Category: Application Security

  • More Bugs, More Noise, More Pressure

    Vulnerability management has a math problem. In 2024, the CVE Program published 40,077 vulnerability records. In 2025, that figure climbed to 48,244. By the end of the second quarter of 2026, another 35,872 records had already been published, with Q2 alone accounting for 20,709 CVEs compared with 15,163 during Q1. Those figures describe a disclosure…

  • Printers, Cameras, BMCs: The Endpoints Your SOC Never Sees

    Enterprise security programs tend to concentrate on the systems that generate the most visible risk: user workstations, servers, cloud workloads, identity providers, and core network infrastructure. Those systems receive endpoint detection, vulnerability scanning, centralized logging, configuration management, and routine incident-response coverage. Yet the same environment can contain hundreds or thousands of devices that sit outside…

  • Microsoft September 2026 Patch Tuesday Fixes 973 Vulnerabilities, Including Two Exploited Zero-Days

    Microsoft’s September 2026 Patch Tuesday addresses 973 vulnerabilities across Windows, Microsoft Office, SQL Server, Exchange Server, SharePoint Server, Azure, and developer tools. Two vulnerabilities are confirmed to have been exploited as zero-days, making them immediate patching priorities despite both carrying an Important severity rating. The scale of the release significantly exceeds August’s 400 vulnerabilities and…

  • Code, Exploit, Patch: AI Agents Now Work Both Sides of Cybersecurity

    AI coding tools started with a fairly narrow promise: help developers write software faster. Early systems completed functions, suggested syntax, generated tests, and explained unfamiliar code. That framing is already becoming outdated. Modern coding agents can inspect entire repositories, execute commands, interact with development tools, test their own output, search external information, maintain context across…

  • What Happens When Extortion Infrastructure Has No Single Point of Failure?

    For years, ransomware disruption had clear technical targets. Investigators could seize servers, sink domains, remove leak sites, or take control of negotiation portals. Those actions could break parts of the criminal operation and force operators to rebuild. DeadLock shows a different design. Its extortion process spreads key functions across blockchain services, encrypted messaging, local HTML…

  • Netizen: Monday Security Brief (8/31/2026)

    Today’s Topics: PaperCut Zero-Days Turn Trusted Print Servers Into a Pre-Auth RCE Path PaperCut entered emergency-response mode in late August after confirming active exploitation against PaperCut NG and PaperCut MF servers. What first appeared as a single zero-day developed into a two-vulnerability attack chain capable of giving an unauthenticated remote attacker code execution inside the…

  • SynkLoader: Inside a Loader Built for Credential Capture, Proxying, and Remote Control

    SynkLoader is a newly identified modular Windows malware family that turns a simple helpdesk impersonation into a full access chain. The operator can profile a host, create persistence, steal a user’s Windows password, proxy traffic through the infected system, run PowerShell commands, and take remote control of the active desktop. Much of the follow-on code…

  • Why Audit Trails Matter More Than Security Teams Think

    A threat actor can use legitimate credentials, approved administrative tools, trusted cloud services, and normal network paths without ever dropping an obvious piece of malware. In that kind of intrusion, the audit trail may be the only record showing that legitimate access became malicious activity. Security programs tend to treat audit logging as foundational infrastructure…

  • Netizen: Monday Security Brief (8/24/2026)

    Today’s Topics: 9,308 Live AWS Keys Expose a Persistent Cloud Identity Problem Publicly exposed cloud credentials are often treated as a code hygiene problem: a developer commits a key, a scanner finds it, the key gets removed from the repository, and the incident appears closed. New research from Truffle Security shows why that model is…

  • Inside the Active Threat Targeting Siemens S7 PLCs Across U.S. Critical Infrastructure

    A new U.S. government warning has put one of industrial automation’s most widely deployed controller families at the center of an active cyber campaign. The concern is not limited to vulnerable software sitting somewhere inside a plant network. The targeted devices can directly control pumps, valves, motors, production lines, safety processes, and other equipment whose…