peter bassill · operator

Threats — writing by Peter Bassill

peter@hardened:~$ ls -t writing/threats/

Threats · page 2 of 4

Breaches, campaigns and the vulnerabilities being used right now. 58 articles

  • Six hundred patches, two emergencies, and one broken Dell

    Microsoft's July Patch Tuesday broke its record again — 622 CVEs, or 570 depending who's counting — then Microsoft blocked its own update on overheating Dells. The headline number is theatre; the real list is two exploited zero-days. A triage, not a panic.

    • 9 min read
  • The week in cyber — 6 to 10 July 2026

    Whitehall credentials for sale after a Fortinet campaign that needed no zero-day, a voluntary pledge launched at Number 10 that most of the FTSE ignored, the Bank of England naming frontier AI as a stability risk, and npm about to break your build on purpose.

    • 7 min read
  • Three weeks with the door open

    A cybercrime crew backdoored 25,000 websites using nothing but public exploits — then left its own server open on the internet for three weeks. The exposed working directory shows an adversary far less polished, and far more industrialised, than its victims imagined.

    • 8 min read
  • Ghosts and runners: living off GitHub

    Attackers have stopped bringing their own infrastructure and started borrowing GitHub's — dormant accounts aged for years to blend in, and CI runners turned into backdoors. A look at the ghost-account and hijacked-runner campaigns, and the dull controls that would stop them.

    • 8 min read
  • The week in cyber — 29 June to 3 July 2026

    A CitrixBleed sequel exploited within a day, on-prem SharePoint on a patch clock that runs out today, the police pricing UK ransomware and asking you not to pay, and the Cyber Security and Resilience Bill heading for the Lords.

    • 6 min read
  • The week in cyber — 24 to 28 June 2026

    Cisco phone systems, an engineering PLM vault and the Linux kernel each turned into a route to root in the same week — against a CISA patch deadline that fell on Sunday.

    • 5 min read
  • FortiBleed: your firewall, turned into a wiretap

    An update on the FortiGate exploitation story. SOCRadar's dismantling of FortiBleed shows 430,000 firewalls targeted and 110 million credentials harvested — by turning the appliance's own diagnostics into a credential tap. A board read, then the technical detail.

    • 8 min read
  • Prinz Eugen: the ransomware that takes your newest work first

    A new Go-based encryptor takes your most recently modified files first, inverting the assumption that fast response limits the damage. One data-broker turned operator, a UK firm already on the leak site. A board-level read, then a full technical teardown.

    • 15 min read
  • The week in cyber — 15 to 19 June 2026

    The NCSC calls it a contest, Parliament widens the net, and the actual ways in this week were an unpatched log server and a hijacked npm account.

    • 6 min read
  • Breached without being touched: the Klue attack and the case for digital sovereignty

    Two security firms were caught in a data theft this week without an attacker going anywhere near their systems. The way in was a sales tool they had connected to their CRM themselves. This is the clearest argument I have for owning your stack that I have seen in a while.

    • 8 min read
  • The criminals have a product team now: The Gentlemen and the industrialised EDR-killer

    A ransomware crew is shipping its affiliates a polished, standardised tool whose only job is to switch off your endpoint protection before the encryptor runs. The interesting part is not the malware. It is the business model.

    • 6 min read
  • The week in cyber — 8 to 12 June 2026

    Oracle PeopleSoft zero-day hits UK universities, Qilin ransomware exploits Check Point VPNs, Microsoft patches a wormable kernel flaw, and two regulatory deadlines land within days of each other.

    • 6 min read
  • The week in cyber — 1 to 5 June 2026

    A self-propagating worm hiding under Red Hat's npm name, two actively-exploited flaws at the edge and the core of the typical UK network, an Android zero-day in the June update, and the Cyber Security and Resilience Bill reaching its final Commons stage.

    • 5 min read
  • The week in cyber — 25 to 29 May 2026

    GCHQ's director on a 'moment of consequence', the TrapDoor supply chain campaign reaching into AI coding assistants, the Cyber Security and Resilience Bill still grinding through Report Stage, and quantum quietly becoming a 2026 planning item.

    • 6 min read
  • The nine-second problem

    An AI agent took nine seconds to delete a production database and its backups. The agent did what it was authorised to do. That is the finding.

    • 4 min read
$ finger peter

Get in touch

Email is fastest. If your message says who you are, what you would like, and a rough sense of when, you will get a useful answer within two working days.
EMAILcomms [at] peterbassill {dot} com
GITHUB@pbassill
CRESTEuropean Council · IR Pan Europe
LOCATIONUnited Kingdom · en_GB
no tracking · no third parties · stored only in my inbox
anti-abuse check: waiting for the form…