<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cybernetic Intern</title><description>Evidence-led cyber security writing for beginners, IT admins, SOC analysts, and security leaders. Every claim cited to a primary source.</description><link>https://cyberneticsintern.com/</link><language>en</language><item><title>The implant never connected to the attacker</title><link>https://cyberneticsintern.com/blog/bambootoken-mqtt-broker-c2/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/bambootoken-mqtt-broker-c2/</guid><description>BambooToken runs command and control over MQTT. The host connects to a broker, the operator connects to the same broker, and the two never meet.</description><pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate><category>THREAT-INTEL</category><category>technical-analysis</category></item><item><title>Publish first, verify later</title><link>https://cyberneticsintern.com/blog/rubygems-publish-first-verify-later/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/rubygems-publish-first-verify-later/</guid><description>RubyGems gave out publish-capable keys before confirming the email, and a CDN handed one user&apos;s key to another. Who did it turned out not to matter.</description><pubDate>Sun, 13 Sep 2026 09:00:00 GMT</pubDate><category>SUPPLY-CHAIN</category><category>incident-breakdown</category></item><item><title>The second entrance had no lock</title><link>https://cyberneticsintern.com/blog/cwe-288-alternate-path-cisco-citrix-kev/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/cwe-288-alternate-path-cisco-citrix-kev/</guid><description>CISA listed exploited CWE-288 authentication bypasses in Cisco Secure FMC and Citrix NetScaler on the same day. Neither vendor offers a workaround.</description><pubDate>Thu, 10 Sep 2026 09:00:00 GMT</pubDate><category>VULN</category><category>defensive-guide</category></item><item><title>The backdoor called itself chronyd</title><link>https://cyberneticsintern.com/blog/stylesmuggler-magento-cve-2026-75650/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/stylesmuggler-magento-cve-2026-75650/</guid><description>Adobe shipped an out-of-band hotfix for a CVSS 10.0 Magento zero-day after three days of exploitation. The implant beacons out shaped like NTP.</description><pubDate>Tue, 08 Sep 2026 02:00:00 GMT</pubDate><category>INCIDENT</category><category>threat-brief</category></item><item><title>You cannot rotate a driver&apos;s licence</title><link>https://cyberneticsintern.com/blog/idscan-nexus-driver-licence-leak/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/idscan-nexus-driver-licence-leak/</guid><description>A dark web service listed 153 million US and Canadian licence scans, including the infrared and ultraviolet captures used to prove they are genuine.</description><pubDate>Sun, 06 Sep 2026 15:00:00 GMT</pubDate><category>IDENTITY</category><category>incident-breakdown</category></item><item><title>Failing the key check was enough to get in</title><link>https://cyberneticsintern.com/blog/litellm-mcp-auth-bypass-cve-2026-59822/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/litellm-mcp-auth-bypass-cve-2026-59822/</guid><description>LiteLLM turned a failed key check into an empty identity, and that identity could reach MCP tools. CISA added CVE-2026-59822 to KEV on September 2, 2026.</description><pubDate>Sat, 05 Sep 2026 08:00:00 GMT</pubDate><category>AI-SEC</category><category>news-explainer</category></item><item><title>Changing a setting was the same as running code</title><link>https://cyberneticsintern.com/blog/papercut-ng-mf-zero-day-cve-2026-81578/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/papercut-ng-mf-zero-day-cve-2026-81578/</guid><description>PaperCut NG and MF are under active exploitation. Two flaws chain into pre-auth code execution, and the one scored lower is the one that mattered.</description><pubDate>Wed, 02 Sep 2026 18:30:00 GMT</pubDate><category>INCIDENT</category><category>technical-analysis</category></item><item><title>Microsoft blocked device code flow, probably not in your tenant</title><link>https://cyberneticsintern.com/blog/device-code-flow-phishing-entra-conditional-access/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/device-code-flow-phishing-entra-conditional-access/</guid><description>Security defaults block device code flow in new Entra tenants. The Conditional Access upgrade path does not include it, so older tenants stay open.</description><pubDate>Mon, 31 Aug 2026 09:00:00 GMT</pubDate><category>IDENTITY</category><category>defensive-guide</category></item><item><title>Six CVEs, two deadlines</title><link>https://cyberneticsintern.com/blog/kev-august-26-two-deadlines-privilege-escalation/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/kev-august-26-two-deadlines-privilege-escalation/</guid><description>CISA added six CVEs to KEV on August 26. Four trace to a published Talos report and got 14 days. Two appear in no research at all, and got three.