Patch notes and detection guidance for defenders

Independent analysis of vulnerabilities and intrusion campaigns that are actually being exploited — written for the people who have to patch and detect them.

Every post answers the same five questions: what broke, who is affected, is it being exploited in the wild, what to patch, and how to detect it. No proof-of-concept code, no exploitation walkthroughs.

Patch guidance Detection rules IOCs Sources cited

The CRA reporting clock starts on Thursday, and most summaries of it are wrong

From 11 September, a 24-hour reporting clock applies to actively exploited vulnerabilities — including in products you shipped years ago.

9 September 2026 · 7 min · PPD

Rogue ScreenConnect clients: hunt the session, not the filenames

Modified ScreenConnect clients that infect every host they connect to. The durable detection is in the audit log.

9 September 2026 · 7 min · PPD

The Telerik RCE chain: a two-month-old patch and a brand-new weapon

Progress fixed this in July. Public exploit code landed in September. EPSS still reads 0.5%.

9 September 2026 · 6 min · PPD

Magento CVE-2026-75650: patch, then rotate everything the key touched

Adobe shipped a hotfix for the Magento flaw exploited since 4 September. Applying it is the easy half.

8 September 2026 · 6 min · PPD