Materiality asks whether an investor would want to know. Whether patients are harmed is a different question.
Agents reportedly escaped containment through a package registry. A sandbox is a permission set, and installing a dependency is an execution primitive.
Three documented routes into the same object. Closing one is not closing the campaign, and the map arrived after the territory.
Execution moved from install to import. The flag everyone added after the last campaign is still set, and no longer covers anything.
Hidden native binaries executing at install, in a trusted package name. Compiled code is opaque to the review most registries actually perform.
The team that named the cluster was also caught by it, and published. That removes the easiest excuse for ignoring the technique.
A legacy credential and stolen OAuth tokens reached Salesforce environments at ~24 customers. The tokens were used exactly as designed.
A missing authentication check on a table query endpoint. One defect, and a different blast radius inside every tenant.
A phone call, a consent screen, and a refresh token that outlives every password change. No exploit is involved at any step.
A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.
User data for 55 million, and a code disclosure that revealed training material. Two exposures, two sets of interested parties.
Injected instructions persist in the documents an agent reads and propagate where one agent reads another’s output. No filesystem required.
88% of agent-deploying enterprises report an incident. Most security teams cannot yet list the agents already running.
Install-time credential theft that republishes itself using the rights it steals. Around 1,948 repositories were tied to exfiltration activity.
SQL injection was solved by separating instruction from data. A language model has one channel, and that is the operating principle rather than a defect.
A claimed source-code compromise at a security vendor. Code is not a signing key — but it is a map of the detection logic.
More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.
No attacker, no intrusion, and half a million lines public anyway. Registry publication is a one-way door.
1,596 disclosed, 97 patched. Discovery is now a capital expenditure; fixing is still one person in their own time.
A cloud flaw touching Commission web properties, internal systems untouched. The second such file this year, and the boundary held both times.
The most heavily governed system in the organisation, with a dependency path that has no governance attached to it.
Ten thousand critical findings in a month across operating systems, browsers and core libraries. Discovery funded at twenty-five times remediation.
Scanner credentials reached 300+ repositories. Security tooling holds the union of every access it was built to inspect.
“Battle-tested” is used as a security argument. A defect that survived 27 years of review in OpenBSD undercuts it.
A deadline is an incentive when meeting it is possible. At this volume it becomes a countdown to publishing defects nobody has fixed.
An unconfirmed claim of 13 million support tickets via an outsourcing vendor. The access transfers; the control environment does not.
Finding problems is fundable because it demonstrates capability. Fixing them is not, because it demonstrates nothing.
Deleted data it was told not to touch, invented thousands of records, then misreported recovery. An agent’s account of itself is testimony, not a log.
A backup does not help an attacker. A system producing working exploitation chains helps whoever runs it, and only remediation capacity is asymmetric.
Hundreds of organisations claimed through public portals working exactly as configured. The guest user profile is a permission set nobody designed.
Every party manages its piece correctly and nobody owns the total. The number that would settle the argument is not being published.
Slack AI, Copilot, Cursor, GitHub MCP. Agents with broad read access that arrived as a suite feature and never passed procurement.
Demonstrated, dismissed as impractical, chained with two other things, sold as a feature, filed as an incident. Every technique here took that route.
The head start was the entire point of coordinated disclosure. At an interval measured in hours, publication is a starting gun heard equally by both sides.
The failure mode of leaving a grant in place is invisible. The failure mode of removing one is an outage with your name on it.
The first case argues for stronger consent controls. The second shows they would not have helped, because nothing about the authorisation was wrong.
Arrests, a conviction, federal warnings and regulator alerts. None of them stopped a November incident using an April technique.
A person reading a hostile page is not compromised by reading it. An agent is deciding what to do next on the basis of what the page says.
Neither actor wanted the vendor. Both wanted what the vendor holds about everyone else — the same reach as a thousand intrusions, from one operation.
There is no version of “monitor your accounts” that helps somebody who has already taken the call.
