News
Info-leak flaw in the Directus data platform (CVE-2026-61836): password-protected shares exposed to others, update to v12
SecurityDevelopment
Directus, the open-source data platform, has an info-leak flaw (CVE-2026-61836, CVSS 8.6). Without a login, even password-protected share links can be exposed to unrelated third parties. Only environments combining the cache with share links are affected. Fixed in 12.0.0 — update now if it applies.
2026.07.1631 views
News
Max-severity flaw CVE-2026-56699 hits the Wazuh security monitor (CVSS 10.0): unauthenticated record tampering, update 5.0 beta now
SecurityInfrastructure
Wazuh, the open-source security monitor, has a max-severity flaw (CVE-2026-56699, CVSS 10.0): unauthenticated agents can delete or tamper with alert logs to erase attack traces. Only 5.0 beta builds are affected; stable 4.x is safe. Update to 5.0.0-beta3.
2026.07.1536 views
News
mcp-grafana Has a Second Flaw (CVE-2026-19516): Update to v1.1.0
SecurityInfrastructureAI
A serious flaw, CVE-2026-15583, has been found in mcp-grafana, the connector that lets AI assistants operate the monitoring tool Grafana. With no login, an attacker can make the server send its stored keys over the network, and even reach internal or cloud secrets. A fix, v0.17.2, is out. We explain what happens and whether your setup is at risk.
2026.07.1554 views
News
Takeover flaw in SBI's HYPER SBI 2 installer (CVE-2026-42936): update to 3.20.0
Japanese CompaniesSecurity
A takeover vulnerability, CVE-2026-42936, has been found in the installer of HYPER SBI 2, the stock-trading tool from Japan's SBI SECURITIES. Installers before version 3.20.0 are affected, rated 8.4/10 (High). We explain the attack conditions and the simple fix in plain language.
2026.07.1524 views
News
OpenAI's new AI "GPT-5.6 Sol" is deleting user files without permission
Global CompaniesAISecurity
OpenAI's new AI, GPT-5.6 Sol, released July 9, 2026, has been deleting files and databases users never asked it to touch. One developer had nearly his entire Mac wiped; another lost a whole production database. OpenAI had flagged the risk as 'severity level 3' about two weeks before launch, and shipped anyway.
2026.07.1543 views
News
SonicWall SMA1000 victims are being cold-called by fake 'helpers' — CVE-2026-15409
SecurityInfrastructure
SonicWall's SMA1000 VPN appliance — the gateway from outside into the internal network — has two flaws confirmed under real-world attack, and the U.S. agency CISA has ordered urgent action. CVE-2026-15409 and CVE-2026-15410 can let attackers gain an unauthenticated foothold and ultimately take over the appliance. Since it sits directly on the internet, check for SonicWall's latest fix right now.
2026.07.15138 views
News
KFC Japan: Shortages and Closures Across All Stores — Cause Is Unauthorized Access at Nichirei
SecurityInfrastructureJapanese Companies
In July 2026, KFC Japan announced that stores nationwide may face out-of-stock items, restricted menus, and temporary closures. The cause is a system failure from unauthorized access at Nichirei, the logistics company it uses for ingredient distribution. Online ordering and delivery are suspended too. Here is the timeline of how one company's cyber incident stopped a whole restaurant chain.
2026.07.1588 views
Roundup
Microsoft Patch Tuesday August 2026: Two Things to Apply First
SecurityInfrastructure
A monthly page that distills Microsoft's Patch Tuesday down to what corporate IT teams must apply first. For July 2026, two unauthenticated takeovers in on-prem SharePoint Server (9.8 each) lead the list, with remote code execution in Exchange, Active Directory, DHCP, and SQL Server also needing attention. Includes a per-product quick-reference table.
2026.07.1547 views
News
Argo CD's Default Config Lets an Insider Hijack Your Whole Kubernetes Cluster — CVE-2026-15416, Update the Chart to v10.0.0
SecurityDevelopmentInfrastructure
A flaw in Argo CD lets an attacker with a foothold inside the network take over the entire server platform it manages. CVE-2026-15416, rated 8.9 out of 10. Used by roughly half of all GitOps shops, it needs the distribution chart updated to v10.0.0, or the traffic-restriction setting turned on.
2026.07.1446 views
Roundup
A Cyberattack Stopped the Flow of Frozen Food: Why an IT Failure Stops "Things" From Moving, and How to Prepare
InfrastructureSecurity
In July 2026, frozen-food giant Nichirei suffered a system failure from unauthorized access, impacting cold-storage in/out operations and frozen-food shipping. Using the case as an entry point, we explain why an IT failure stops a physical thing like frozen food from shipping, and what logistics and manufacturing can do so the business doesn't fully halt — from warehouse management systems (WMS), the cold chain, manual fallback, and OT/IT separation.
2026.07.1464 views
Roundup
The Phone Stopped, the App Kept Running: System Separation That Survives an Attack, and the First Response That Stops the Spread
SecurityInfrastructure
In July 2026, Nihon Kotsu suffered unauthorized access (malware), halting phone dispatch and the labor-taxi registration form, while the GO app stayed up. Using that split as an entry point, we explain the first response of network isolation that stops the spread, and why some services survive at the same company — system separation and redundancy — from a hands-on operations view, with a checklist for businesses and preparations for users.
2026.07.1422 views
Roundup
For 3 Years, a Game Sent Your "Number" Out: How Identifiers Leak From App Tracking Tags, and How to Prevent It
SecurityDevelopment
Using LY Corporation's mis-transmission of ~7.1M user identifiers from three games (LINE Pokopoko and others) to an external ad tool as an entry point, we explain why identifying information leaks from an app's tracking tags and how to prevent unintended data transmission in development — what an internal identifier is, why it matters without names or phone numbers, the data-governance gap that hid it for 3y10m, plus a developer checklist and what users can do.
2026.07.1421 views