weekly
[SIGNALS WEEKLY] Exploited Edge, Social Engineering, and Subtle Evasion
A Teams message from “IT” can now be the first step in a domain takeover: remote-support session, silent install, then AD and WinRM movement.
weekly
A Teams message from “IT” can now be the first step in a domain takeover: remote-support session, silent install, then AD and WinRM movement.
weekly
Three clocks are running: active PaperCut exploitation, QTFY infrastructure rebuilding after disruption, and AI-agent activity outpacing log governance. Hunt the transitions—not the tidy incident story.
weekly
Exposed management planes are becoming the shortest path from ordinary web access to operational impact. Ray CVE-2025-62593 is now in CISA’s KEV, while new Haiwell and Metasys flaws put AI compute and OT interfaces on the same uncomfortable list.
weekly
Edge exploits, helpdesk vishing, stolen CI tokens, and decentralized C2 share one objective: scale access while shrinking defender visibility. Hunt the transitions, not just the opening IOC.
weekly
Zero-click Zimbra access, exposed PLC tampering, and Teams-to-ransomware chains compress the defender’s window. Prioritize server logs, controller-change evidence, and external admin-surface discovery.
forecasts
We put a 30% chance on two public FCEB cases proving post-deadline edge exploitation by year-end.
weekly
The perimeter kept the keys. Edge appliances and OT switches are becoming the shortest path from exposure to stolen identity and ransomware. The plumbing became the persistence layer.
gametheory
Nine actively exploited flaws show why patching closes an entry point—but not necessarily the incident.
weekly
OAuth consent made SaaS data theft look normal. Niche web plugins kept handing attackers first doors. OT debug ports reminded everyone that “engineering access” can age into exposure.
weekly
The boring stack moved. CUCM WebDialer. Splunk sidecar. Messaging recovery keys. Very normal. Very annoying.
weekly
The control plane blinked. Management surfaces are still getting treated like furniture.
weekly
The management plane blinked. Everyone treated it like plumbing until the attacker used it like a front door. PeopleSoft PSEMHUB, REDCap, VPN gear, SD-WAN managers, logging sidecars — different products, same pattern. The exposed control layer keeps turning into the incident path.