Security news & analysis
The story behind the headline, in plain language: what happened, why it happened, and what it means for the systems you have facing the internet.
8 briefings published
We scanned 1,106 online stores: the platform fixes what the browser sees, not what your customer gets emailed
We passively scanned 1,106 online stores on their own domains and sorted them by platform. Shopify's 341 stores send HSTS and CSP 98.5% of the time — and only 25.8% of them enforce DMARC. A managed platform buys you the half a browser sees, and nothing on the half that reaches your customer's inbox.
Read the analysisMore briefings
The State of Web Security at Bulgarian and Italian Web Agencies (2026)
We passively checked the homepages of 376 web agencies that rank in Google in Bulgaria and Italy. 81% send no Content-Security-Policy, 63% no HSTS, and only 27% enforce DMARC — the people who build websites for a living mostly skip the free hardening they could be selling.
PaperCut's second emergency patch in two days — and why its print server is a 2023 ransomware rerun
PaperCut disclosed two critical zero-days, CVE-2026-82078 and CVE-2026-81578, in its NG/MF print-management software on August 27, 2026, already under active attack. The first emergency patch got bypassed within a day, forcing a second one on August 28. If you run a PaperCut server, apply Emergency Patch Release 2 now and check whether its admin interface is reachable from the internet.
SharePoint's third active exploit in ten days — why CISA now says patching alone isn't enough
Microsoft's July 2026 Patch Tuesday fixed a SharePoint flaw, CVE-2026-56164, that was already under active attack — the third SharePoint vulnerability exploited in about ten days. CISA is now telling organizations to harden SharePoint servers, not just patch them. If you self-host SharePoint, treat that as the real signal: know what's exposed, don't just wait for the next fix.
One HTTP header could impersonate any user in Gitea's Docker image (CVE-2026-20896)
A high-severity flaw in Gitea's official Docker image — CVE-2026-20896, CVSS 9.8 — let one HTTP header impersonate any user, including an admin. It only bites instances that enabled reverse-proxy login and kept the wildcard default. Upgrade to 1.26.3 or later, stop trusting every IP, and ask whether your Git server should face the internet at all.
Attackers are mass-scanning WordPress and Joomla sites to plant webshells — here's what it means for you
A global campaign is mass-scanning WordPress, Joomla, and other CMS sites and planting webshells through vulnerable plugins and extensions. Australia's cyber agency warned about it on July 9, and CISA has flagged fresh Joomla flaws being exploited. If you run a CMS site, the move is to update your plugins now and check what of yours is exposed.
An AI agent just ran a full ransomware attack on its own — but the way in was boring
Researchers documented JADEPUFFER, the first ransomware operation run end-to-end by an AI agent. The headline is the AI. The root cause is ordinary: an app left facing the internet with a known, already-patched flaw and no login required. The fix is the same as it's always been — know what of yours is exposed.
The SharePoint bug ransomware crews are exploiting right now — and what it means if you host your own
Microsoft SharePoint Server has a critical remote-code-execution flaw, CVE-2026-45659, that ransomware crews are actively exploiting, and CISA ordered federal agencies to patch it by July 4, 2026. If you run SharePoint on your own servers, patch to the May 2026 update now and check whether it should be reachable from the internet at all.
Looking for the how-to guides instead of the news? Browse the Learn library →