Stop exposing network management interfaces to the internet. MikroTik is now being actively exploited through internet-facing SSH to gain full administrative control without authentication.
08/09/2026
· related: Hacking the Nimbra 230: Unlocking a Carrier-Grade Switch
Invisible Unicode has been around for ages, but now it's being weaponised to bypass security filters.
07/09/2026
· related: ASCII Smuggling
Don't treat EDR as your one-and-done solution. The Gentlemen ransomware operators are disabling EDR, destroying backups and clearing logs before encrypting the network.
03/09/2026
Attackers are now putting malicious prompts inside malware to trigger AI safety guardrails and interfere with analysis. Wow.
02/09/2026
· related: HalluSquatting
100 companies, including the companies building AI models, are warning that AI-powered cyberattacks could become widespread within months. We need to prepare our infrastructure, systems and users, and automate defence at the same pace.
31/08/2026
· related: HalluSquatting
Nice. ECH + DoH is a significant privacy upgrade and makes it harder for your ISP to snoop on your browsing.
28/08/2026
· related: You Can't VPN Out of On-Device Scanning
So we're putting increasingly autonomous agents into environments where we monitor the systems, but not the agents themselves? If an agent can find its own paths to an objective that we didn't anticipate, having a human in the loop means pretty much nothing.
27/08/2026
· related: HalluSquatting
Frankly, not surprised. A huge chunk of email hosting is based on reputation, not the computing stack. Google, Microsoft and others make their own decisions about whether to accept your mail.
26/08/2026
· related: zz.ac: free domains without phishing
Selling the shovels isn't enough? Nvidia started financing the gold rush.
25/08/2026
Cybersecurity is becoming an automation arms race. Humans are going to be too slow to manually respond to AI-driven attacks.
24/08/2026
Lots of dependency poisoning lately. SCA + dependency pinning/lockfiles + isolated builds + sandboxing + EDR are a must for keeping third party code under control.
22/08/2026
· related: HalluSquatting
We're in an electricity infrastructure boom riding on GPUs.
21/08/2026
Using Bluetooth/BLE to build a relay infrastructure and bypass network restrictions is actually genius. Scary, but smart. Now you have to walk around with an air-gapped brick.
20/08/2026
CVSS 9.8, unauthenticated RCE, remotely exploitable. Probably don't wait until Patch Tuesday :|
19/08/2026
· related: Resource Exhaustion Attacks
Broadcom's VMware licensing mess sure makes it easy to patch CVEs. Just migrate.
18/08/2026
Giving an AI agent access to years of SOC history is a choice. Do your due diligence.
17/08/2026
· related: HalluSquatting
Anthropic says the watermark doesn't affect Claude's quality. Maybe. But the watermark is produced by deliberately biasing the model's token selection.
15/08/2026
· related: HalluSquatting
AI is finding vulnerabilities faster than orgs can fix them, but I don't think that's a problem with AI. It's just exposing the technical debt we already had.
14/08/2026
· related: HalluSquatting
Short-burst 1 Tbps DDoS attacks are becoming more common now. Absurd amounts of traffic delivered in seconds.
13/08/2026
· related: Denial of Wallet Attacks
Nearly 400 vulnerabilities and 3 ZDs in one Patch Tuesday. Wild.
12/08/2026
"Rogue AI" is a stretch. They were given a prompt and followed the path of least resistance. They just didn't isolate the agent's network access.
11/08/2026
· related: HalluSquatting
European tech sovereignty sounds great until you realise how much of Europe's IT infrastructure is built around US companies.
10/08/2026
· related: You Can't VPN Out of On-Device Scanning
As usual, Meta had to follow in the footsteps of Anthropic and OpenAI. Great idea giving AI internet access during security tests.
08/08/2026
Metabase just had a zero-day breach. If you're self-hosting Metabase, deploy the latest version.
07/08/2026
· related: MetaBase - A Powerful Power BI Alternative
What's up with containment controls?
