Blog

  • When Big Events Meet Bigger Threats: Securing the 2026 Playing Field

    This week’s roundup circles a common theme: the security choreography behind the events and infrastructure we tend to take for granted. From stadium-scale readiness for global sporting spectacles to the quiet takedown of servers powering state-backed cyberattacks, these items are a reminder that “preparedness” is less a moment than a long, unglamorous process. Here’s our take on each.

    CISA’s overview of its World Cup 2026 work leans on full-scale exercises and multi-jurisdiction coordination, and the interesting subtext is scale: a tournament spread across dozens of host cities means security can’t be centralized—it has to be rehearsed locally and stitched together federally. The framing here matters because it treats the World Cup as a distributed-risk problem rather than a single venue to defend. Read the agency’s summary Preparing for the World Stage.

    A companion piece emphasizes the fan-facing side—keeping the experience “safe, seamless” for communities hosting matches. It’s worth noting the deliberate blend of security and hospitality language: the goal isn’t just to prevent incidents but to make the protection invisible, which is arguably the hardest bar to clear. See Securing the American Experience.

    On the more technical front, CISA highlights OpenEoX and better vulnerability management, tackling a chronically underappreciated issue: end-of-life software. The “the end is just the beginning” framing captures a real pain point—products stop getting patches long before organizations stop running them, and standardizing how that lifecycle data is communicated could quietly close a lot of gaps. Details in Enhanced Vulnerability Management with OpenEoX.

    The Super Bowl LX writeup rounds out the physical-event trio, foregrounding partnerships and resilience. Read alongside the World Cup material, it suggests these marquee events increasingly serve as recurring stress tests for the same regional coordination muscles—useful, because the lessons should compound year over year rather than reset each time. More in Super Bowl LX.

    Finally, the standout enforcement story: Dutch authorities reportedly seized 800 servers and arrested two hosting-company operators tied to infrastructure used for cyberattacks and influence operations. What makes this notable is the target—not the attackers themselves, but the “bulletproof”-style hosting layer that enables them, a lineage traced back to previously sanctioned providers. Going after the plumbing is harder to pull off but potentially far more disruptive. Full reporting from Brian Krebs: Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks.

  • Weekly Security Roundup: ICS Advisories Pile Up, AI’s Double Edge, and Cybercrime Reckonings

    This week’s ingest is heavy on industrial control system (ICS) advisories, but the through-line is broader: attackers keep finding leverage in the seams of our infrastructure and tooling, whether that’s a PLC compiler, an AI support bot, or a “residential proxy” that turns out to be a botnet. Below, our take on the items worth your attention, with sources linked for the full details.

    OpenPLC v3 arbitrary code execution. A vulnerability that turns file-write access into native code execution “through the normal OpenPLC program compilation process” is a reminder that build and compile pipelines are attack surface, not neutral plumbing. Open-source control software runs quietly in a lot of places; keep an eye on your deployments. Read the CISA advisory.

    The language of AI could reshape human speech. Bruce Schneier flags a subtle cultural risk: LLMs are trained on written and scripted language, missing the “vast majority of speech” that happens face to face. As we increasingly talk like the machines that learned to talk like us, we risk a feedback loop that flattens linguistic diversity. A rare non-vulnerability item here, and a worthwhile long view. Read Schneier’s post.

    Felons and fraudsters behind an offensive-security startup. Brian Krebs digs into a company dangling millions for zero-days that’s reportedly run by convicted felons with a history of fake intelligence firms. The zero-day acquisition market has always had a trust problem; this is a vivid case study in why provenance matters when someone’s buying the keys to widely used software. Read the KrebsOnSecurity investigation.

    Hitachi Energy PROMOD V ships credentials in the clear. An insecure-HTTP-transmission flaw enabling credential theft or session hijacking in energy-planning software is a basic hygiene failure with serious downstream implications. Encryption in transit should be table stakes for anything touching the grid. Read the CISA advisory.

    Hitachi Energy e-mesh EMS buffer overflow. A second Hitachi Energy advisory this week, this one a buffer overflow that could cause denial of service or code execution in an energy management system. Two flaws from one vendor in a single cycle is worth noting for asset owners tracking exposure. Read the CISA advisory.

