Denshattack, test: when a train ride reminds us that rail is fun
The Verge publishes an enthusiastic review of Denshattack, a rail shooter that advocates for a return to guided level design. We're rather in agreement.
Jul 18, 2026 4 2
The Verge publishes an enthusiastic review of Denshattack, a rail shooter that advocates for a return to guided level design. We're rather in agreement.
Jul 18, 2026 4 2
The Register and The Hacker News reported on September 2, 2026, that SonicWall SMA1000 appliances are once again under active attack, with two zero-days capable of forming a full exploit chain. Immediate operational priority.
Sep 3, 2026 2 1
The Hacker News documents a new class of attack: malicious .git configurations that, when read by AI coding agents, execute attacking code. The tools meant to secure become vectors.
Sep 3, 2026 9 2
The Hacker News documents a campaign of fake software installers that begin by disabling Windows Update and reducing Microsoft Defender protections. This is no longer a classic drive-by attack: it's a preamble to a lasting intrusion.
Sep 3, 2026 2 1
The Register documents how an old Lenovo login system, left in place after a forgotten SSO integration, allowed access to 5,000 Dropbox accounts. A textbook case of federated identity debt in supply chains.
Sep 3, 2026 22 3
The pro-Russian group UAC-0099 has found an original workaround against automated analysis by LLM: embedding prompts about nuclear weapons in its malware. The AI tools trigger their filters and refuse to analyze it—a reversed jailbreak that turns AI safeguards against defenders.
Sep 2, 2026 14 3
For 33 hours, traffic to Softaculous—the web application installer used by millions of cPanel/Plesk hosting providers—was silently redirected via a BGP hijack attack. A major exposure window for a critical infrastructure in global web hosting.
Sep 2, 2026 15 3
Cyberattacks have targeted pacemakers and exfiltrated millions of patient records in August 2026. The healthcare sector joins water and energy on the list of critical infrastructures regularly targeted.
Sep 1, 2026 12 3
The HollowByte flaw in OpenSSL allows an attacker to send an 11-byte TLS request to inflate server memory until saturation. A rarely achieved attack-to-impact ratio, affecting a library present on millions of servers.
Sep 1, 2026 10 2
A campaign conceals malicious code in PNG files via steganography, then deploys a custom reverse tunnel to maintain persistent access. The reverse tunnel technique continues to diversify in its delivery vectors.
Sep 1, 2026 2 1
Aurora ransomware operators integrate Cursor AI into their attack chain to generate and adapt their payloads across 10 targets. A deliberate operational decision—not an accident.
Sep 1, 2026 15 3
Two years of social engineering, a backdoor hidden in build scripts, and detection via a 500-millisecond SSH latency spike. The book *Half a Second* reconstructs CVE-2024-3094—and extracts lessons every developer must learn.
Aug 31, 2026 15 3