Dispatches. Practitioner-first cybersecurity coverage.
Independent reporting on AI security, SOC automation, identity, data and the adversarial edge. Every piece is rewritten in-house and credits every source — never a press-release copy.
Archive
Page 2 of 5-
Vendor Cisco SD-WAN Controllers Hit by 10.0 Auth Bypass — Active Exploitation Confirmed
A maximum-severity authentication bypass in Cisco Catalyst SD-WAN Controller (CVE-2026-20182, CVSS 10.0) lets unauthenticated attackers gain administrative control over the SD-WAN fabric via UDP 12346. Cisco has confirmed limited in-the-wild exploitation; the vulnerable component has now produced two 10.0-rated bypasses in three years.
-
AI Security OpenAI's Daybreak Hands Defenders a Frontier Vulnerability Model
OpenAI launched Daybreak, a defensive cyber initiative pairing three GPT-5.5 variants with Codex Security to give vendors access to AI vulnerability discovery, threat modeling, and patch validation. The release confirms that frontier labs now treat vuln-finding capability as gated infrastructure rather than a public product.
-
AI Security Anthropic's Mythos and the Asymmetry Problem in AI Vulnerability Discovery
Anthropic held back its Claude Mythos Preview from public release because it finds software vulnerabilities at a rate defenders cannot match in their patch cycles. Bruce Schneier argues the deeper concern isn't software at all — it's every other rule-based system AI can now mine for exploits.
-
Threat Intel Active Exploitation of Ivanti EPMM Forces a 72-Hour Federal Patch Window
A high-severity flaw in Ivanti's on-prem mobile device management platform, CVE-2026-6973, hit CISA's Known Exploited Vulnerabilities list with one of the tightest deadlines of the year. The exploitation requires admin authentication — which means previously compromised credentials are the live attack path.
-
Vulnerabilities Critical cPanel Auth Bypass CVE-2026-41940 Hits Asia-Pacific Governments and MSPs Within 24 Hours of Disclosure
A critical authentication-bypass in cPanel and WHM was weaponized within a day of public disclosure, with multiple operators using AdaptixC2, Mirai variants, and Sorry ransomware against government targets in Southeast Asia and managed service providers across five countries.
-
Threat Intel Scattered Spider's 'Tylerb' Pleads Guilty in California, Faces 22 Years for SIM-Swap Spree That Defined the Crew
A 24-year-old Scottish national admitted to wire-fraud conspiracy and aggravated identity theft tied to the 2022 phishing campaign that put Scattered Spider on the map, the second senior member to plead guilty in US federal court and a useful read on how durable the loose-knit crew remains a year after its first conviction.
-
Policy CISA Drops Eight Live-Fire CVEs Into KEV With April–May Deadlines, Three of Them Cisco SD-WAN
Federal civilian agencies have less than two weeks to remediate eight newly weaponized CVEs added to CISA's Known Exploited Vulnerabilities catalog — three of them in Cisco Catalyst SD-WAN Manager, plus reactivated bugs in PaperCut, Zimbra, Quest KACE, JetBrains, and Kentico that are now tied to nation-state and ransomware operators.
-
AI Agents Flowise's Third Live-Fire RCE: 12,000 AI-Agent Builders Exposed to a CVSS 10.0 Code-Injection Bug
A maximum-severity code-injection flaw in Flowise's CustomMCP node, CVE-2025-59528, is being exploited from a single Starlink IP across more than 12,000 internet-facing instances — the third in-the-wild Flowise vulnerability in seven months.
-
Identity Stolen Session Cookies Now Outpace Stolen Passwords — and 31% of Them Walk Past MFA
Recorded Future's 2025 identity-threat data, surfaced this week by Dark Reading, indexed 276 million stolen credentials carrying active session cookies — about 31% of all malware-sourced creds, each one effectively pre-authenticated. Identity is the perimeter, and the multi-factor prompt is no longer the chokepoint defenders thought it was.