    Siemens Mendix Studio Pro build-pipeline parsing flaw. Like the OpenPLC issue above, this one triggers when the tool reads a “specially crafted malicious project” during the build. The recurring theme this week: your development and build tooling can be weaponized against you. Update to V11.12 or later. Read the CISA advisory.

    Labcenter Proteus 9 memory-safety bugs. Out-of-bounds writes, stack overflows, and use-after-free in electronics design software round out the theme of engineering tools as targets. Attackers understand that compromising a design workstation can quietly poison what gets built downstream. Read the CISA advisory.

    Hydro-Québec EV charging backend, CVSS 9.8. Improper access control and weak authentication throttling in an EV charging station backend earn one of the highest scores in this batch. As charging networks scale, their backends become critical infrastructure in their own right—and this is a loud warning about their maturity. Read the CISA advisory.

    CISA adds an actively exploited ColdFusion bug to KEV. A path-traversal flaw in Adobe ColdFusion is now confirmed to be under active exploitation. If you still run ColdFusion, treat this as a drop-everything patch under BOD 26-04’s risk-prioritized timeline. Read the CISA alert.

    FBI seizes the NetNut proxy platform and Popa botnet. A significant takedown: the FBI grabbed hundreds of domains tied to a residential proxy service run by a publicly traded firm, just weeks after

  • This Week in Security: AI-Fueled Patch Records, SharePoint Under Siege, and Surveillance’s Long Shadow

    A packed week across the security landscape, with a striking through-line: artificial intelligence is now reshaping both offense and defense—from a record-breaking Patch Tuesday to essays warning about where AI-driven surveillance and infrastructure are taking us. Below, our take on the items worth your attention, from active exploitation alerts to industrial control advisories and a few thought-provoking reads. This is a curated draft; sources are linked throughout.

    Optics that watch back. ETH Zurich researchers have built a “Fourier pixel” that can both display and sense light simultaneously—a genuinely impressive feat of physics. But the security implications are hard to ignore: a screen that is also a camera collapses the assumption that a display is a one-way device. It’s a reminder that hardware capabilities often outrun our threat models. (Schneier on Security)

    570 patches, and AI gets the credit. Microsoft’s latest Patch Tuesday nearly tripled last month’s already-record haul, and the company points to AI-assisted vulnerability discovery as the driver. That’s a double-edged story: better tooling finds more bugs before attackers do, but it also signals an accelerating patch treadmill that stretched IT teams will struggle to keep up with. Prioritization by risk matters more than ever. (KrebsOnSecurity)

    SharePoint remains a prime target. CISA is warning of active exploitation across all supported on-premises SharePoint Server versions, adding fresh CVEs to its KEV catalog. On-prem SharePoint has become a recurring soft spot for unauthorized access; if you still run it, hardening isn’t optional. (CISA)

    Four more known-exploited flaws. CISA’s mid-July KEV additions span SonicWall SMA1000 appliances, Active Directory Federation Services, and SharePoint—a cluster of edge and identity infrastructure that attackers clearly favor. The overlap with the SharePoint alert underscores that these aren’t theoretical bugs. (CISA)

    An 18-year-old bug, still exploited. The addition of a 2008-era Cisco IOS CSRF flaw to the KEV catalog is a quiet gut-check on patch lifespans. Vulnerabilities don’t expire just because they’re old—unpatched legacy gear keeps them alive. (CISA)

    File-upload flaws in the wild. Two more KEV entries—affecting iCagenda and Balbooa Forms—show how unrestricted file uploads remain a durable, low-effort attack vector, especially in third-party web components. Smaller plugins deserve the same scrutiny as flagship products. (CISA)

    Russia’s router campaign continues. A joint advisory details FSB Center 16 actors opportunistically compromising poorly configured networking devices across critical sectors. The takeaway is unglamorous but vital: basic router hygiene—patching, secure configuration, disabling legacy protocols—remains a frontline defense against state-sponsored targeting. (CISA)

