·1436 words·7 mins
How the traffic laundering economy turns jailbroken FireSticks into residential proxies, and what defenders can actually do about it.
·1142 words·6 mins
A practitioner breakdown of the npm worm that sweeps environment variables on install and republishes itself through Trusted Publishing.
·2357 words·12 mins
The largest DBIR ever published, read for signal. Where generative AI actually shows up in the data and where the fundamentals still rule.
·1491 words·7 mins
Google caught the first AI-assisted zero-day in the wild. How attackers talked a model into helping, and why the method matters more than the exploit.
·1417 words·7 mins
CISA and NCSC published a joint analysis of FIRESTARTER, a backdoor that survives reboots and evades signature detection on Cisco edge devices.
·1326 words·7 mins
How the DNS hijacking attack chain worked across 120+ countries, and what practitioners should be checking in their own environments.
·945 words·5 mins
How the April 2026 compromise of CPUID’s site turned CPU-Z and HWMonitor downloads into a multi-stage malware delivery chain.
·1599 words·8 mins
Why endpoint management servers are a high-value target, how both flaws were exploited, and the actions practitioners should take today.
·805 words·4 mins
What the IBM X-Force Threat Intelligence Index 2026 says about AI-accelerated attacks, and why basic hygiene failures still cause the damage.
·2845 words·14 mins
A threat that matured abroad has found a home in the US. How ATM jackpotting works, why it keeps working, and what the industry guidance says.