</description><pubDate>Sat, 29 Aug 2026 13:35:00 GMT</pubDate><category>VULN</category><category>news-explainer</category></item><item><title>Two minutes, ten minutes, twenty minutes</title><link>https://cyberneticsintern.com/blog/tale-of-two-socs-red-team-detection/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/tale-of-two-socs-red-team-detection/</guid><description>CISA red-teamed two organisations at once with the same tradecraft. One never noticed. The other isolated three hosts in minutes off a medium alert.</description><pubDate>Fri, 28 Aug 2026 19:15:00 GMT</pubDate><category>DETECT</category><category>postmortem</category></item><item><title>The detection audit you can run in a week</title><link>https://cyberneticsintern.com/blog/detection-programme-audit-five-checks/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/detection-programme-audit-five-checks/</guid><description>Five checks that tell you whether your detections work, each producing evidence rather than a coverage number. No vendor needed, and none takes a quarter.</description><pubDate>Fri, 28 Aug 2026 09:00:00 GMT</pubDate><category>DETECT</category><category>defensive-guide</category></item><item><title>The perfect 10 that belongs to nobody</title><link>https://cyberneticsintern.com/blog/oracle-proxy-plugin-cve-2026-21962-kev/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/oracle-proxy-plugin-cve-2026-21962-kev/</guid><description>CISA added a CVSS 10.0 Oracle proxy flaw to KEV seven months after disclosure. The public exploitation evidence is thinner than the coverage suggests.</description><pubDate>Mon, 24 Aug 2026 22:30:00 GMT</pubDate><category>VULN</category><category>news-explainer</category></item><item><title>AI did not make ICS attacks possible. It made them ordinary.</title><link>https://cyberneticsintern.com/blog/ai-generated-exploit-scripts-siemens-s7/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/ai-generated-exploit-scripts-siemens-s7/</guid><description>Five US agencies say threat actors use AI to write exploit scripts for Siemens S7 PLCs. The advisory reports preparation, not compromise.</description><pubDate>Sun, 23 Aug 2026 16:00:00 GMT</pubDate><category>AI-SEC</category><category>threat-brief</category></item><item><title>The rescue email arrives before the breach is public</title><link>https://cyberneticsintern.com/blog/ransom-busters-fake-recovery-service/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/ransom-busters-fake-recovery-service/</guid><description>A firm called Ransom Busters offers to delete stolen data for $20,000 to $60,000. GuidePoint assesses it is the affiliate that took the data in the first place.</description><pubDate>Sat, 22 Aug 2026 16:30:00 GMT</pubDate><category>RANSOMWARE</category><category>threat-brief</category></item><item><title>A CVSS 10.0 you cannot patch</title><link>https://cyberneticsintern.com/blog/entra-id-cve-2026-69836-cloud-kev/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/entra-id-cve-2026-69836-cloud-kev/</guid><description>Microsoft fixed a CVSS 10.0 Entra ID flaw before disclosing it and says no customer action is needed. CISA added it to KEV anyway. Both are right.</description><pubDate>Fri, 21 Aug 2026 18:30:00 GMT</pubDate><category>CLOUD</category><category>news-explainer</category></item><item><title>The AI picked the targets. People did the breaking in.</title><link>https://cyberneticsintern.com/blog/autonomous-ai-campaign-cve-2026-33824/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/autonomous-ai-campaign-cve-2026-33824/</guid><description>Unit 42 documented an AI agent attacking unattended. The autonomous runs failed, the manual ones worked, and seven of eight target CVEs were already in KEV.</description><pubDate>Thu, 20 Aug 2026 21:26:00 GMT</pubDate><category>THREAT-INTEL</category><category>threat-brief</category></item><item><title>Ray&apos;s browser guard was one string comparison</title><link>https://cyberneticsintern.com/blog/ray-cve-2025-62593-browser-guard/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/ray-cve-2025-62593-browser-guard/</guid><description>CISA set an August 20, 2026 deadline for a Ray flaw whose fix shipped 271 days earlier. The guard it bypassed was a check on one header string.</description><pubDate>Wed, 19 Aug 2026 08:00:00 GMT</pubDate><category>AI-SEC</category><category>technical-analysis</category></item><item><title>Patched July 29, compromised by August 5</title><link>https://cyberneticsintern.com/blog/vcenter-cve-2026-59310-mass-exploitation/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/vcenter-cve-2026-59310-mass-exploitation/</guid><description>A directory traversal in the vCenter syslog server gave attackers root without authentication. QUIRSO tracked 361 victim IPs in 47 countries inside three days.