    Industrial control advisories pile up. A batch of ICS advisories landed this week, several with alarming severity. Rockwell Automation’s 1715-AENTR EtherNet/IP Adapter carries a maximum CVSS 10, allowing attackers to alter I/O states and memory. (CISA) ABB’s T-MAC Plus sits at 9.9 with multiple CVEs, (CISA) while ABB Ability Edgenius inherits a Linux kernel privilege-escalation bug, (CISA) and ABB’s Advant Master Online Builder was shipped with an incorrect, vulnerable

  • Roundup: ICS Advisories Pile Up as Privacy, Surveillance, and Ukraine’s Defense Shakeup Dominate the Week

    This week’s ingest leans heavily on operational technology, with a full slate of CISA industrial control system advisories, but the more interesting tensions sit at the policy layer: how democracies handle surveillance mandates, age verification, and privacy in an AI-saturated world. There’s also a notable leadership reshuffle inside Ukraine’s defense apparatus. Here’s our take on what’s worth your attention.

    Ransomware and disruptive intrusions keep finding soft targets in food production, and Fairlife’s decision to halt U.S. output after a cyber incident is a reminder that manufacturing downtime, not data theft, is often the real cost. For a company whose retail sales cleared $1 billion, a production pause has cascading supply-chain implications. Details are still thin, but this belongs on any list of why OT resilience matters. (The Record)

    Ukraine’s defense ministry is in flux: Zelensky dismissed tech-forward minister Mykhailo Fedorov, prompting public pushback from people who credit him with pulling drones and digital innovation into the military. (The Record) The replacement is telling—Yevhenii Khmara, a major general with an intelligence and long-range-strike background, now serves as acting defense minister. (The Record) Read together, these two items suggest a shift in emphasis from the “digital ministry” ethos toward operational and intelligence continuity—worth watching for anyone tracking how Ukraine’s wartime tech culture evolves.

    Sen. Ron Wyden is asking the Trump administration to lean on Canada over its proposed lawful-access legislation, warning it could “weaponize American technology infrastructure” for surveillance. (The Record) It’s a striking framing: cross-border pressure over a close ally’s domestic surveillance law, grounded in the argument that mandates in one country ripple through shared tech supply chains. This is the encryption-backdoor debate wearing new clothes.

    Across the Atlantic, Ofcom has opened an investigation into TikTok over alleged age-verification failures, with the regulator calling age checks “a cornerstone” of UK online safety law. (The Record) The enforcement question here is whether age assurance can be done at all without creating new privacy and data-collection problems of its own—a tension regulators rarely acknowledge cleanly.

    On the privacy front, Daniel Solove’s argument (via Schneier) that individual “control” over personal data is a failed regulatory model deserves attention. (Schneier on Security) The proposed pivot—data minimization, fiduciary duties, and liability for harmful algorithmic design, modeled on food and drug accountability—is a serious reframing of who bears the burden. In an AI era where consent theater is meaningless, shifting responsibility onto companies feels less like a policy preference and more like a necessity.

    For a change of pace, there’s a genuinely lovely bit of cryptographic history: newly surfaced papers detailing Alan Turing’s “Delilah” portable voice-encryption project from 1943–45. (Schneier on Security) Beyond the collector’s-item angle, it’s a reminder that secure voice—still a hard problem—was being wrestled with in handwritten notebooks eighty years ago.

    The bulk of this week’s advisories come from CISA’s ICS program, and the pattern is instructive. Denial-of-service dominates: NASA’s Core Flight System Health & Safety app (CISA), Rockwell’s Flex 5000 Adapter (CISA), the 1756-EN2/EN3/ENBT modules (CISA), the CompactLogix/ControlLogix/GuardLogix family (CISA), and Siemens SICAM 8 grid gear (CISA) all carry availability risks that matter more in operational environments than a CVSS score alone conveys.

    A few advisories stand out for higher impact. Rockwell’s Arena simulation software carries arbitrary-code-execution flaws (CVSS 7.8), the most serious of the batch. (CISA) AutomationDirect’s Productivity Suite bundles six CVEs spanning memory corruption and information disclosure.