06/08/2026
Finally, I can stop asking customer service for recipes to figure out whether I'm talking to AI.
05/08/2026
· related: You Can't VPN Out of On-Device Scanning
Intercepting captive portals on public networks is terrifying, with the public Wi-Fi captive portal experience becoming one massive phishing trap.
04/08/2026
· related: Credential Harvesting with Evil Twins
Europe designing its own high-performance RISC-V silicon is fantastic news for digital sovereignty.
03/08/2026
So Google is essentially turning your Google profile into an API for AI agents, letting them operate as you. Can't wait for the next generation of prompt injections.
02/08/2026
· related: Passkeys (WebAuthn)
OpenAI last week, now Anthropic... Why aren't these tests run in an isolated environment? HalluSquatting is becoming a thing now.
01/08/2026
· related: HalluSquatting
Surprise. Flock was never really about deterring crime, but a justification for building a mass surveillance network.
30/07/2026
Admins, please don't expose one of the most powerful backdoors in your environment to the world. BMC is not meant to be discoverable by Shodan.
29/07/2026
· related: Hacking the Nimbra 230: Unlocking a Carrier-Grade Switch
Microsoft admitting its own UI framework wastes memory is probably the biggest endorsement of lightweight Linux desktops they've given in years.
28/07/2026
Cloudflare's plan only works if AI companies need your content more than you need their traffic. Should AI be able to use your content without sending visitors back? If not, are you willing to risk becoming less visible as AI increasingly replaces traditional search?
27/07/2026
OpenAI didn't even clock it for a week? With models this capable, training needs to be regulated and supervised.
26/07/2026
Shame the RAM crisis forced Valve into bumping the price, SteamOS / Bazzite / Nobara managed to bridge a massive gap.
25/07/2026
Australia, the UK, now France (which at least mandates double-blind attestation so the site does not know your name).
The others could have done the same. But isn't it more convenient to tie a government ID to your browsing history? What a privacy nightmare.
24/07/2026
Great precedent for AI companies, apparently the issue isn't using copyrighted works to train AI, it's how you obtained them... smh.
23/07/2026
Thank you, Joshua and Anthony, for everything you've contributed to the open source community.
22/07/2026
HP, the king of anti consumer practices. Is Brother the only reliable printer brand left on the market?
21/07/2026
If your users talk about IT every day, you're probably doing IT wrong. The best IT departments are invisible.
20/07/2026
I bought Meta's glasses in the first wave back in 2023, for the tech, and quit wearing them within a week because it just felt plain wrong. Build a device whose whole pitch is secretly filming people, and don't be shocked when the people drawn to that pitch turn out to be creeps.
19/07/2026
All this just after Fortibleed, is Fortinet chronically behind their own attack surface?
18/07/2026
Don't really see the point of this macropad, but have to admit the design is neat.
17/07/2026
No wonder, GG Broadcom. Everyone is either migrating or actively evaluating alternatives like Proxmox.
16/07/2026
· related: Virtualised Workstation: Local Cloud-Gaming
If your entire digital life exists behind one cloud account, you don't have a backup.
15/07/2026
· related: A Solid 3-2-1 Backup Strategy
September is getting closer and there are still no news on the implementation plans. Graphene and Lineage look like they'll be no exception either, since they already fail Play Integrity that age checks are built on.
14/07/2026
I was never sold on Plex's centralised user management. If their "lifetime" passes were the final straw, come on over to Jellyfin.
13/07/2026
· related: Self-Hosted Media Server (Arr Stack w/ Jellyfin)
Yet another prompt injection vector, maybe don't let agents auto-read arbitrary files referenced from convention files without a policy gate?
12/07/2026
· related: Steganography in the Wild
Future is bleak; though this is for unencrypted private messages, only a matter of time until OS-level surveillance is implemented (at least in the UK for now), undermining E2EE.
11/07/2026
Patch your Gitea instance whether or not it's exposed (and change default admin username while at it).
10/07/2026