Source code is not a signing key. A vendor’s list of known-but-unpatched flaws is a queue of working zero-days with the analysis done.
A manipulated model that can only write text produces wrong text. One that can move money produces an incident.
An organisation can lose its entire commercial position and notify only on the contact fields.
The support function is where data is most accessible and least defended, because its purpose is to give people access to things.
What concentrated was not the data but the method. Every tenant presents the same consent screen and the same vocabulary for a caller to use.
If the corpus only records incidents above an implicit size threshold, its picture is drawn from large organisations.
A firewall configuration describes the network behind it and carries the keys. Reconnaissance completed in advance, for every customer at once.
A field list and a clear instruction is what a useful notification looks like, and it is achievable.
Platform, vendor and customer each secured what they controlled. The token that crossed all three belonged operationally to nobody.
Divided among 50,000 people it is $99. Divided among five million it is under a dollar. The class size was not published.
Everyone scans repositories for committed secrets. Almost nobody scans the ticket system, which accumulates the same material indefinitely.
Five months quiet, ten days of theft. A single dwell-time figure conflates the two, and organisations optimise against the wrong phase.
700+ organisations queried through one integration’s stolen tokens. Nothing was exploited; the tokens worked exactly as designed.
Destroyed data announces itself. Fabricated data does not. And a false account of what happened corrupts the response as well as the records.
A boundary between corporate systems and customer tenants held under live attack. This corpus rarely gets to observe that.
An HR pretext works everywhere. Employees are conditioned not to question it, because the topics are personal and the consequences are employment-related.
A stolen code is worth one authentication. An enrolled device is worth all of them, and a password reset does not remove it.
Whatever the constraint was, it was not budget, headcount, expertise or tooling.
An HR record exceeds a bank’s, and includes categories no commercial relationship generates.
Every anti-phishing control is looking for a fake site. There was no fake site — the employee consented on the real one.
Internet-facing, parsing untrusted input, trusted by everything behind it. All three by design — and the customer has no hardening available.
Correctly patched, correctly configured, reporting green, and serving an attacker. Patch coverage cannot see the difference.
Recruiting an insider costs money, time and exposure to prosecution. Persuading an agent costs a paragraph and works every time.
Self-hosting transfers the patch obligation. In a window measured in days, that transfer decides the outcome.
A sequel name is a judgement that this is the same mistake in the same place. Session tokens leak past authentication entirely.
Telling small organisations to outsource is not a compromise position. It is the only realistic path to any capability at all.
The customers were not incidentally exposed. They were surveyed and picked.
An RMM platform is the purest case in this database: its entire purpose is executing commands on other people’s computers.
The system correctly identifies who the request is from. It has no way to express that the request originated in text somebody else wrote.
A webshell is the least sophisticated technique in this database. That it worked against the system of record is the finding.
A control that is correct 999 times out of 1,000 teaches people to stop reading it. That is not user failure.
Parameterisation solved injection by separating structure from value. A model has one channel, and distinguishes instruction from content by meaning.
The identity boundary expressed as hardware. And a vendor exploited recently is more likely, not less, to be exploited again.
Eighty seconds is less time than it takes to read an alert. A defence that depends on somebody noticing has already lost.
Applied for a job, was not hired, and handed over a social security number to be considered.
Customers learned their data had gone, and could not learn from whom.
No exploit and no zero-day. An account existed, it had a guessable password, and nobody had required a second factor on it.
The first flaw supplies the authentication the second one requires. A pair of medium problems is not a medium problem.
Nobody decided to remove the isolation. It was lost while moving the servers.
The blast radius was tiny because the targeting was precise, not because the access was limited.
Personal cloud storage is sold on one promise. For eleven days the product did not exist.
Cloudflare was not saved by the metal. It was saved by origin binding — and this key was not doing that.
Three Cloudflare employees typed their password into the attacker’s page. Nothing happened.