threat intelligence
32 posts
CVE-2024-3400 shipped exploited before the advisory
Why the gap between CVE disclosure and production detection is structural - and where attackers operate inside it.
Massachusetts bans precise geolocation sales
Massachusetts banned the sale of precise location data. The statute kills a commercial attack vector and creates real telemetry gaps for defenders.
The integration is the attack surface
Pentagon raised Israeli collection risk to top tier. The technical exposure is supply chain privilege inherited from vendor software, not espionage.
Editorial independence is a failed control
UK media failed to disclose defence sector ties in nearly 60 percent of cases. The disclosure gap is an information supply chain vulnerability - and it is exploitable.
Spanish police flagged GrapheneOS as suspicion
Authorities treating GrapheneOS as a targeting signal inverts threat intel logic and exposes the wrong population to scrutiny. The mechanism breakdown.
EY Canada's 2026 report cited papers that don't exist
EY Canada published a cybersecurity report with mostly hallucinated citations. Here's what that means for how you should read threat intelligence.
CISA pushed GovCloud keys to GitHub
Technical analysis of a CISA admin leaking AWS GovCloud keys on GitHub - exposure mechanics, CloudTrail detection paths, and residual session risk post-rotation.
ShinyHunters dumps 94GB of 7-Eleven franchisee data
ShinyHunters leaked 94GB of 7-Eleven franchisee data after extortion refusal. Technical analysis of TTPs, info-stealer-to-SaaS pipeline, and franchise IT exposure.
Dutch police pull 800 racks offline
Dutch police seized 800 bulletproof hosting servers and arrested two operators. Technical analysis of the OpSec failures and tenant exposure.
AI is making attackers worse, not better.
Defender telemetry through 2026 shows model-mediated attackers produce more volume, less variance, weaker adaptation. Substitution is not uplift.
What a $5 VPS honeypot taught me
An open-source honeypot probe database queryable via curl, HTTP, and MCP - what it catches, why it helps small defenders, and where the risks actually sit.
Mandiant clocked 5 days in 2023
Mean time-to-exploit for critical CVEs has collapsed to days. The mechanism is patch diffing, n-day industrialisation, and telemetry gaps on appliances.