Editorial
Blog
In-house analysis and situation reports from the NEOSEC Intel newsroom. Deeper than Twitter, shorter than a whitepaper.
- · J. Benjamin Espagné
CVSS 10.0, Priority Score 0.00 — and Still This Week's Most Urgent Patch
N-able is patching out of band: CVE-2026-86218 allows code execution on the N-central server with no login at all. CVSS v4 10.0 — alongside an EPSS of 0.4 percent and a priority score of 0.00. Why both figures are correct, why the flaw still needs closing today, and what the case reveals about the limits of any external prioritisation.
schwachstellenmanagementrmmn-ableRead more → - · J. Benjamin Espagné
The First 24 Hours After an AI Agent Incident
An agent holding live credentials does something nobody authorised. What happens in the next 24 hours decides both the damage and your ability to notify — and conventional playbooks miss, because they reach for host isolation instead of revoking an identity. The sequence hour by hour, with the second clock that runs in parallel in Europe: 24 hours to the NIS2 early warning, and the logging duty under Article 12 of the AI Act.
ai-securityincident-responseagentenRead more → - · NEOSEC Intel Redaktion
OT Remote Access: How the VPN Became the Attack Surface
BeyondTrust puts more than half of 2024's ransomware incidents on a remote service as the entry point — a VPN appliance, an RDP server. In OT environments those are the same tunnels and jump hosts that keep production running, and they open the first door for attackers.
otnis2kritisRead more → - · NEOSEC Intel Editorial
Mirage2FA: The Victim Completes MFA Correctly — and the Attacker Takes the Session
ANY.RUN has documented Mirage2FA, a phishing kit rented out as a service that does not break the Microsoft 365 sign-in but relays it: the victim completes MFA correctly and the attacker keeps the session cookie. Why a password reset afterwards achieves nothing, what one mail-gateway rule removes — and why 1 September settles the decision regardless.
phishingaitmmicrosoft-365Read more → - · NEOSEC Redaktion
Ten Days, Eight Hours — and Your Logs Are Gone
The SIRIUS Report 2025 from Europol and Eurojust describes how investigators obtain digital evidence. For companies it holds more than the title suggests: it is about your own log retention, about how well a criminal complaint holds up — and about who has been on the receiving end of binding orders since 18 August.
e-evidencenis2dfirRead more → - · NEOSEC Threat Intel
Dysphoria: 296,000 IoT Devices Abused for DDoS and Residential Proxying
Shadowserver reports 296,000 compromised IoT devices, every entry rated CRITICAL. Dysphoria has grown from a DDoS botnet into relay infrastructure, and one variant has dropped the attack function altogether. Why 155 UPnP port mappings are the best detection signal, and what network owners should check now.
botnetiotthreat-intelRead more → - · NEOSEC Redaktion
Did Iran Take Its Cue from China? The Barati Arrest and the Mabna Institute
An Iranian hacker arrested in Montenegro, an eight-year-old US case, more than 31 terabytes of stolen research data. Kim Zetter asks whether Tehran began building an economic-espionage capability around 2013 — the same year Mandiant exposed China as APT1. What the case means for European universities and research institutions.
iranaptwirtschaftsspionageRead more → - · NEOSEC Redaktion
Google Ads as Malware Delivery: The MacSync Stealer Case
A Google ad impersonating Anthropic's Claude Code sends macOS users to a Google Sites page carrying an obfuscated terminal command. In six phases, browser passwords, cloud tokens and — where present — the seed phrase of a Ledger wallet end up with the attacker. What the case means for developers and their employers, and the one question to settle first after a suspected infection.
malvertisingmacosstealerRead more → - · NEOSEC Redaktion
Cybersecurity Is Survival
Howard Solomon's CSO Online piece says plainly what the industry thinks and rarely states: an organisation that still budgets security mainly as prevention is buying theatre. His most uncomfortable point lands squarely in the European scoping debate — companies work actively to avoid being seen as critical, because the label brings obligations and liability.
