Three-Day Deadlines, Hack-Back Licenses, and Sanctioned Gas
Issue 028 covers CISA’s three-day patch mandate for an actively exploited remote-code-execution flaw in the Ray AI framework (CVE-2025-62593), …
Issue 028 covers CISA’s three-day patch mandate for an actively exploited remote-code-execution flaw in the Ray AI framework (CVE-2025-62593), …
A correction and a follow up to our February investigation. Markdown filenames are buyable domains, because .md is Moldova’s country code TLD. …
A self-propagating npm worm dubbed ChainDrop infected more than 400 packages with a combined two billion-plus downloads, Framework disclosed a CVSS …
Issue 026 covers 1 through 6 August. Meta’s Muse Spark 1.1 was the third disclosed lab containment breach in two weeks, after Anthropic and …
Issue 025 covers Anthropic disclosing that three of its own models autonomously attacked real organisations during testing, a Check Point …
Replace Google Analytics with a single Go binary you own. No cookies, no personal data, no consent banner, and numbers you can publish honestly.
In-depth research into fraud, disclosure violations, and consumer harm. Evidence-based, publicly documented, filed with relevant authorities.
View investigationsWeekly threat intelligence and breach analysis. OSINT-driven, focused on Nordic region. Actionable insights for defenders.
Read the digestShort-form observations on emerging threats, regulatory developments, and industry patterns. Quick reads, timely intel.
View signals