Our Blog
Research, analysis, and practical guidance on cybersecurity and AI security from our London team.
Device Linking as Wiretap: German Customs Reads WhatsApp and Signal
German customs investigators are reportedly reading suspects' WhatsApp and Signal chats by linking a second device to the account. The encryption is never broken, because the linking feature delivers the messages to the new device by design.
OpenAI DevDay 2026: the security questions behind agents, plugins and sign-in
OpenAI's DevDay keynote paired computer-use agents, an app marketplace and a security scanning product. Here is what security teams should ask before adopting any of them.
CVE-2026-87902: Actively Exploited, but Preconditions Decide Your Real Exposure
WordPress core's CVSS 9.2 path traversal drew exploitation attempts within hours of the patch. It is also a case study in why a vulnerable version is not the same as an exploitable one — the route to code execution depends on a site's theme layout and PHP configuration.
Citrix NetScaler zero-days CVE-2026-88771 and -88772 are under active attack
CISA has added two critical NetScaler ADC and Gateway flaws to its KEV catalog, and each can independently give an attacker remote code execution. The order of operations matters: check for compromise and preserve evidence before you patch.
RSA Forgery Attack: Faster Than Factoring, But Not Against Padded Signatures
A newly implemented attack on RSA signatures is making headlines as a way to 'break RSA' without factoring. The underlying idea dates from 2007, and it only threatens unpadded signatures, which is not how RSA is deployed in practice.
Payy Network's Ethereum bridge drained of $1.83M USDC: what is confirmed
Payy says its Ethereum bridge contract was drained of its full balance and that the cause was not a compromised key, social engineering or its off-chain infrastructure. The root cause is still undisclosed, so here is what the public record supports and what bridge teams should check.
Meter's Bridge Mint Bug: $2.3M in Unbacked Tokens, an 88% Price Crash
A flawed validation check in Meter Passport let an attacker mint unbacked wrapped MTR and MTRG, dump them on a DEX, and crater both tokens — forcing the chain and bridge offline.
Magic Eden's Retired Payment Processor Bled $1.8M via Zombie Approvals
A bug in a payment processor Magic Eden stopped using in 2024 let attackers drain NFTs and wETH from old wallet approvals — even after the marketplace itself was shut down.
Lunex Stealer: BYOVD With an AMD Driver Blinds EDR, Then Steals Credentials
Ontinue's analysis of the Lunex malware-as-a-service platform shows a four-stage chain that starts with a fake CAPTCHA and uses a vulnerable AMD driver to neutralise endpoint security without killing it.
Coding agents make software engineering harder, says Simon Willison
Simon Willison argues that coding agents raise the bar on discipline and knowledge rather than lowering it. Here is what that means for security teams.
Anthropic's AI Misuse Report: Agents Do the Work, Humans Steer
Anthropic's report on detected Claude misuse describes AI agents handling reconnaissance, exploitation and data theft while humans pick targets and review output. Here is what security teams should take from it.
Cloudflare Containers Flaw Exposed Other Customers' Leftover Disk Data
A thin-provisioning misconfiguration let one Cloudflare Containers tenant read residual data from disk blocks previously used by other customers. Cloudflare says it has fixed the flaw and found no evidence of exploitation.
Eight exploited CVEs hit Linux, F5, Check Point, Arista and Zyxel
A single day's CVE roundup lists eight vulnerabilities as confirmed exploited, and most sit in infrastructure that security teams rely on for control and visibility. Here is how to triage them.
Plugin4Shell: A Zero-Click RCE in Claude Code, Codex, Copilot and Gemini CLI
A SHA-pinning bypass lets a malicious marketplace plugin silently swap in attacker code across four major AI coding agents — with no click required, and no fix yet for two of them.
Self-Jailbreaking: When Reasoning Training Quietly Breaks LLM Safety
A new paper shows that fine-tuning reasoning models on ordinary math and code tasks can make them talk themselves past their own safety guardrails — no adversarial prompt required.