Device code phishing didn't need new code — it needed a legitimate Microsoft login flow- 238
May 11, 2026
A technique security researchers first observed in isolated red-team and espionage use back in 2020 has,
An unclaimed breach at a critical drug-packaging supplier tests healthcare's newest fault line- 234
May 12, 2026
West Pharmaceutical Services, one of the world's largest suppliers of components for injectable medicine delivery,
When a ransomware gang gets ransomware'd: what The Gentlemen's leak reveals about the RaaS economy- 232
May 10, 2026
In early May 2026, one of the most prolific ransomware-as-a-service operations running today discovered
WannaCry at nine years: the day a stolen NSA tool became a lesson in negligence- 231
May 12, 2026
Nine years on, WannaCry remains the starkest illustration of a principle this publication returns to often: the
CISA's CI Fortify quietly concedes that eviction alone has failed- 222
May 6, 2026
The Cybersecurity and Infrastructure Security Agency has a new answer to a question it has spent three
Poland's water utilities become the latest target in Russia's shadow campaign- 218
May 7, 2026
Poland's domestic intelligence service has confirmed what regional cybersecurity researchers had already begun tracking: hackers
Beijing's Deniable Army: A Breach in Rome and a Warrant in Washington- 216
May 10, 2026
Two stories surfaced within days of each other in the spring of 2026, on opposite sides of
Belarus's Oldest Digital Weapon Returns to Kyiv- 215
June 28, 2026
Nearly a decade into its operational life, the Belarus-aligned threat group known as Ghostwriter has not
MuddyWater's Double Game: Iran's Cyber Unit Trades Precision for Reach- 213
June 28, 2026
An intrusion that looks like a ransomware shakedown and a breach wave spanning nine countries on four
Proprietary by Design: The Ransomware Ecosystem's Shift Toward Custom Tooling- 207
June 17, 2026
The commodity toolchain is becoming a liability. Rclone gets flagged. Cobalt Strike beacon patterns get detected. The