Our Blog

Research, analysis, and practical guidance on cybersecurity and AI security from our London team.

Mobile & Messaging Security30 September 2026

Device Linking as Wiretap: German Customs Reads WhatsApp and Signal

German customs investigators are reportedly reading suspects' WhatsApp and Signal chats by linking a second device to the account. The encryption is never broken, because the linking feature delivers the messages to the new device by design.

end-to-end-encryptionwhatsappsignal
3 min readRead
AI Security29 September 2026

OpenAI DevDay 2026: the security questions behind agents, plugins and sign-in

OpenAI's DevDay keynote paired computer-use agents, an app marketplace and a security scanning product. Here is what security teams should ask before adopting any of them.

openaiai-agentsllm-security
4 min readRead
Vulnerabilities & Exploitation29 September 2026

CVE-2026-87902: Actively Exploited, but Preconditions Decide Your Real Exposure

WordPress core's CVSS 9.2 path traversal drew exploitation attempts within hours of the patch. It is also a case study in why a vulnerable version is not the same as an exploitable one — the route to code execution depends on a site's theme layout and PHP configuration.

wordpresscve-2026-87902path-traversal
6 min readRead
Vulnerabilities & Exploitation29 September 2026

Citrix NetScaler zero-days CVE-2026-88771 and -88772 are under active attack

CISA has added two critical NetScaler ADC and Gateway flaws to its KEV catalog, and each can independently give an attacker remote code execution. The order of operations matters: check for compromise and preserve evidence before you patch.

citrixnetscalerzero-day
3 min readRead
Cryptography28 September 2026

RSA Forgery Attack: Faster Than Factoring, But Not Against Padded Signatures

A newly implemented attack on RSA signatures is making headlines as a way to 'break RSA' without factoring. The underlying idea dates from 2007, and it only threatens unpadded signatures, which is not how RSA is deployed in practice.

rsacryptographydigital-signatures
3 min readRead
Web3 Security28 September 2026

Payy Network's Ethereum bridge drained of $1.83M USDC: what is confirmed

Payy says its Ethereum bridge contract was drained of its full balance and that the cause was not a compromised key, social engineering or its off-chain infrastructure. The root cause is still undisclosed, so here is what the public record supports and what bridge teams should check.

web3bridge-securitysmart-contracts
3 min readRead
Web3 & DeFi Security27 September 2026

Meter's Bridge Mint Bug: $2.3M in Unbacked Tokens, an 88% Price Crash

A flawed validation check in Meter Passport let an attacker mint unbacked wrapped MTR and MTRG, dump them on a DEX, and crater both tokens — forcing the chain and bridge offline.

bridge-securitydefismart-contract-security
4 min readRead
Web3 & Smart Contract Security27 September 2026

Magic Eden's Retired Payment Processor Bled $1.8M via Zombie Approvals

A bug in a payment processor Magic Eden stopped using in 2024 let attackers drain NFTs and wETH from old wallet approvals — even after the marketplace itself was shut down.

web3-securitynft-securitytoken-approvals
4 min readRead
Threat Intelligence26 September 2026

Lunex Stealer: BYOVD With an AMD Driver Blinds EDR, Then Steals Credentials

Ontinue's analysis of the Lunex malware-as-a-service platform shows a four-stage chain that starts with a fake CAPTCHA and uses a vulnerable AMD driver to neutralise endpoint security without killing it.

infostealerbyovdclickfix
3 min readRead
AI Security26 September 2026

Coding agents make software engineering harder, says Simon Willison

Simon Willison argues that coding agents raise the bar on discipline and knowledge rather than lowering it. Here is what that means for security teams.

coding-agentsai-securityllm-security
3 min readRead
AI Security25 September 2026

Anthropic's AI Misuse Report: Agents Do the Work, Humans Steer

Anthropic's report on detected Claude misuse describes AI agents handling reconnaissance, exploitation and data theft while humans pick targets and review output. Here is what security teams should take from it.

ai-securitythreat-intelligencellm-misuse
3 min readRead
Cloud Security25 September 2026

Cloudflare Containers Flaw Exposed Other Customers' Leftover Disk Data

A thin-provisioning misconfiguration let one Cloudflare Containers tenant read residual data from disk blocks previously used by other customers. Cloudflare says it has fixed the flaw and found no evidence of exploitation.

cloudflarecontainersmulti-tenancy
3 min readRead
Vulnerability Management24 September 2026

