·1326 words·7 mins
How the DNS hijacking attack chain worked across 120+ countries, and what practitioners should be checking in their own environments.
·1054 words·5 mins
Reduced offensive capability, automated request blocking, and a verification path for legitimate practitioners. What it changes for security work.
·945 words·5 mins
How the April 2026 compromise of CPUID’s site turned CPU-Z and HWMonitor downloads into a multi-stage malware delivery chain.
·1599 words·8 mins
Why endpoint management servers are a high-value target, how both flaws were exploited, and the actions practitioners should take today.
·1402 words·7 mins
What happens when a frontier model finds vulnerabilities faster than anyone can patch them, and how the industry is trying to get ahead of it.
·2038 words·10 mins
At least 11 phishing kits now abuse the OAuth device flow to bypass MFA entirely. How the attack works and how to shut it down.
·1191 words·6 mins
Every consumer router made outside the US is now on the FCC Covered List. Why firmware verification matters more than the import ban.
·1872 words·9 mins
Two weeks after writing about the structural problems with compliance platforms, the allegations landed. What assessors already knew.
·2488 words·12 mins
What to watch at RSAC 2026, filtered for practitioners: the agentic AI themes with substance and the ones that are vendor noise.
·1696 words·8 mins
If your IAM program doesn’t treat non-human identities with the same rigor as human accounts, you have a problem that’s already being exploited.