Offboarding Needs a Last-Door Receipt
CrowdSec revoked a departing employee’s core access but deliberately left GitHub open for three more days. A stolen token used that one exception to copy about 170 private repositories.
Cybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
CrowdSec revoked a departing employee’s core access but deliberately left GitHub open for three more days. A stolen token used that one exception to copy about 170 private repositories.
Cisco fixed an actively exploited flaw in Identity Services Engine. The hard part is proving whether the system that records network access can still be trusted.
Cisco fixed an email-parsing flaw already used in attacks. Teams should patch every gateway, then investigate from logs the gateway could not rewrite.
Revolut released sensitive customer records after fraudulent requests arrived from a legitimate government agency email domain. The failure offers a practical lesson for every team that handles official demands for data.
Check Point has fixed two critical flaws in VPN certificate handling. The useful response is to patch every affected gateway, verify the fix on the running nodes, and keep threat claims tied to evidence.
GitLab fixed a flaw that let an unauthenticated visitor read server files on affected self-managed installations. Patch promptly, then use a concrete secret map to decide what evidence to preserve and which credentials may need replacing.
Researchers linked a May flood of RubyGems packages to agents being tested by OpenAI. The practical lesson is to cap every agent run by external effects, not by prompt or task label.
Cisco has confirmed active exploitation of a Secure Firewall Management Center flaw that can give a remote attacker root access. The hotfix closes the route, but operators also need to check the earlier exposure window and preserve an incident record.
Magento stores were compromised through an unpatched flaw even while running current security updates. Here is how to separate blocking the next request from investigating the first one.
Nearly 22,000 Exchange servers were still exposed after a fix shipped. The practical problem is bigger than one patch: teams must prove the running build, support entitlement, and replacement path together.
Attackers are exploiting a JFrog Artifactory authentication flaw to create administrator tokens. Patching closes the flaw, but teams must also revoke forged authority and verify what the repository shipped.
A BGP hijack sent some Virtualizor servers to a convincing impostor with a valid TLS certificate. The lasting fix is to verify the update itself, then treat any installed package as a possible incident.
CISA used similar red-team methods against two critical-infrastructure organisations. One security team acted within minutes while another lost the real warnings among routine noise.
A Citrix NetScaler flaw moved from a denial-of-service bulletin to active exploitation and a public remote-code-execution analysis. Here is how to patch the gateway, preserve evidence, and check the trust behind it.
ServiceNow fixed three maximum-severity flaws that could be reached without signing in. The urgent work is patching, but the durable lesson is to map every action, identity, and integration the platform can reach.
PaperCut released a second emergency patch after its first response was bypassed. Here is how to restrict access, patch every server, investigate the earlier window, and prove the fix is actually running.
A Gitea flaw is being exploited after turning ordinary repository access into commands on the server. Here is how to patch, investigate, and rebuild trust in the code and credentials that server could reach.
miniOrange fixed two WordPress login flaws, but six paid editions sat outside the public advisory. Here is how to find the real version, patch it, and check what happened before the fix.
Apple sent mercenary-spyware warnings across 110 countries, and investigators saw a record response. Here is how to verify the alert, reduce exposure, protect other people, and get expert help without destroying useful evidence.
A poisoned Rust package disappeared quickly, but code compiled during that window could have exposed developer and CI credentials. Here is how to check the right evidence and rebuild trust.
VMware fixed a critical vCenter flaw, but researchers found persistent access on hundreds of systems. Here is how to separate patching from recovery.
The White House has ordered a federal program for supervised private cyber operations against foreign criminal groups. The useful question is whether its still-unwritten rules can keep targeting, authority, evidence, and accountability inside clear boundaries.
Attackers began testing a critical Adobe Commerce account-takeover flaw soon after the August patch appeared. The useful lesson is how to prove an isolated patch reached every store node without mistaking deployment activity for protection.
CISA now links a patched SharePoint Server flaw to ransomware campaigns. Here is how to separate patching, exposure review, and incident response without turning every server into a crisis.
Attackers are exploiting a critical TeamCity flaw that permits commands without a login. Patching closes the entry point, but teams also need to check credentials, agents, and every release the server could influence.
Attackers are exploiting an authentication-bypass flaw in N-able N-central. The lesson for developers and platform teams is not only to patch, but to treat every remote-management console as part of the application threat model.
Explore the fundamentals of incident response and how developers can play a key role in minimizing damage from security incidents.