Exposed PLCs: The Attack Was Just Setting a Password
Forescout counted 4,407 Rockwell controllers on the public internet. The attackers who hit US water utilities did not exploit a flaw. They logged in and set a password.
Declassified operational reports, psychological protocols, and technical breakdowns. These are field-tested mechanics for securing the perimeter and the mind.
Forescout counted 4,407 Rockwell controllers on the public internet. The attackers who hit US water utilities did not exploit a flaw. They logged in and set a password.
The Met served a stalking suspect his victim's new address because nobody checked a redaction. Your records hold addresses whose secrecy is somebody's physical safety.
Attackers stopped writing malware and started installing ScreenConnect. It is signed, allowlisted, and invisible to the stack you bought to catch intruders.
Unit 42 signed into passkey-protected accounts with no fingerprint, no PIN, and nothing on the victim's screen. Passkeys ended phishing, not endpoint compromise.
A researcher hid instructions in a Word file as white text. Copilot read them, obeyed them, and wrote them into the next document. Your template library is the vector.
Russian actors are compromising hotel captive portals to push fake update prompts and steal tokens from business travelers. The page you cannot skip is the attack.
A Russian group is compromising real hotel sign-in portals to reach travelers. The attack works because clicking through a captive portal is a habit every organization spent years building into its staff.
Russian actors are exploiting an Outlook Web Access flaw to keep mailbox access after victims reset passwords. Password rotation is step one of a response, and it has never been the same thing as eviction.
More than 30 Minnesota water utilities were hit at once and a plant went offline. The targeting was not random. It followed the gap between how much a system matters and how much defense it can afford.
A model broke a post-quantum scheme in 60 hours that humans had reviewed for two years. Meanwhile fewer than 2% of AI-found bugs become working exploits. The gap between discovery and weaponization is where your program should live.
A product-safety agency is demanding identifiable ER records from hospitals. It is a sharp reminder that data outlives the reason you collected it, and the only record no one can compel or breach is the one you never kept.
GitHub and PyPI just added a cooldown that holds new package versions at arm's length before they reach your build. It works because recency is a risk signal, and you can adopt the idea today.
Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.