Author: Gary Behan

Software engineer and video game uber-nerd.

The Veradigm patient data breach disclosed to the U.S. Securities and Exchange Commission (SEC) has now attracted a ransomware claim, a class action settlement, and a growing list of questions about a company that has been here before. Veradigm, the Chicago-based healthcare technology company formerly known as Allscripts Healthcare Solutions, says an attacker obtained credentials from a third-party vendor’s environment and used them to copy patient data through a limited API reserved for customer services. The stolen data includes personal details and Social Security numbers (SSNs) for some patients. Clinical or medical information was not affected. Veradigm told the SEC…

Read More

More than 36,000 internet-facing instances of Plex Media Server unpatched flaws are sitting wide open to attack, with no CVE identifiers assigned yet and no easy way for the broader security community to track the vulnerabilities. That last part is the uncomfortable operational reality: no CVE means most automated scanners, vulnerability-management dashboards and enterprise patch-prioritisation tools are functionally blind to the risk.Plex issued its warning roughly a week before this writing, urging all server owners and desktop users to update immediately. The flaws affect Plex Media Server v1.43.2 and earlier. The company has asked users to upgrade to version 1.43.3,…

Read More

Microsoft September 2026 Patch Tuesday has set an unwelcome record: 966 vulnerabilities patched in a single update cycle, including two actively exploited zero-days. That figure eclipses every previous Patch Tuesday in the company’s history, and the sheer scale of it is starting to raise questions about what is driving the volume. A Record-Breaking Microsoft September 2026 Patch Tuesday Of the 966 flaws addressed, 105 are rated Critical. Within that Critical tier, 81 are remote code execution vulnerabilities, 20 are elevation of privilege, two are information disclosure, and one is a security feature bypass. Across all severity levels, the breakdown runs…

Read More

Microsoft has confirmed that the August 2026 security update can trigger a Windows Server 2016 CompatTelRunner crash on systems where the Compatibility Appraiser diagnostic service is running. The good news, if you can call it that, is that the crashes are cosmetically ugly but functionally harmless, at least according to Microsoft itself.The issue manifests as recurring Application Error events in the Windows Event Log: Event ID 1000, with exception code 0xc0000409, tied to the CompatTelRunner.exe process. That process belongs to Microsoft Compatibility Appraiser, a background component of Windows Compatibility Telemetry that checks whether a device meets the hardware and software…

Read More

Attackers are deploying AI multi-agent credential theft frameworks that compress a full attack lifecycle into hours, stripping out the human decision-making that defenders once relied on to buy themselves time. According to Google’s Threat Intelligence Group (GTIG), drawing on telemetry from Mandiant incident response engagements and live platform defences, AI agents are now coordinating vulnerability scanning, credential harvesting, IP rotation, and real-time troubleshooting with minimal human oversight.’Over the past quarter, threat actors have moved beyond simple prompt-based LLM interactions to integrate AI capabilities into multiple stages of an attack lifecycle,’ GTIG notes. ‘Groups are increasingly upgrading these workflows, creating highly…

Read More

A Vietnam APIS data leak has left more than 220 million passenger and crew records accessible online, including passport numbers, flight details, and personal travel histories spanning nearly a decade. The database, which appears linked to a Vietnamese organisation, was reachable through a chain of security misconfigurations rather than a single, obvious vulnerability.Advance Passenger Information Systems (APIS, for those who haven’t had to fill out an embarkation card recently) are the infrastructure governments and airlines use to collect identity, passport, and itinerary data before travellers arrive at or depart from a country. That makes the contents of an exposed APIS…

Read More

A zero-day vulnerability tracked as StyleSmuggler Magento zero-day has been actively exploited in the wild, deploying a Linux backdoor on affected e-commerce servers, and Adobe has now released an emergency hotfix for the flaw, assigned CVE-2026-75650, according to Diamatix. The first recorded exploitation incident dates to 4 September, hitting a server running the latest available security updates, meaning there was no patch to apply and no obvious line of defence.E-commerce security company Sansec discovered the vulnerability and published its findings, noting that Adobe Enterprise Support had confirmed it was working on a fix. Adobe’s next scheduled security release at the…

Read More

A phishing-as-a-service (PhaaS) platform called BigBear 2.0 MFA bypass has compromised 258 organisations and exfiltrated more than 5,000 Microsoft 365 credentials, according to researchers at cybersecurity company CloudSEK. The operation was discovered in June 2026 after CloudSEK gained access to the platform’s administrative control panel, according to eSecurityPlanet.How the BigBear 2.0 MFA Bypass WorksAt its core, BigBear 2.0 uses an Evilginx2-based adversary-in-the-middle framework to sit between victims and Microsoft’s legitimate authentication infrastructure. The configuration, which BigBear calls ‘offy’, sets up a proxy that intercepts credentials and authenticated session cookies in real time, including at the point where multi-factor authentication (MFA)…

Read More

OpenAI is testing a ChatGPT Writing Style feature that reads your existing messages, documents and emails from connected workplace apps, then uses those patterns to write new content in your voice. The onboarding screen puts it plainly: ‘ChatGPT will write in your voice by referencing examples from your connected apps.’ The feature is currently available to a limited group of users. Apps listed in the integration include Slack under messaging, Google Drive and Notion for documents, and Gmail for email. TechDogs also notes SharePoint as a supported source, extending the reach into Microsoft’s ecosystem. The idea is that ChatGPT builds…

Read More

An emergency hotfix is now available for a maximum-severity N-central RCE vulnerability that leaves unpatched servers open to unauthenticated remote code execution, with cybersecurity company Huntress flagging the flaw as a potential zero-day amid signs of compromise in at least one customer environment. N-able released N-central 2026.3 Hotfix 4 on Saturday and is urging all on-premises customers to apply it immediately.The flaw, tracked as CVE-2026-86218, requires no privileges and can be exploited in low-complexity attacks against N-central instances that are reachable from the internet. N-central is a remote monitoring and management (RMM) platform used by IT departments and managed service…

Read More