News
Analysis of what happened, with every figure attributed to a named source — and 14,951 stories filed between 2014 and 2021, still here and still searchable.
Analysis
- The server that manages every client needed no password
September 5, 2026 · 6 sources
A max-severity pre-authenticated flaw in N-able's N-central let attackers run code on the RMM console that reaches every managed machine.
- The malicious code came in as styling
September 4, 2026 · 6 sources
StyleSmuggler abused Magento's own Style properties to slip code past the store's safeguards — a control blind to the channel it trusted.
- The fix exists; your browser may not have it yet
September 4, 2026 · 6 sources
The sixth exploited Chrome zero-day of 2026, and a fix that rolls out over weeks and applies only on restart: patched and protected are not the same day.
- The backup account was never only a backup account
September 3, 2026 · 4 sources
A 12-year-old PostgreSQL flaw turned the REPLICATION attribute — the one granted to a routine backup account — into code execution on the server.
- The data was compulsory, and there is no other city
September 2, 2026 · 3 sources
Everyone in a municipal file was legally obliged to be there. Compulsion is a stronger basis for an obligation than agreement.
- Three quarters of them had already left
September 1, 2026 · 3 sources
Only 18,000 of 75,000 affected were still customers. Most of the harm came from records nobody needed any more.
- The key was in the page source, so nothing had to be broken into
September 1, 2026 · 4 sources
An admin key served to every visitor in the site's own JavaScript. The harm came from joining fields that are harmless apart.
- A standalone system, and a major incident, in the same week
August 26, 2026 · 4 sources
Two official statements about one event, pulling in opposite directions and both probably true. They answer different questions.
- No timeline for restoration, which is the only number that mattered
August 25, 2026 · 4 sources
Manufacturing, order processing and shipping all stopped. The customer's exposure was set in a contract signed years earlier.
- A generator went dark for four days, and the reason was foreign policy
August 22, 2026 · 4 sources
The operator's exposure was decided by people who will never see its network diagram, on grounds unrelated to it.
- There is no gateway for the telephone
August 5, 2026 · 4 sources
AI voice phishing reached the largest funds in one week. Several blocked it, and what they had is the useful half.
- The attacker scales, and the defender is a town of 1,800
August 4, 2026 · 5 sources
Thirty water systems, one technique, and utilities with no security function to address advice to.
- Two hours from disclosure to exploitation, and a day from entry to encryption
July 22, 2026 · 3 sources
Both windows closed in the same month: the one before a flaw is used, and the one before an intrusion becomes a consequence.
- The model you downloaded is code you ran
July 16, 2026 · 3 sources
Models arrive through a channel that dependency scanning does not inspect, into the machines that hold everything.
- Six hundred fixes in one day, and the queue stopped being arithmetic
July 14, 2026 · 3 sources
Remediate everything critical in thirty days became arithmetically impossible, and the policy did not change.
- The ransom note was written by a model, and so was everything before it
July 9, 2026 · 3 sources
Every step was ordinary except the last: the counterparty in a negotiation may not be a person.
- 2,270 attacks a week, and not one decision you can make with it
June 30, 2026 · 3 sources
A figure that counts blocked scanning noise, quoted as a measure of threat. Nothing changes if it doubles.
- Two years without an update, one week inside, and nobody's idea of a target
June 26, 2026 · 3 sources
Software two years behind is rarely neglected. It is unowned, which is why it was also unmonitored.
- 86,000 of the same box, in 194 countries, all at once
June 24, 2026 · 3 sources
Nobody chose the monoculture. It is the sum of a hundred thousand individually correct purchases.
- Twelve million addresses, seven million passwords, two different problems
June 17, 2026 · 3 sources
Two exposures with different half-lives and different remedies, reported as one number.
- Nobody shared the code, and the account was taken anyway
May 20, 2026 · 3 sources
A relay forwards the one-time code within seconds. The most repeated piece of security advice describes a different attack.
- Most claims are not ransomware, they are misdirected payments
May 19, 2026 · 3 sources
Payment fraud accounts for 58–60% of cyber insurance claims by volume. Budgets are set against the other question.
- Four years, 500 organisations, and no need to change the lure
May 14, 2026 · 3 sources
A campaign documented in 2022 was still working in 2026 with its core intact. Techniques only evolve when they stop working.
- Manufacturing leads the target list because it can least afford to stop
May 12, 2026 · 3 sources
A stopped line costs a known amount per hour. That certainty is what an extortion business prices against.
- The most important door had no lock
April 28, 2026 · 4 sources
An authentication bypass in cPanel & WHM let unauthenticated attackers into the panel that runs every site on the server. CISA lists it as used in ransomware.
- They paid, and received a receipt for a deletion nobody can check
April 28, 2026 · 3 sources
Breached twice in a fortnight, then paid for shred logs. Deletion is a negative, and negatives cannot be demonstrated.
- Their staff, your access, nobody's joiner-leaver process
April 22, 2026 · 3 sources
Contractor staff hold the client's access while sitting outside its directory. Each party owns half of what revocation needs.
- Two banks, one supplier, and a leak site that gave it away
April 20, 2026 · 3 sources
Two competitors posted the same day with the same data. The shared dependency was revealed by the attackers' schedule.
- The consent granted once, and never looked at again
April 15, 2026 · 3 sources
A month dominated by OAuth abuse. A standing grant is implicit trust with a permanent credential, issued by whoever clicked.
- Negotiating with a name that did not exist last quarter
March 25, 2026 · 3 sources
A new extortion brand has no record of honouring anything, and rebranding runs in only one direction.
- When the breach is somebody else's, you still own the clock
March 20, 2026 · 3 sources
One compromised platform reaching many organisations splits the duty to notify from the facts needed to do it.
- When the target is the production line, the patient waits
March 18, 2026 · 3 sources
Attacks on manufacturing capacity harm people who appear in no file, and no breach statistic counts them.
- Ransomware against data nobody will buy
March 12, 2026 · 3 sources
Research data has no resale market and its publication embarrasses nobody. Only irreplaceability is left.
- All four of a country's telecoms, and nowhere to switch to
February 20, 2026 · 3 sources
A months-long espionage campaign reached every major operator in one market, which removes changing supplier as a response.
- No exploit, no malware: a valid login opened a national registry
February 15, 2026 · 3 sources
Stolen credentials reached a national bank account registry. Nothing in the intrusion was technically anomalous.
- The data protection authority was breached, and it was probably compliant
February 10, 2026 · 3 sources
Zero-days in a mobile device manager reached the European Commission and a national regulator. Compliance and security are not the same property.
- Ten minutes from entry to administrator, and the rota runs in hours
February 3, 2026 · 3 sources
An AI-assisted intrusion reached administrative control of a cloud environment in under ten minutes. Response is organised in hours.
- A hospital knew in August and could say what happened in January
January 27, 2026 · 3 sources
159 days between detecting an intrusion and being able to say what was taken. Notification cannot start until that second clock stops.
- A 9.4 in the single sign-on, and the patch did not help
January 21, 2026 · 4 sources
An authentication bypass in FortiCloud SSO, exploited from 21 January against devices that were already fully patched.
- The automation platform was the credential store nobody inventoried
January 7, 2026 · 4 sources
A CVSS 10.0 chain in n8n reached a forged administrator session. What it opened was every credential the platform had been given.
- 716,000 people, 120 brands, and a company none of them chose
January 7, 2026 · 4 sources
A telehealth platform behind 120 consumer brands was accessed across two days. Two irreconcilable totals are still in circulation.
By month
Reviewed 2026-09-01.