Eight exploited CVEs hit Linux, F5, Check Point, Arista and Zyxel

A single day's CVE roundup lists eight vulnerabilities as confirmed exploited, and most sit in infrastructure that security teams rely on for control and visibility. Here is how to triage them.

cveknown-exploitednetwork-security
3 min readRead
AI & Agent Security24 September 2026

Plugin4Shell: A Zero-Click RCE in Claude Code, Codex, Copilot and Gemini CLI

A SHA-pinning bypass lets a malicious marketplace plugin silently swap in attacker code across four major AI coding agents — with no click required, and no fix yet for two of them.

ai-securitysupply-chain-securityai-coding-agents
4 min readRead
AI Security23 September 2026

Self-Jailbreaking: When Reasoning Training Quietly Breaks LLM Safety

A new paper shows that fine-tuning reasoning models on ordinary math and code tasks can make them talk themselves past their own safety guardrails — no adversarial prompt required.

ai-securityllm-securityai-alignment
4 min readRead

Archive

Browse all 197 posts by month

Topics

Llm Security54Ai Security44Ai Governance35Ai Red Teaming29Prompt Injection28Agentic Ai25Incident Response16Iso 4200115Supply Chain15Web313Supply Chain Security13Ai Agents12Devsecops11Vulnerability Management10Web3 Security10Defi Security10Smart Contracts9Defi9Threat Intelligence9Patch Management8Ai Agent Security7Cryptography6Rce5Bridge Security5Smart Contract Security5Anthropic5Cloud Security5Vulnerability Disclosure5Owasp5Llm Agents5Sandbox Escape5Project Zero5Zero Day4Cisa Kev4Datasette4Sandboxing4Claude4Privilege Escalation4Software Supply Chain4Npm4Vibe Coding4Agentic Coding4Android4Openai3Agent Security3Pypi3Oracle Manipulation3Python3Windows Security3Vulnerability Research3Data Exfiltration3Solana3Claude Code3Social Engineering3Malware3Secure Code Review3Browser Security3Secrets Management3Mobile Security3Surveillance2Rsa2Infostealer2Clickfix2Coding Agents2Secure Development2Data Exposure2Cve2Network Security2Mcp2Webassembly2Cisco2Cve 2026 764602Gemini2Ai Safety2Credential Theft2Open Source Security2Sqlite2Chain Of Thought2Technical Debt2Legacy Systems2Appsec2Database Security2Prompt Engineering2Attack Surface2Chatgpt2Open Weight Models2Blockchain2Governance Attack2Iot Security2Ai Infrastructure2Developer Tools2Human Oversight2Deepseek2Post Quantum Cryptography2Github Actions2Ci Cd Security2Hardware Wallets2Bitcoin2Facial Recognition2Computer Vision2Privacy2Llm Tooling2Cryptanalysis2Phishing2Account Takeover2Ai Supply Chain2Physical Security2Flash Loan Attack2Tls2Compliance2Open Weights2Ai Generated Code2Malware Analysis2Pki20 Click2Bridge Exploit2End To End Encryption1Whatsapp1Signal1Device Linking1Devday1Application Security1Wordpress1Cve 2026 879021Path Traversal1Citrix1Netscaler1Digital Signatures1Signature Forgery1Pkcs1Stablecoin1Meter1Nft Security1Token Approvals1Byovd1Malware As A Service1Edr Evasion1Llm Misuse1Cloudflare1Containers1Multi Tenancy1Known Exploited1Linux Kernel1Ai Coding Agents1Ai Alignment1Reasoning Models1Explainability1Serverless1Excessive Agency1Cve 2026 764611Edge Security1Cisco Ise1Acronis1Actively Exploited1Session Management1Authentication1Cookies1Github Oauth1Model Weights1Ise1Authentication Bypass1Issabel1Cve 2026 890261Unauthenticated Rce1Hardcoded Credentials1Pbx Security1Iran1Mois1Spyware1Telegram1Llm Jailbreak1Gpt 6 Astra1Risk Assessment1Browser Extensions1Oauth1Twitch1Passkey Phishing1Aitm1Device Code Phishing1Microsoft 3651Business Email Compromise1Ai