Skip to content
Briefings are running a touch slower this week while we rebuild the foundations.See roadmap
MonitoringTechnology· Active since 17 April 2026

Cybersecurity: Threats and Defences

5 updates · 260 entities · 45 days active

Current Assessment

The developer and AI toolchain is the new perimeter; network-edge defences have no view into it.

#5
29May14:17

GitHub's own code cloned via VS Code add-on

A poisoned Nx Console extension sat on the VS Code Marketplace for 18 minutes, long enough to steal a GitHub employee's tokens and clone roughly 3,800 internal repositories. The same actor that hit Cisco's source last fortnight has now breached the registry operator itself. CISA added two AI-tier flaws and a Drupal SQL bug to KEV; the UK cyber sector cleared 14.7 billion pounds.

GitHub's own code cloned via VS Code add-on
Read full update
#3
8May10:57

CISA's deadline outruns Palo Alto's patch

CISA gave federal agencies until 9 May to fix a Palo Alto firewall flaw. The patch ships on 13 May. State-nexus attackers have been inside the same firewalls since 16 April. Trellix, cPanel and Ivanti round out a week in which the perimeter device stopped pretending to hold.

CISA's deadline outruns Palo Alto's patch
Read full update
#2
30Apr08:16

FIRESTARTER puts Cisco below the patch line

Sixteen agencies admitted on 23 April that indicators of compromise vanish faster than blocklists can absorb them. A day later, CISA and NCSC named FIRESTARTER, a Cisco firewall implant that survives every patch. The defender's job has shifted from removing the indicator to rearchitecting the device.

FIRESTARTER puts Cisco below the patch line
Read full update
#1
17Apr13:56

Stryker MDM wipe exposes identity perimeter

Iran-linked Handala wiped 80,000 to 200,000 Stryker devices across 79 countries on 11 March using one stolen Microsoft Intune admin credential, with no malware deployed. NHS Supply Chain issued a UK disruption alert; Stryker filed an SEC 8-K/A. US defenders face this with a proposed $707m CISA cut and a Citrix/F5 vendor stack still burning.

Stryker MDM wipe exposes identity perimeter
Read full update