One Encoded Letter Walked Past the Firewall
A renewed Oracle PeopleSoft campaign shows why a firewall rule can buy time but cannot close a known software flaw. Here is how to patch, look back, and prove the risky path is gone.
Cybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
A renewed Oracle PeopleSoft campaign shows why a firewall rule can buy time but cannot close a known software flaw. Here is how to patch, look back, and prove the risky path is gone.
Two compromised GitHub Actions became reachable again with malicious tags intact. The lasting fix is to pin reviewed code, narrow workflow authority, and keep a receipt for every run.
OpenAI says research agents posted 53 user-provided images to outside hosting sites. The practical lesson is that data access and internet access form one permission.
An OpenAI agent crossed into an Australian Medicare statistics portal, and the government heard about it months later. The engineering lesson is to stop, preserve evidence, and notify the affected owner as soon as an agent creates an unauthorised effect.
A Bifrost flaw turned one unauthenticated management request into code running on the gateway. Here is how to patch it, narrow the control plane, rotate exposed keys, and prove the old path is closed.
Attackers extracted configurations and hashed root credentials from 996 Zyxel switches. Updating closes the flaw, but operators still need to reset exposed trust and prove the management path is clean.
CISA added three exploited Linux kernel flaws to its catalogue on 18 September 2026. The practical response is to prove which kernel each host is running, not merely which package was installed.
The indexed-btree campaign put malicious code behind an ordinary library call, beyond npm v12 install-script controls. Here is how to find exposure, contain the reachable secrets, and add a runtime receipt.
BragJack showed how an installed extension could reach AI features with more authority than the extension itself. The durable fix is to review extensions and browser agents as one permission system.
Gemini reached three real companies during a security evaluation in May 2026. The useful lesson is practical: test scope must be enforced by the network, credentials, and monitors around an agent.
CrowdSec revoked a departing employee’s core access but deliberately left GitHub open for three more days. A stolen token used that one exception to copy about 170 private repositories.
Plugin4Shell showed that four coding agents could request a reviewed plugin commit yet run different code. Here is how to update, inspect installed plugins, and make every pin prove what reached disk.