Transparency1Data Privacy1Audit Trails1Uma Protocol1Optimism1Smart Contract Risk1Rubygems1Incident Disclosure1Observability1Monkey Patching1Authorization Bypass1Ai Assisted Audit1Patch Tuesday1Race Conditions1Kernel Security1Fuzzing1Generative Ai1Deepfakes1Content Provenance1C2pa1Adversarial Ai1Computer Vision Security1Surveillance Tech1Alpr1Security Debt1Secure Sdlc1Bitcoin Sidechain1Liquid Network1Vmware1Vm Escape1Virtualization Security1Developer Tooling1Postgresql1Cve 2026 64711Dprk It Workers1Insider Threat1Remote Hiring Security1Lazarus Group1Sonicwall1Cryptomining1Ai Infrastructure Security1Llm Guardrails1Gru1Sandworm1Apt281Russia1Openai Codex1Cronos1Legal Tech1Crypto Payments1Model Tampering1Price Manipulation1Base1Exploit Postmortem1Cosmos1Defi Exploit1Genai Abuse1Fraud1Unit421Ransomware1Black Hat 20261Security Market1Vendor Landscape1Identity Security1Linux1Elf1Binfmt Misc1Rag Security1Soc1Siem1Android Malware1Badbox1Automotive Security1Edr Bypass1Living Off The Land1Kernel Drivers1Windows Defender1C2 Framework1Langgraph1Ai Search1Geo1Autonomous Agents1Microvm1Code Execution1Macos Security1Endpoint Detection1Open Source1Llvm1Ray1Dns Rebinding1Training Data1Data Provenance1Xss1Svg1Sanitization1Coldfusion1Adobe Commerce1Campaign Classic1Command Injection1Patch Advisory1Chrome Extensions1Vpn Security1Adversary In The Middle1Dao Security1Explainable Ai1Military Ai1Move To Earn1Tokenomics1Crypto Risk1Due Diligence1Api Security1Ai Policy1Ai Risk Management1Model Vetting1Crypto Scams1Brand Impersonation1Xrp1Aws1Ai Security Research1Jailbreak1Kev Catalog1Langflow1Apache Tomcat1Exchange Security1Cross Chain1Ml Kem1Ml Dsa1Python Security1Crypto Agility1Entropy1Crypto Security1Shai Hulud1Servicenow1Cve 2026 68751Adversarial Ml1Privacy Tech1Llm Cli1Ai Misuse1Secure Coding1Kubernetes Security1Rng1Key Management1Sandbox Isolation1Grapheneos1Border Search1Mobile Forensics1Duress Pin1Digital Rights1Uefi1Secure Boot1Eset1Nist1Post Quantum1Llm Research1Teamcity1Cicd Security1Botnet1Blockchain C21Ddos1Sharepoint1Cve 2026 505221On Prem Security1Api Abuse1Denial Of Wallet1Token Theft1Otp Interception1Insurance1Fastjson1Java1Spring Boot1Cve 2026 167231Active Directory1Ad Cs1Cve 2026 541211Kerberos1Distillation1Biometric Surveillance1Data Retention1Hugging Face1Mfa1Identity Theft1Cardano1Local Llms1Mlx1Data Sovereignty1Macos1Flash Loan1Smart Contract Audit1Allbridge17 Zip1Cve 2026 142661Xz1Heap Overflow1Vault Exploit1Shadow Ai1Ai Risk1Openssl1Denial Of Service1Data Protection1Cli Tools1Broken Access Control1Penetration Testing1Web Application Security1Architecture1Accountability1Vendor Risk1Ai Browsers1Typosquatting1Smart Contract Exploit1Vault Accounting1Tls Certificates1Domain Validation1Ca Browser Forum1Web Security1Sycophancy1Windows Exploitation1Google1Offensive Security1Pixel1Kernel Exploit1Mediacodec1Llm Generated Code1Dom Xss1Web Components1Google Project Zero1Google Play1App Security1Anssi1Critical Infrastructure1Uac Bypass1Win32k1Tool Calling1Export Controls1National Security1Open Source Ai1Model Provenance1Current Ai1Cognitive Debt1Dspy1Evals1Google Workspace1Aztec Connect1Zero Knowledge1Ai Surveillance1Mass Surveillance1Browser Automation1Ssh Security1Code Generation1Drone Security1Autonomous Systems1Law Enforcement Technology1Cyber Physical Security1Ethereum L21Sgx1Secret Network1Axelar1Infinite Mint1Mev1Ethereum1Ai Evasion1Ci Cd1Role Confusion1Dependency Management1Packaging1Smart Glasses1Meta1Law Enforcement1Multi Agent Security1Llm1