Desk live·
ForensicPost
Section

Cloud

Identity is the control plane, and the control plane is an API. Files here follow permission paths rather than perimeters: what a role could do, what it did, and which log would have shown you.

Files in section113
Median time to detection9 days
Cases with no useful log34%
AI files, filed separately20
Top of section26-0817 · Vulnerabilities · Sev 4

Unisoc Modem Flaw Gives Android Kernel Access Through a Video Call, With No Fix

Researchers published the second stage of a chain that turns a VoLTE video call into full Android kernel access on three Unisoc chipsets. The modem and application processor share memory with no hardware boundary, and the vendor has not answered.

10 min readConfidence: high
Filter
Sort

Metabase Zero-Day Hit Five Companies Before the Flaw Was Disclosed

A CVSS 10.0 flaw in a reporting tool that stores the credentials for every warehouse behind it.

3 sources · 11 min read

VMware vCenter Flaw Exploited in 47 Countries Within a Week of the Patch

361 hosts in 47 countries, and 95% of them taken inside two days of the first exploitation.

3 sources · 10 min read

Research Puts Three Quarters of Insider Incidents Down to Negligence, Not Sabotage

About 75% of insider incidents involve nobody acting maliciously. Programmes built to detect grievance address a quarter of the problem.

3 sources · 10 min read

Vendor Analysis Maps Three ShinyHunters Attack Paths Into Salesforce Tenants

Three documented routes into the same object. Closing one is not closing the campaign, and the map arrived after the territory.

2 sources · 9 min read

AsyncAPI npm Compromise Ran Its Payload at Import, Not Install

Execution moved from install to import. The flag everyone added after the last campaign is still set, and no longer covers anything.

1 source · 9 min read

CISA Tells SharePoint Operators to Hunt Before They Rotate Keys

Rotating the stolen key is the fix. It is also what erases the proof anyone used it.

3 sources · 11 min read

Malicious Jscrambler npm Versions Ran Native Binaries During Installation

Hidden native binaries executing at install, in a trusted package name. Compiled code is opaque to the review most registries actually perform.

2 sources · 8 min read

Scattered Lapsus$ Hunters Name Combines Three Separate Crews

A name concatenated from three crews. Attribution language implies a roster, and a coalition brand quietly breaks that implication.

2 sources · 10 min read

Exposed Elasticsearch Instance Held 24 Billion Credential Records

24 billion credential records from 36 sources in one indexed store. The thefts were old; the index is what makes them usable.

1 source · 8 min read

Klue Compromise Reached Salesforce Environments at Two Dozen Customers

A legacy credential and stolen OAuth tokens reached Salesforce environments at ~24 customers. The tokens were used exactly as designed.

1 source · 9 min read

ServiceNow API Flaw Allowed Unauthenticated Table Queries, Researchers Report

A missing authentication check on a table query endpoint. One defect, and a different blast radius inside every tenant.

1 source · 8 min read

UNC6040 Phoned Staff to Authorise Salesforce Connected Apps

A phone call, a consent screen, and a refresh token that outlives every password change. No exploit is involved at any step.

3 sources · 11 min read

A Worm in the Registry, Wearing a Vendor’s Name

A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.

2 sources · 9 min read

Udemy Breach Exposed 1.4 Million Addresses and Instructor Payout Details

1.4 million addresses, and instructor payout methods. A card can be reissued; a bank account configured to receive money cannot.

1 source · 7 min read

CVE Submissions Rose 263% Between 2020 and 2025

Four different things drive the 263%, and only one is bad news. The count measures workload, not software quality.

2 sources · 10 min read

The Package That Steals the Pipeline That Builds the Package

Install-time credential theft that republishes itself using the rights it steals. Around 1,948 repositories were tied to exfiltration activity.

3 sources · 12 min read

FBI Recorded 1,008,597 Fraud Complaints and $20.9 Billion in Losses for 2025

AI-referencing complaints are ~4% of reported losses. The other 96% is the story — and the AI share is undercounted by construction.

2 sources · 10 min read

The Disclosure-to-Exploitation Window Is Closing on the Patch Window

Exploitation is arriving before organisations can deploy. Patching in twenty days is worth less than surviving a compromised appliance.

2 sources · 11 min read

FTC Bars Kochava From Selling Sensitive Location Data Without Consent

No intrusion, no misconfiguration — a functioning business selling movement traces. From the traced person’s position the distinction is thin.

3 sources · 12 min read

ShinyHunters Campaign Compromised More Than a Thousand Organisations via Device Code Phishing

More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.

2 sources · 10 min read
© 2026 ForensicPost Media · the desk · newsletter · correctionsGlossary