Threats and Incidents Spirals: from web shell to encryption in under a day
Spirals ransomware encrypted an IT firm's network in under 24 hours. We break down the attack timeline and show where it could have been stopped.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Threats and Incidents Spirals ransomware encrypted an IT firm's network in under 24 hours. We break down the attack timeline and show where it could have been stopped.
AI Security Anthropic released the Claude Security Plugin in beta — a multi-agent vulnerability scanner for Claude Code. How it works, where it helps, what it won't replace.
Vulnerabilities and CVEs Two CVSS 9.1 flaws in FortiSandbox let an unauthenticated attacker run OS commands. Both are in CISA KEV. Analysis, detection and remediation.
AI Security Google shipped Gemini 3.6 Flash: lower output pricing, ~17% fewer tokens and a 1M context window. What it means for cost, deployments and security.
Vulnerabilities and CVEs Microsoft patched a record 570 vulnerabilities and three zero-days in July 2026. How to triage that many fixes and what you must not defer.
Threats and Incidents A 0-day in Oracle PeopleSoft (CVE-2026-35273) hit 100+ organisations including NAIC. Analysis, and a lesson in reading extortion groups' claims.
AI Security OpenAI and Broadcom unveiled Jalapeño, a custom ASIC for LLM inference. What the custom silicon race means for cost, availability and AI security.
Identity and Access How to split an environment into tiers, what really belongs to Tier 0, how to enforce the split technically and how to migrate without downtime.
AI Security Zenity Labs showed how a single link could create an autonomous agent in ChatGPT Workspace working for an attacker. CSRF in the age of agents.
Vulnerabilities and CVEs The public Certighost exploit lets an ordinary domain user impersonate a domain controller through AD CS and run DCSync. Analysis and detection.
Threats and Incidents The Anubis attack on Coca-Cola's Fairlife halted US production, and entry came through a third party. An analysis of an OT incident and SEC disclosure.
Penetration Testing and AppSec Why object-level authorization fails most often: overlooked IDOR variants, UUID myths, durable fix patterns, a testing method and log-based detection.
Identity and Access How JWT verification works and where it breaks: alg confusion, kid injection, JWKS handling, iss/aud validation, revocation, testing and detection.
AI Security METR published no capability number for GPT-5.6 Sol because the model gamed evaluations too often — and attacked its own test environment. What it means.
Penetration Testing and AppSec Why extension checks solve nothing: filenames, types, serving, parsers, archives and limits. A target upload pipeline and a practical testing method.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.