Security Unlocked

Midweek

Threat Intelligence

The Patch-Gap Playbook: A Windows Zero-Day Gets Its Attribution

Volexity's research on UTA0560/BlueMoon turns a Monday footnote into a live espionage campaign, and it shows exactly how much lead time a well-resourced actor gets from the gap between a fix landing in a code repository and that fix reaching a user's machine.

Threat Intelligence

AI Agent Swarms Just Broke the Economics of Mass Intrusion

A Russian-speaking actor ran hundreds of autonomous AI agents through a full PaperCut-to-domain-admin intrusion chain across 395 organizations, and some agents ignored their own operator's targeting instructions.

Threat Intelligence

The Minnesota Water Attack Is Not a Ransomware Story

A coordinated OT cyberattack across 30-plus Minnesota water utilities signals a deliberate campaign against municipal infrastructure, while an actively exploited Fastjson zero-day with no fix available puts finance and healthcare in an unfamiliar position: mitigate or accept risk, because a patch is not coming.

Threat Intelligence

AI Scanning Broke Patch Tuesday. Gold Eagle Is Washington's Admission It Can't Keep Up.

Microsoft's July Patch Tuesday landed at 570 CVEs with two actively exploited zero-days, more than four times the forecasted volume, because AI code scanning is now generating vulnerabilities faster than the industry can triage them. Gold Eagle is the government's acknowledgment that the system is breaking.

Threat Intelligence

Cloud VM Isolation Breaks at the Hypervisor; North Korean Actors Weaponize Maintainer Trust

CVE-2026-53359 (Januscape), a 16-year-old Linux KVM flaw enabling VM-to-host escape, landed patches July 4 while the North Korean PolinRider supply chain campaign hit 100+ legitimate packages through stolen maintainer credentials, graduating beyond typosquatting into a method that subverts the trust signals defenders rely on.