Cyber Security
August 14, 2026
Ransomware early warning: watching leak sites for your name, your clients and your suppliers
On 13 August the Clop ransomware group posted claims naming Shell and Philips, and both companies confirmed they had experienced a security incident once the claims were reported (NL Times). Philips called it an attempted attack on a specific server ...
#ransomware#threat-intelligence#incident-response#supply-chain#notifiable-data-breaches
August 21, 2026
Cutting vulnerability noise: using AI and public data to demote CVEs that don't matter
A container image scan finishes and hands back a few hundred findings. A dozen are critical. Most of the rest are base image packages with a CVE ID, a CVSS score, and no patched version anywhere in the world. The team has one afternoon a fortnight fo ...
#vulnerability-management#cve#patch-management#devsecops#osv
August 28, 2026
Supply-chain attacks: package cooldowns and policy checks for npm, PyPI and NuGet
On 4 August 2026, a self-propagating worm called ChainDrop tore through npm. BleepingComputer reported more than 1,300 compromised packages with about two billion monthly downloads between them, including keyv, cacheable, flat-cache and file-entry-ca ...
#supply-chain-security#npm#dependency-management#devsecops#ci-cd
September 4, 2026
Cloud posture on autopilot: continuously auditing AWS, Azure and Microsoft 365
Most of the cloud security incidents we get called into have nothing to do with a novel exploit. Someone opened a security group to 0.0.0.0/0 for a vendor's remote session and never closed it. A storage account got flipped to public so a contractor c ...
#cloud-security#microsoft-365#azure#aws#configuration-drift#continuous-compliance
