Rogue ScreenConnect clients: hunt the session, not the filenames

Modified ScreenConnect clients that infect every host they connect to. The durable detection is in the audit log.

9 September 2026 · 6 min · PPD

The Telerik RCE chain: a two-month-old patch and a brand-new weapon

Progress fixed this in July. Public exploit code landed in September. EPSS still reads 0.5%.

9 September 2026 · 6 min · PPD

Magento CVE-2026-75650: patch, then rotate everything the key touched

Adobe shipped a hotfix for the Magento flaw exploited since 4 September. Applying it is the easy half.

8 September 2026 · 6 min · PPD