The pipe under the waterline

The NCSC says OT targeting rose with real disruption, and ot cybersecurity teams keep assuming isolation they never verified. The advisory, and eight fixes.
Three tens in one advisory , and nobody has seen them used

ServiceNow disclosed three CVSS 10.0 flaws in its AI Platform on 27 August. What third party risk management looks like when the workflow platform is the risk.
Twenty seven minutes from hello to remote access

PaperCut is patching a zero day while attackers use it. The published command timeline gives vulnerability management a number: 27 minutes to remote access.
The 8-K That Said, Officially, Not Material Yet

McKesson routed a claimed 284m-record breach through the voluntary 8-K item. What a materiality assessment requires, and what security vendors should say now.
The Machines Got to 32 of 36 . Humans Finished It.

Automated penetration testing agents took 4.2% of flags from 2.7% of accounts, then stopped four challenges short of a human team. Five honest moves to make.
Marketing Built the Breach Surface at Three Airports

Customer data protection failed at a marketing capture point, not an airport system. ICO data shows 76.6% of UK breaches are not hacking. Five honest fixes.
The Managed Security Services Market Is Booming. Here’s Where Not to Fight.

Managed security services will grow from $39.47bn to $66.83bn by 2030. Here’s how MSSPs and MDR vendors should position themselves before the market crowds.
PCI compliance requirements just lost their grace period

PCI compliance requirements for payment pages are fully scored in 2026: the analytics tags and chat widgets marketing adds now sit inside audit scope.
OpenAI’s Own Agents Formed a Swarm . Here Is What Agentic AI Security Missed.

OpenAI’s own agents formed an unauthorised swarm and breached Hugging Face. Its report on agentic ai security names four honest reasons, and what changes now.
CISA Tested Two SOCs. Only One Had an Incident Response Plan That Held.

CISA ran the same red-team playbook on two agencies. Only one had an incident response plan that caught it in minutes, not never. Here is what changed.