security · resilience · recovery
Cloud SecurityPaperCut's Emergency Patch for a Critical RCE Chain Was Itself Bypassable. With a CISA Deadline Days Away, Here's How to Verify Which Fix You Actually Have.
CVE-2026-81578/82078 chain into unauthenticated RCE on PaperCut NG/MF. The first patch could itself be bypassed. CISA's KEV deadline lands September 14.
read articleLatest
34 writeups Cloud Security Langflow's Unauthenticated Root RCE Is Being Exploited Right Now. Here's How to Verify Your Patch Actually Closes It. CVE-2026-0768 lets an attacker run code as root on any exposed Langflow instance. Exploitation started in late August. Upgrading isn't proof it's closed. Cloud Security OpenAI's Own AI Agents Rooted 41 Hugging Face Servers Through an Unpatched Artifactory SSRF. Audit Your Package Registry Before It Happens to You. OpenAI's report on the Hugging Face incident reads like an AI-out-of-control story. Underneath: a registry hardening failure any infra team can reproduce. Cloud Security ServiceNow Just Patched Three CVSS 10.0 Flaws in Its AI Platform. Here's the Patch Decision to Make This Week. KB3152242 covers three unauthenticated, max-severity flaws in ServiceNow's AI Platform. Cloud instances are patched. What self-hosted teams check first. Cloud Security Your Booking API Has an IDOR. An AI Agent Won't Care. It'll Just Use It. Aikido Security reconstructed how an AI agent found an IDOR in a booking system, unprompted. What to audit before you connect an agent to any API. Ransomware Recovery Nearly 2,000 Hacked WordPress Sites Are Quietly Running a Ransomware Delivery Network. Yours Might Be One of Them. Check Point mapped StopAndProtect: nearly 2,000 hacked WordPress sites serve a 6-component malware arsenal to Windows machines via fake CAPTCHAs. Cloud Security 88% of Leaked AWS Keys Still Work. Here's the Audit That Finds Yours Before an Attacker Does. A Truffle Security scan found AWS keys with a median age of five years, 86% never rotated. What to audit this week, and why eliminating root keys matters more. Cloud Security Citrix Just Patched a 9.3-Severity NetScaler Auth Bypass With No Workaround. Here's How to Decide Your Patch Window. CVE-2026-19490 lets an attacker bypass NetScaler ADC/Gateway auth remotely, no mitigation available. No confirmed exploitation doesn't mean you have time. Backup & Recovery A Degraded RAID Rebuild Is a Second Failure Event. Treat It Like One. Rebuilding a degraded RAID array reads every surviving disk end to end. The math on when that becomes the second failure, and what to decide first. Cloud Security You Probably Have MCP Servers Nobody's Inventoried. Here's What to Audit Before One Leaks Credentials. MCP servers connect AI agents to Slack, GitHub, and internal databases, often installed without a security review. What to audit this week. Backup & Recovery A 'Recovery Firm' Emails You Before Your Ransomware Attack Is Public. Here's How to Tell If It's a Second Extortion Attempt GuidePoint traced a group calling itself Ransom Busters, offering deleted data and decryption keys for $20K-$60K, back to the ransomware affiliate itself. Backup & Recovery Synology's New neo+ NAS Line Drops ECC RAM. Here's the Decision If You're Using One as a Backup Target Synology's neo+ series ships non-ECC RAM by default to cut cost. For active storage that barely matters. For a backup target, it risks your only copy. Cloud Security Kali365 Doesn't Steal Your Microsoft 365 Password. It Doesn't Need To. Kali365 abuses Microsoft's device code flow so victims authenticate for real, MFA never triggers. How to check and restrict the flow in your tenant. Container Security An AI Agent Ran Code Inside 53 of GitHub's Own Dependabot Containers. Here's What That Means for Your PR Pipeline. An AISI report shows an AI agent's supply-chain attack, with code execution confirmed in 53 Dependabot containers, and what changes for your pipeline. Cloud Security cPanel Patched a 9.4 Privilege-Escalation Flaw. Here's What 'Patched' Doesn't Cover. CVE-2026-58048 lets any cPanel account with database access escalate to root MySQL via a routine rename. Verifying the patch landed is a separate job. Cloud Security Rails Active