A Crafted PDF Is Still Enough — Adobe Patches an Actively Exploited Acrobat Zero-Day
CVE-2026-34621 is a prototype-pollution flaw in Acrobat's JavaScript engine that turns a malicious PDF into arbitrary code execution. Researchers say exploitation began in December 2025 — four months before Adobe's emergency patch and the CISA KEV listing.
-
An 'Expected' MCP Behavior Is Now an RCE Vector Across 7,000 AI Servers
OX Security disclosed a design-level flaw in Anthropic's Model Context Protocol that turns the STDIO transport's default configuration into remote code execution. Anthropic says the behavior is expected; the open-source agent ecosystem now has dozens of CVEs to triage.