peter bassill · operator
$ grep -l "tag:threat-intel" writing/

tag: threat intel.

7 pieces tagged threat intel, newest first. The full taxonomy is on the tag index.

2026·09·29 Patching is step five: inside the NetScaler zero-days Attackers exploited two Citrix NetScaler ADC and Gateway flaws for weeks before fixes shipped on 27 September. How CVE-2026-88771 turns a log line into a root shell, who is affected, and why the NCSC lists patching fifth. vulnerability management · incident response · patching · threat intel · board 12 min 2026·09·27 Critical is not the same as urgent: what 70,686 CVEs in 2026 actually ask of you Of 70,686 CVEs published between 1 January and 22 September, 161 are known to be exploited. What NVD, EPSS, CISA's catalogue and Exploit-DB say about severity, deadlines and the software attackers use, and a one-line triage rule. vulnerability management · patching · threat intel · research · board 19 min 2026·09·15 Aimed at a person, not a network: Iran's CHOSEN BRICK The NCSC, FBI and AIVD have published a joint advisory on CHOSEN BRICK, Windows malware Iranian state actors use to find, watch and expose dissidents, activists and journalists. A fake MRI result, a fake Norton, a Telegram bot, and a deliberate move from the work laptop to the home one. What it does, how to look for it, and what employers of people at risk should do this week. state-aligned · threat intel · spyware · social engineering · high-risk individuals · board 17 min 2026·07·17 Patch FortiSandbox by Sunday: when the security appliance is the hole CISA has told federal agencies to patch two actively-exploited FortiSandbox flaws by Sunday — both unauthenticated, CVSS 9.1 remote code execution. The malware sandbox is the way in. Why the KEV is your real triage list, and why your security appliances are the target. patching · vulnerability management · threat intel 7 min 2026·07·17 The TfL hackers were teenagers. Unusually, they were caught. Two young Britons — Thalha Jubair, 20, and Owen Flowers, 18 — jailed five and a half years each for the 2024 Transport for London attack: £29m of damage, 148 systems down, done with social engineering. The UK's largest cybercrime case — and, unusually, they were caught. threat intel · law enforcement · social engineering 8 min 2026·07·11 Three weeks with the door open A cybercrime crew backdoored 25,000 websites using nothing but public exploits — then left its own server open on the internet for three weeks. The exposed working directory shows an adversary far less polished, and far more industrialised, than its victims imagined. threat intel · web security · craft 8 min 2026·07·09 Ghosts and runners: living off GitHub Attackers have stopped bringing their own infrastructure and started borrowing GitHub's — dormant accounts aged for years to blend in, and CI runners turned into backdoors. A look at the ghost-account and hijacked-runner campaigns, and the dull controls that would stop them. supply chain · threat intel · craft 8 min

→ all tags  ·  all writing