peter bassill · operator

Threats — writing by Peter Bassill

peter@hardened:~$ ls -t writing/threats/

Threats

Breaches, campaigns and the vulnerabilities being used right now. 58 articles

  • Critical is not the same as urgent: what 70,686 CVEs in 2026 actually ask of you

    Of 70,686 CVEs published between 1 January and 22 September, 161 are known to be exploited. What NVD, EPSS, CISA's catalogue and Exploit-DB say about severity, deadlines and the software attackers use, and a one-line triage rule.

    • 19 min read
  • The 999 lines held: Dyfed-Powys Police and the staff question

    Dyfed-Powys Police kept 999 and 101 running through a cyber incident and has so far found no evidence the public's data was accessed; staff data is still under investigation. What went right, what "technical difficulties" costs, and why your own people should never hear last.

    • 10 min read
  • The week in cyber — 21 to 25 September 2026

    A BIG-IP zero-day already under attack, Revolut's second breach this month, prompt-injected AI agents at Salesforce, an AI phishing service dismantled by Microsoft and the Met, and a whisky retailer undone by a bolt-on app — five stories, all about trust handed to someone else.

    • 6 min read
  • Somebody else's problem: the lockbox codes, the reporting tool, and the supplier review

    A London property manager kept bank details, passwords and key-safe codes where a cloud analytics tool could read them; a vulnerability in that tool did the rest. Why "the cloud" is not a security decision, and a supplier review you can actually run and evidence.

    • 19 min read
  • Aimed at a person, not a network: Iran's CHOSEN BRICK

    The NCSC, FBI and AIVD have published a joint advisory on CHOSEN BRICK, Windows malware Iranian state actors use to find, watch and expose dissidents, activists and journalists. A fake MRI result, a fake Norton, a Telegram bot, and a deliberate move from the work laptop to the home one. What it does, how to look for it, and what employers of people at risk should do this week.

    • 17 min read
  • The week in cyber — 7 to 11 September 2026

    The EU’s vulnerability clock started, Microsoft shipped a record Patch Tuesday, CrowdStrike’s sensor became an escalation path, and Parliament said no to personal director liability — four things, each with a decision attached.

    • 5 min read
  • Trezor, ShipMonk, and the deletion that never happened

    Trezor's shipping partner was breached through a Metabase zero-day in August. This week the count reached 81,000, because 67,000 records came from 2019 to 2021 orders ShipMonk had confirmed in writing were deleted. A timeline, and what it teaches about supplier assurances.

    • 15 min read
  • The week in cyber — 31 August to 4 September 2026

    Parliament writes a 24-hour clock into law while attackers work through the appliances at your network edge — four things from the week, each with a decision attached.

    • 6 min read
  • The UK threat landscape: August 2026

    The first of a monthly series. In August, 8.7 million airport customers, more than a thousand charities and a national police database lost data through exposed keys and open portals rather than exploits; a small power generator went dark; and the patch window shrank to days.

    • 33 min read
  • The week in cyber — 20 to 24 July 2026

    A zero-click Russian email campaign, a SharePoint patch trailing its own exploitation, an AI agent that escaped its sandbox, and a council insider nobody was watching — four containment failures and the board questions they leave behind.

    • 5 min read
  • The week in cyber — 13 to 17 July 2026

    Allied agencies named the FSB unit scanning UK routers, Microsoft shipped its largest patch on record with two flaws already exploited, the Cyber Security and Resilience Bill reached the Lords, and a poisoned npm package walked around this year's install-time defences.

    • 5 min read
  • wp2shell: WordPress core has an unauthenticated RCE. Patch now.

    wp2shell (CVE-2026-63030) is an unauthenticated remote code execution flaw in WordPress core — not a plugin — patched on 17 July in 6.9.5 and 7.0.2. No public exploit yet, but one is coming fast. Why a core flaw is different, and why you should patch every site now.

    • 8 min read
  • Patch FortiSandbox by Sunday: when the security appliance is the hole

    CISA has told federal agencies to patch two actively-exploited FortiSandbox flaws by Sunday — both unauthenticated, CVSS 9.1 remote code execution. The malware sandbox is the way in. Why the KEV is your real triage list, and why your security appliances are the target.

    • 7 min read
  • The TfL hackers were teenagers. Unusually, they were caught.

    Two young Britons — Thalha Jubair, 20, and Owen Flowers, 18 — jailed five and a half years each for the 2024 Transport for London attack: £29m of damage, 148 systems down, done with social engineering. The UK's largest cybercrime case — and, unusually, they were caught.

    • 8 min read
  • The Qantas breach was a phone call: what we know

    A living account of the Qantas breach, now pinned on a tech-support scam. No zero-day — a phone call to a contact centre exposed 5.7 million customers. What's confirmed, what's still unproven, and the help-desk controls that actually stop it. Updated as it develops.

    • 10 min read
$ finger peter

Get in touch

Email is fastest. If your message says who you are, what you would like, and a rough sense of when, you will get a useful answer within two working days.
EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox
anti-abuse check: waiting for the form…