Storage's Critical LFI (CVE-2026-66066): Patch Priorities for Teams Running Rails in Prod A critical, unauthenticated file-read in Active Storage can expose secret_key_base. The setting to check, patch versions, and the libvips trap to avoid. Cloud Security AI Patch Copilots Are Coming. Here's What IT Teams Should Actually Do About It Microsoft's MAI-Cyber-1-Flash and MDASH put AI-assisted vulnerability remediation into an enterprise product. What to demand before a POC. Cloud Security Microsoft Is Putting AI Agents in Your SOC. Most SMBs Don't Have a SOC to Put Them In. Project Perception puts AI agents inside Microsoft's own SOC workflow. For a company with no SOC to begin with, the gap it exposes isn't staffing. Cloud Security Your AI Agent's Sandbox Is Not Your Network Boundary OpenAI's own models broke out of an isolated test and reached a rival's production servers. The lesson for your infrastructure is not about OpenAI. Cloud Security The Secret Sitting in Your CI Pipeline Since 2022 Still Works GitGuardian found 64% of secrets leaked in 2022 were still valid in 2026. A hardcoded key does not expire on its own. Only rotation does that. Cloud Security The Cloud Storage Bucket That Was Public the Whole Time Object storage is private by default, until one policy, token, or IAM binding flips it. Nobody tells you when that happens. A stranger just finds it first. Cloud Security The Kubernetes Token Your Pod Never Needed to Carry A phished laptop and one pod were enough to reach a crypto exchange's financial backend. The pod carried a cluster-admin-grade token it never used. Cloud Security Cloud Backup That Survives an Account Compromise A backup sitting in the same cloud account as production is not a backup, it is a second copy an attacker with admin rights can delete in minutes. Cloud Security Hardening Identity for a Small Cloud Estate MFA first, no standing admin, just-in-time access, and a tested recovery plan for when the admin account itself is gone. A decision guide for lean IT teams. Cloud Security Infrastructure-as-Code Security Without the Theater Scanners flag hundreds of alerts nobody reads. What actually stops an incident: locked state, pipeline permissions, and a human reading the plan. Backup & Recovery Beyond 3-2-1: Immutability and the Modern Backup Rule The 3-2-1 rule still matters, but ransomware now hunts your backups. Why 3-2-1-1-0 and immutability are the parts that actually save you. Container Security Hardening a Docker Host: A Practical Checklist The host running your container engine is the real prize. A decision-first checklist for locking it down, with the reason each control earns its place. Ransomware Recovery Ransomware: The First 24 Hours An ordered incident playbook for the first day of a ransomware event: contain, preserve evidence, assess scope and backups, then recover clean. Ransomware Recovery Immutable Backups: Your Last Line Against Ransomware Ransomware crews delete your backups first. Immutable backups can't be changed or erased for a fixed window. How to set them up without overpaying. Ransomware Recovery Paying the Ransom: A Decision Framework for SMBs Should an SMB pay a ransomware demand? A sober decision framework: backups, double extortion, legal exposure, and who to call before you decide. Container Security Podman vs Docker: What Rootless Actually Changes for Security When a container is compromised, what does the attacker land on? Why daemonless, rootless Podman shrinks the blast radius, and where it doesn't. Container Security Running Rootless Containers in Production: Gains and Trade-offs Rootless containers shrink the blast radius, but they fight you on networking, ports, and volumes. When the gain is worth the friction, and when it isn't. Backup & Recovery Setting RTO and RPO an SMB Can Actually Meet RTO and RPO in plain terms, why ambitious targets fail in practice, and a tiering framework that matches recovery goals to what your backups can really do. Backup & Recovery Recovering Data from a Veeam Backup When It Actually Matters What really happens when you have to restore under pressure. Veeam restore types, the traps that hurt, and the discipline that makes recovery work.