Dispatches. Practitioner-first cybersecurity coverage.
Independent reporting on AI security, SOC automation, identity, data and the adversarial edge. Every piece is rewritten in-house and credits every source — never a press-release copy.
Archive
Page 4 of 6-
Germany Names the Architect Behind GandCrab and REvil's Double-Extortion Era
After years of operating behind the handle 'UNKN,' the alleged head of GandCrab and REvil now has a face. Germany's BKA named 31-year-old Daniil Maksimovich Shchukin, tying him to 130 attacks and €35 million in damage.
-
Vercel's Context.ai Breach Pins the Real Cost of an 'Allow All' OAuth Click
A Vercel employee gave a small AI productivity tool full Google Workspace permissions. Months later, that tool was breached — and the attacker walked the OAuth scope straight into Vercel's environment.
-
FortiClient EMS Falls to a Second Pre-Auth Bypass in Weeks — and Lands on the KEV in 24 Hours
CVE-2026-35616 lets unauthenticated attackers pivot through a Fortinet endpoint management console that thousands of enterprises use to push policy to laptops. Honeypot data shows exploitation began over a holiday weekend, and CISA gave federal agencies three days to patch.
-
OpenAI Opens GPT-5.4-Cyber to Thousands of Defenders as the SOC-Copilot Race Tightens
OpenAI's Trusted Access for Cyber program now extends a defender-tuned model to thousands of vetted individuals and hundreds of teams. Anthropic's Glasswing rollout a week earlier sets up a head-to-head between the two frontier vendors over which AI gets first look at the SOC.
-
Criminals Are Still Skeptical About AI — And That's the Real Story
A new forum-analysis study finds cybercriminals are curious about AI but full of doubts about effectiveness and operational security. The diffusion-of-innovation framing reframes the 2026 threat story from 'AI arms race' to 'early adoption, slow uptake.'
-
A Python Notebook RCE Was Weaponized in Under Ten Hours — What the Marimo Flaw Tells Us About Dev-Tool Exposure
Attackers exploited a pre-auth RCE in the Marimo notebook platform nine hours and forty-one minutes after disclosure, harvesting credentials and deploying malware routed through Hugging Face. The speed collapses the patch window for developer tooling that security teams rarely inventory.
-
GRU's Forest Blizzard Turned 18,000 Home Routers Into a Silent OAuth Interception Layer
A GRU-linked campaign scaled OAuth token theft against government ministries by quietly rewriting DNS on thousands of end-of-life SOHO routers — no endpoint malware required. The technique bypasses MFA because it harvests tokens issued after login.
-
CSA Spins Out CSAI as a Standalone Nonprofit for Agentic AI Governance
The Cloud Security Alliance carved its AI work out into a separate 501(c)(3) foundation at RSAC 2026. The mission statement — 'Securing the Agentic Control Plane' — reframes AI security from defending models to governing the identity, authorization, and runtime of autonomous agents.
-
Microsoft's April Patch Drop: 169 Fixes, a SharePoint Zero-Day, and Windows Defender's 'BlueHammer'
April 2026 is the second-largest Patch Tuesday on record. One of the 169 CVEs is already under active exploitation in Microsoft SharePoint Server, and a publicly-disclosed Defender bug nicknamed BlueHammer rounds out an unusually dense release.