</description><pubDate>Tue, 18 Aug 2026 07:30:00 GMT</pubDate><category>INCIDENT</category><category>incident-breakdown</category></item><item><title>A Mac with Screen Sharing on the internet is now a mining rig</title><link>https://cyberneticsintern.com/blog/macos-screen-sharing-cve-2026-65400/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/macos-screen-sharing-cve-2026-65400/</guid><description>CVE-2026-65400 lets an attacker authenticate to macOS Screen Sharing with no credentials. Exposed Macs are being rooted and turned into Monero miners.</description><pubDate>Sun, 16 Aug 2026 20:45:00 GMT</pubDate><category>VULN</category><category>news-explainer</category></item><item><title>The job offer was the attack: a Windows zero-day delivered by fake recruiters</title><link>https://cyberneticsintern.com/blog/lazarus-afd-zero-day-dream-job/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/lazarus-afd-zero-day-dream-job/</guid><description>Lazarus used a Windows kernel zero-day, CVE-2026-68820, to blind endpoint security after luring defence engineers with fake job offers.</description><pubDate>Sat, 15 Aug 2026 01:40:00 GMT</pubDate><category>THREAT-INTEL</category><category>threat-brief</category></item><item><title>Boil water notices, caused by a password change</title><link>https://cyberneticsintern.com/blog/water-utility-plc-internet-exposure/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/water-utility-plc-internet-exposure/</guid><description>The FBI and CISA report attackers changing IP addresses and passwords on exposed water sector PLCs, causing pressure loss, flooding and manual operations.</description><pubDate>Sat, 15 Aug 2026 01:30:00 GMT</pubDate><category>INCIDENT</category><category>defensive-guide</category></item><item><title>A perfect 10: the Metabase flaw that hands over every connected database</title><link>https://cyberneticsintern.com/blog/metabase-sql-injection-cve-2026-72898/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/metabase-sql-injection-cve-2026-72898/</guid><description>CVE-2026-72898 lets an unauthenticated attacker reach admin on Metabase and read every connected database credential. Metabase confirms active exploitation.</description><pubDate>Fri, 14 Aug 2026 18:20:00 GMT</pubDate><category>VULN</category><category>news-explainer</category></item><item><title>Gunra ransomware: when the attacker owns your login page</title><link>https://cyberneticsintern.com/blog/gunra-ransomware-advisory/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/gunra-ransomware-advisory/</guid><description>A six-agency advisory details Gunra ransomware: Conti-derived, RaaS, double extortion. Its way in is vulnerabilities that have been on the KEV list since 2025.</description><pubDate>Fri, 14 Aug 2026 17:40:00 GMT</pubDate><category>RANSOMWARE</category><category>threat-brief</category></item><item><title>A worm got into npm through one maintainer&apos;s account</title><link>https://cyberneticsintern.com/blog/shai-hulud-npm-worm-keyv/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/shai-hulud-npm-worm-keyv/</guid><description>On August 4, 2026 a self-replicating worm hijacked the keyv npm package family, stealing developer credentials and using them to infect hundreds more packages.</description><pubDate>Fri, 14 Aug 2026 17:10:00 GMT</pubDate><category>SUPPLY-CHAIN</category><category>incident-breakdown</category></item><item><title>Your AI prototyping tool is now internet-facing infrastructure</title><link>https://cyberneticsintern.com/blog/langflow-rce-ai-tooling-kev/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/langflow-rce-ai-tooling-kev/</guid><description>CVE-2026-9198 lets an unauthenticated attacker run code on default IBM Langflow deployments. CISA added it to the exploited list on August 4, 2026.</description><pubDate>Fri, 14 Aug 2026 16:30:00 GMT</pubDate><category>AI-SEC</category><category>news-explainer</category></item><item><title>A Cisco firewall flaw is being exploited, and there is no workaround</title><link>https://cyberneticsintern.com/blog/cisco-asa-ftd-vpn-dos-kev/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/cisco-asa-ftd-vpn-dos-kev/</guid><description>CVE-2026-20349 lets an unauthenticated attacker reboot Cisco ASA and FTD firewalls via the VPN service. Cisco confirms exploitation and offers no workaround.</description><pubDate>Fri, 14 Aug 2026 10:00:00 GMT</pubDate><category>VULN</category><category>news-explainer</category></item><item><title>Payroll pirates: an eight-year-old fraud that MFA did not stop</title><link>https://cyberneticsintern.com/blog/payroll-pirate-storm-2755/</link><guid isPermaLink="true">https://cyberneticsintern.com/blog/payroll-pirate-storm-2755/</guid><description>Storm-2755 is redirecting Canadian salaries by hijacking Microsoft 365 sessions and editing Workday. The FBI described this same playbook back in 2018.</description><pubDate>Fri, 14 Aug 2026 09:00:00 GMT</pubDate><category>IDENTITY</category><category>threat-brief</category></item></channel></rss>