nis2resilienzcisoRead more → - · NEOSEC Intel-Redaktion
22,000 breaches – what they reveal about real incident preparedness
The Verizon DBIR 2026 analyses more than 22,000 confirmed security incidents across 145 countries. Three findings change the terms for mid-market organisations: exploitation of vulnerabilities is now the leading initial-access route for the first time, nearly half of all incidents run through a third party, and AI-assisted attackers are closing the patch gap faster than before.
incident-responseransomwaresupply-chainRead more → - · J. Benjamin Espagné
Trust Issues: How MCP Servers Can Hijack Your AI
Every MCP server is a trust boundary. Since April the specification has fixed authorization — which does nothing for tool poisoning or prompt injection. New since then: Microsoft's demonstration that poisoned tool descriptions are a general-purpose exfiltration technique, and the finding that nine of eleven MCP registries waved a malicious submission through unreviewed.
ai-securitymcpprompt-injectionRead more → - · J. Benjamin Espagné
The Augmented Analyst — and Why ISC2 No Longer Puts a Number on the Workforce Gap
ISC2 dropped its workforce gap estimate in 2025 — not because the gap narrowed, but because respondents consider skills more pressing than headcount. That changes the case for AI in the SOC. Plus the attack path few people mention: alert text is largely attacker-controlled, and the triage layer reads everything by definition.
ai-securitysocalert-fatigueRead more → - · J. Benjamin Espagné
48,185 CVEs: Why Prioritisation Is No Longer a Question of Diligence
48,185 CVEs were published in 2025, and nearly 10,000 in July 2026 alone. More important than the volume is what changed in April: the NVD now enriches only 15 to 20 percent of intake, and Mandiant puts the mean time to exploit at minus seven days. Why CVSS no longer carries prioritisation — and why the KEV catalogue does not measure what many read into it.
schwachstellenmanagementcveepssRead more → - · J. Benjamin Espagné
BSI C5:2026 — and How to Read a Cloud Attestation Properly
C5:2026 adds container management, confidential computing, post-quantum cryptography and substantially expanded supply chain criteria. More important than the additions is what to do with an attestation: type 2 rather than type 1, read the exceptions, check the scope — and work through the obligations the report assigns to the customer. Plus a correction: the reference to § 8a BSIG no longer holds after the German NIS2 transposition.
nis2compliancecloudRead more → - · J. Benjamin Espagné
XIEM® or Splunk: The Question Is Not the Tool, but Who Operates It
A comparison in our own interest, openly labelled as such. With a correction on licensing — Splunk now also bills by workload, not only by volume — and with the section missing from the original: when XIEM® is the wrong choice. The decisive question is not which SIEM is better, but who operates it the day after deployment.
siemxiemsplunkRead more → - · J. Benjamin Espagné
Detection Coverage: 21 Percent — and 13 Percent of Rules Never Fire
In production environments, detection rules exist for 21 percent of ATT&CK techniques — while the telemetry already ingested would support over 90 percent. And 13 percent of existing rules are broken and never fire. The second figure is the more dangerous one: in any heatmap it looks exactly like coverage.
detection-engineeringmitre-attacksiemRead more → - · J. Benjamin Espagné
Nineteen Days Without a Model: What the Mythos Suspension Teaches About AI Dependency
In April the subject was a model that finds vulnerabilities autonomously. In June, Mythos 5 and Fable 5 were disabled worldwide under US export controls — nineteen days, across every platform at once, non-US users first. The real lesson is therefore not about the speed of attacks but about the fact that an AI model is a supplier.
ai-securitylieferkettenis2Read more → - · J. Benjamin Espagné
"A Board Matter" Means Article 20: What NIS2 Requires of Management Personally
Since NIS2, "a board matter" is no longer a question of attitude but a set of duties with a citation. The decisive provision is not the much-quoted Article 21 but Article 20: approval, oversight — and a training obligation that applies to management itself, not only to staff. Plus six questions where the time taken to answer is already the answer.
nis2governancehaftungRead more →