Category: Cybersecurity

Cybersecurity / information-security related content. Displays on pages filtered for the category.

  • This Week in Security: AI-Fueled Patch Records, SharePoint Under Siege, and Surveillance’s Long Shadow

    A packed week across the security landscape, with a striking through-line: artificial intelligence is now reshaping both offense and defense—from a record-breaking Patch Tuesday to essays warning about where AI-driven surveillance and infrastructure are taking us. Below, our take on the items worth your attention, from active exploitation alerts to industrial control advisories and a few thought-provoking reads. This is a curated draft; sources are linked throughout.

    Optics that watch back. ETH Zurich researchers have built a “Fourier pixel” that can both display and sense light simultaneously—a genuinely impressive feat of physics. But the security implications are hard to ignore: a screen that is also a camera collapses the assumption that a display is a one-way device. It’s a reminder that hardware capabilities often outrun our threat models. (Schneier on Security)

    570 patches, and AI gets the credit. Microsoft’s latest Patch Tuesday nearly tripled last month’s already-record haul, and the company points to AI-assisted vulnerability discovery as the driver. That’s a double-edged story: better tooling finds more bugs before attackers do, but it also signals an accelerating patch treadmill that stretched IT teams will struggle to keep up with. Prioritization by risk matters more than ever. (KrebsOnSecurity)

    SharePoint remains a prime target. CISA is warning of active exploitation across all supported on-premises SharePoint Server versions, adding fresh CVEs to its KEV catalog. On-prem SharePoint has become a recurring soft spot for unauthorized access; if you still run it, hardening isn’t optional. (CISA)

    Four more known-exploited flaws. CISA’s mid-July KEV additions span SonicWall SMA1000 appliances, Active Directory Federation Services, and SharePoint—a cluster of edge and identity infrastructure that attackers clearly favor. The overlap with the SharePoint alert underscores that these aren’t theoretical bugs. (CISA)

    An 18-year-old bug, still exploited. The addition of a 2008-era Cisco IOS CSRF flaw to the KEV catalog is a quiet gut-check on patch lifespans. Vulnerabilities don’t expire just because they’re old—unpatched legacy gear keeps them alive. (CISA)

    File-upload flaws in the wild. Two more KEV entries—affecting iCagenda and Balbooa Forms—show how unrestricted file uploads remain a durable, low-effort attack vector, especially in third-party web components. Smaller plugins deserve the same scrutiny as flagship products. (CISA)

    Russia’s router campaign continues. A joint advisory details FSB Center 16 actors opportunistically compromising poorly configured networking devices across critical sectors. The takeaway is unglamorous but vital: basic router hygiene—patching, secure configuration, disabling legacy protocols—remains a frontline defense against state-sponsored targeting. (CISA)

    Industrial control advisories pile up. A batch of ICS advisories landed this week, several with alarming severity. Rockwell Automation’s 1715-AENTR EtherNet/IP Adapter carries a maximum CVSS 10, allowing attackers to alter I/O states and memory. (CISA) ABB’s T-MAC Plus sits at 9.9 with multiple CVEs, (CISA) while ABB Ability Edgenius inherits a Linux kernel privilege-escalation bug, (CISA) and ABB’s Advant Master Online Builder was shipped with an incorrect, vulnerable

  • Roundup: ICS Advisories Pile Up as Privacy, Surveillance, and Ukraine’s Defense Shakeup Dominate the Week

    This week’s ingest leans heavily on operational technology, with a full slate of CISA industrial control system advisories, but the more interesting tensions sit at the policy layer: how democracies handle surveillance mandates, age verification, and privacy in an AI-saturated world. There’s also a notable leadership reshuffle inside Ukraine’s defense apparatus. Here’s our take on what’s worth your attention.

    Ransomware and disruptive intrusions keep finding soft targets in food production, and Fairlife’s decision to halt U.S. output after a cyber incident is a reminder that manufacturing downtime, not data theft, is often the real cost. For a company whose retail sales cleared $1 billion, a production pause has cascading supply-chain implications. Details are still thin, but this belongs on any list of why OT resilience matters. (The Record)

    Ukraine’s defense ministry is in flux: Zelensky dismissed tech-forward minister Mykhailo Fedorov, prompting public pushback from people who credit him with pulling drones and digital innovation into the military. (The Record) The replacement is telling—Yevhenii Khmara, a major general with an intelligence and long-range-strike background, now serves as acting defense minister. (The Record) Read together, these two items suggest a shift in emphasis from the “digital ministry” ethos toward operational and intelligence continuity—worth watching for anyone tracking how Ukraine’s wartime tech culture evolves.

    Sen. Ron Wyden is asking the Trump administration to lean on Canada over its proposed lawful-access legislation, warning it could “weaponize American technology infrastructure” for surveillance. (The Record) It’s a striking framing: cross-border pressure over a close ally’s domestic surveillance law, grounded in the argument that mandates in one country ripple through shared tech supply chains. This is the encryption-backdoor debate wearing new clothes.

    Across the Atlantic, Ofcom has opened an investigation into TikTok over alleged age-verification failures, with the regulator calling age checks “a cornerstone” of UK online safety law. (The Record) The enforcement question here is whether age assurance can be done at all without creating new privacy and data-collection problems of its own—a tension regulators rarely acknowledge cleanly.

    On the privacy front, Daniel Solove’s argument (via Schneier) that individual “control” over personal data is a failed regulatory model deserves attention. (Schneier on Security) The proposed pivot—data minimization, fiduciary duties, and liability for harmful algorithmic design, modeled on food and drug accountability—is a serious reframing of who bears the burden. In an AI era where consent theater is meaningless, shifting responsibility onto companies feels less like a policy preference and more like a necessity.

    For a change of pace, there’s a genuinely lovely bit of cryptographic history: newly surfaced papers detailing Alan Turing’s “Delilah” portable voice-encryption project from 1943–45. (Schneier on Security) Beyond the collector’s-item angle, it’s a reminder that secure voice—still a hard problem—was being wrestled with in handwritten notebooks eighty years ago.

    The bulk of this week’s advisories come from CISA’s ICS program, and the pattern is instructive. Denial-of-service dominates: NASA’s Core Flight System Health & Safety app (CISA), Rockwell’s Flex 5000 Adapter (CISA), the 1756-EN2/EN3/ENBT modules (CISA), the CompactLogix/ControlLogix/GuardLogix family (CISA), and Siemens SICAM 8 grid gear (CISA) all carry availability risks that matter more in operational environments than a CVSS score alone conveys.

    A few advisories stand out for higher impact. Rockwell’s Arena simulation software carries arbitrary-code-execution flaws (CVSS 7.8), the most serious of the batch. (CISA) AutomationDirect’s Productivity Suite bundles six CVEs spanning memory corruption and information disclosure.