cat newsletter.md
One email each morning
Every story published in the previous twenty-four hours, with the same opening summary that appears on the site. No roundups of other people's writing, no sponsored items, nothing that was not published here that day.
What you are agreeing to
- One email a day, at 07:30 IST — and only when something was published in the preceding day. A quiet day means no email rather than a filler one.
- Titles and summaries, not full articles. The email is a list; the writing stays on the site.
- Confirmation first. Subscribing sends one email with a link. Nothing else arrives until that link is clicked, so an address typed by somebody else never ends up on the list.
- One click to leave. Every email carries an unsubscribe link that works without a login or a reply.
- The address is used for this and nothing else. It is not sold, shared or used to advertise. See the privacy policy.
What it looks like
The stories from 2026-10-08, in the order the digest sends them. This is the email, not an illustration of one.
Root Notes
Breaches, patches and the infrastructure underneath — in five minutes.
- The ransomware affiliate ran his commands through an AI assistant's tool protocol, then scanned the internet for more of them
CloudSEK documents a Gentlemen ransomware affiliate who wired Model Context Protocol into his attack chain as an execution channel, reached every victim through stolen CI/CD secrets, and published the proceeds on his own leak site rather than the gang's. The investigation started with an open directory he left unauthenticated.
- Nobody broke into Denmark's population register — a company allowed to search it looked up 8.8 million people
Danish authorities say unidentified parties misused a private company's legitimate access to the Central Person Register and stayed inside the limits that access permits. Names, addresses and CPR numbers for 8.8 million people, roughly four fifths of the register, were retrieved over about ten days in September.
- The command server's address is four words in a poem, and moving the botnet means editing the poem
Lumen's Black Lotus Labs tracked a malware family that does not carry its command-and-control address. It fetches a poem from GitHub, pulls four words out of fixed positions, and looks them up in a dictionary compiled into the binary. The operator has rewritten the poem eleven times since April.
- Kibana let one tenant claim another's data stream, and removing the package does not give it back
A Kibana user with delegated package-management rights, and no Elasticsearch administrative privileges, could install a package that claimed a data stream identifier already belonging to someone else. Ownership was never checked, so another tenant's telemetry could be redirected through infrastructure the attacker controlled.
- The host key check ran, and passed, on a curve the attacker chose for it
wolfSSH never verified that the elliptic curve in a server's host key matched the algorithm both sides had just negotiated. A machine-in-the-middle could swap in a key on a different curve, sign with its own private key, and be accepted with no error. Fixed in 1.6.0 — and it needs one more condition that is common in embedded code.
- Two hours passed between the proof of concept going public and the first attempt landing in a honeypot
watchTowr published technical detail and working exploit code for the Atlassian file-read flaw. Previdian's honeypots saw exploitation attempts within two hours. Yesterday we argued the advisory's stated limitation was not one; what has changed since is that nobody even has to work the path out.
Unsubscribe
subscribe --daily
One email each morning. No filler.
Would rather not hand over an address? The same stories go out on RSS, and all 342 of them are in the archive.