Skip to content

Polymath Central

Thoughts and musings of David Greenberg, a polymath

Cybersecurity

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

September 8, 2026 Blogmaster

Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users’ personal information, including their HIV…

Cybersecurity

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

September 7, 2026 Blogmaster

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. “Requiring prior administrative or code execution access,…

Technology

The complex corporate web behind a $3.2 billion AI data center

September 7, 2026 Blogmaster

In early June, a fire broke out in a still-unfinished building at the Lake Mariner data center in Somerset, New York, exposing just how little the local fire department knew…

Cybersecurity

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

September 7, 2026 Blogmaster

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images…

Cybersecurity

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

September 7, 2026 Blogmaster

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing,…

Cybersecurity

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

September 7, 2026 Blogmaster

A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and…

Cybersecurity

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

September 7, 2026 Blogmaster

Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated…

Cybersecurity

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

September 7, 2026 Blogmaster

If managing security across multiple cloud providers wasn’t hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations…

Technology

The complex corporate web behind a $3.2 billion AI data center

September 7, 2026 Blogmaster

In early June, a fire broke out in a still-unfinished building at the Lake Mariner data center in Somerset, New York, exposing just how little the local fire department knew…

Cybersecurity

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

September 7, 2026 Blogmaster

Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able’s incident notice says the flaw has been exploited in…

Posts pagination

1 2 … 352

Polymath Central

Thoughts and musings of David Greenberg, a polymath

Proudly powered by WordPress | Theme: Newsup by Themeansar.