CYBERNETIC INTERN · WRITING
Cybernetic
Intern
Security writing from someone who does the work. Incidents, vulnerabilities and defences: explained plainly first, then in technical depth, with every claim cited to a primary source.
EVERY EXTERNALLY VERIFIABLE CLAIM IS CITED. PRIMARY SOURCES FIRST.
The implant never connected to the attacker
BambooToken runs command and control over MQTT. The host connects to a broker, the operator connects to the same broker, and the two never meet.
READ ↗MORE
- Publish first, verify laterRubyGems gave out publish-capable keys before confirming the email, and a CDN handed one user's key to another. Who did it turned out not to matter.READ ↗
- The second entrance had no lockCISA listed exploited CWE-288 authentication bypasses in Cisco Secure FMC and Citrix NetScaler on the same day. Neither vendor offers a workaround.READ ↗
- The backdoor called itself chronydAdobe shipped an out-of-band hotfix for a CVSS 10.0 Magento zero-day after three days of exploitation. The implant beacons out shaped like NTP.READ ↗
- You cannot rotate a driver's licenceA dark web service listed 153 million US and Canadian licence scans, including the infrared and ultraviolet captures used to prove they are genuine.READ ↗
- Failing the key check was enough to get inLiteLLM turned a failed key check into an empty identity, and that identity could reach MCP tools. CISA added CVE-2026-59822 to KEV on September 2, 2026.READ ↗
- Changing a setting was the same as running codePaperCut NG and MF are under active exploitation. Two flaws chain into pre-auth code execution, and the one scored lower is the one that mattered.READ ↗
- Microsoft blocked device code flow, probably not in your tenantSecurity defaults block device code flow in new Entra tenants. The Conditional Access upgrade path does not include it, so older tenants stay open.READ ↗
- Six CVEs, two deadlinesCISA added six CVEs to KEV on August 26. Four trace to a published Talos report and got 14 days. Two appear in no research at all, and got three.READ ↗
- Two minutes, ten minutes, twenty minutesCISA red-teamed two organisations at once with the same tradecraft. One never noticed. The other isolated three hosts in minutes off a medium alert.READ ↗
- The detection audit you can run in a weekFive checks that tell you whether your detections work, each producing evidence rather than a coverage number. No vendor needed, and none takes a quarter.READ ↗
- The perfect 10 that belongs to nobodyCISA added a CVSS 10.0 Oracle proxy flaw to KEV seven months after disclosure. The public exploitation evidence is thinner than the coverage suggests.READ ↗
- AI did not make ICS attacks possible. It made them ordinary.Five US agencies say threat actors use AI to write exploit scripts for Siemens S7 PLCs. The advisory reports preparation, not compromise.READ ↗
- The rescue email arrives before the breach is publicA firm called Ransom Busters offers to delete stolen data for $20,000 to $60,000. GuidePoint assesses it is the affiliate that took the data in the first place.READ ↗
- A CVSS 10.0 you cannot patchMicrosoft fixed a CVSS 10.0 Entra ID flaw before disclosing it and says no customer action is needed. CISA added it to KEV anyway. Both are right.READ ↗
- The AI picked the targets. People did the breaking in.Unit 42 documented an AI agent attacking unattended. The autonomous runs failed, the manual ones worked, and seven of eight target CVEs were already in KEV.READ ↗
- Ray's browser guard was one string comparisonCISA set an August 20, 2026 deadline for a Ray flaw whose fix shipped 271 days earlier. The guard it bypassed was a check on one header string.READ ↗
- Patched July 29, compromised by August 5A directory traversal in the vCenter syslog server gave attackers root without authentication. QUIRSO tracked 361 victim IPs in 47 countries inside three days.READ ↗
- A Mac with Screen Sharing on the internet is now a mining rigCVE-2026-65400 lets an attacker authenticate to macOS Screen Sharing with no credentials. Exposed Macs are being rooted and turned into Monero miners.READ ↗
- The job offer was the attack: a Windows zero-day delivered by fake recruitersLazarus used a Windows kernel zero-day, CVE-2026-68820, to blind endpoint security after luring defence engineers with fake job offers.READ ↗
- Boil water notices, caused by a password changeThe FBI and CISA report attackers changing IP addresses and passwords on exposed water sector PLCs, causing pressure loss, flooding and manual operations.READ ↗
- A perfect 10: the Metabase flaw that hands over every connected databaseCVE-2026-72898 lets an unauthenticated attacker reach admin on Metabase and read every connected database credential. Metabase confirms active exploitation.READ ↗
- Gunra ransomware: when the attacker owns your login pageA six-agency advisory details Gunra ransomware: Conti-derived, RaaS, double extortion. Its way in is vulnerabilities that have been on the KEV list since 2025.READ ↗
- A worm got into npm through one maintainer's accountOn August 4, 2026 a self-replicating worm hijacked the keyv npm package family, stealing developer credentials and using them to infect hundreds more packages.READ ↗
- Your AI prototyping tool is now internet-facing infrastructureCVE-2026-9198 lets an unauthenticated attacker run code on default IBM Langflow deployments. CISA added it to the exploited list on August 4, 2026.READ ↗
- A Cisco firewall flaw is being exploited, and there is no workaroundCVE-2026-20349 lets an unauthenticated attacker reboot Cisco ASA and FTD firewalls via the VPN service. Cisco confirms exploitation and offers no workaround.READ ↗
- Payroll pirates: an eight-year-old fraud that MFA did not stopStorm-2755 is redirecting Canadian salaries by hijacking Microsoft 365 sessions and editing Workday. The FBI described this same playbook back in 2018.READ ↗