Signals & intelligence

Latest security news

What changed, why it matters, and what to do about it. Written for people who have to act on it before lunch.

Threat ReportAug 27, 2026 · 4 min read

New ransomware strain targeting healthcare infrastructure

Operators are chaining stolen VPN credentials with rapid lateral movement across flat clinical networks. Segment first, then rehearse the restore.

Cyber Security Space desk

Policy & Defense

CISA issues advisory on critical ICS vulnerabilities

Multiple industrial controllers ship with hardcoded credentials and unauthenticated firmware upload paths. Inventory exposure before patch planning.

Aug 26, 2026 · 3 min read

Vulnerabilities

Zero-day in widely used VPN client actively exploited

Exploitation predates the vendor advisory. Assume compromise on unpatched appliances and rotate every credential that touched them.

Aug 25, 2026 · 5 min read

Threat Report

Nation-state group shifts tactics to supply chain attacks

Build systems and package registries are now the preferred entry point. Signing and provenance are the controls that actually move the needle.

Aug 22, 2026 · 6 min read

Research

Identity is the new perimeter — and attackers know it

Session token theft and MFA fatigue campaigns continue to outpace malware-based access. Phishing-resistant MFA is no longer optional.

Aug 19, 2026 · 5 min read

Research

AI supply chain: model registries as an attack surface

Pickled model artefacts and unsigned pipelines create silent code execution paths inside ML platforms.

Aug 15, 2026 · 7 min read

Stay ahead of threats.

Get this week's signals by email.

A single Monday email: what broke, what got exploited, and what to patch first.