This website uses cookies
Read our Privacy policy and Terms of use for more information.
malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 36/2026 - The Trust Layer Got Compromised.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Sep 5, 2026
•
7 min read
Plus: U.S. strikes on Iran pushed federal agencies to warn about retaliatory attacks on water and utility systems, the Sality botnet was disrupted after 23 years, and Pegasus found its way onto Serbian activists' phones

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 35/2026 - They Didn't Steal the Data. They Turned Off the Lights.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Aug 29, 2026
•
7 min read
Plus: TeamPCP finally got two arrests in Australia, Slovak traffic cameras came with a Russian backdoor pre-installed, and SharePoint exploit chains are being actively weaponized

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 34/2026 - The Agents Disagreed. Then They Deployed Malware.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Aug 22, 2026
•
7 min read
Plus: Cl0p's PTC Windchill zero-day is hitting 40+ companies with GE, Philips, and Shell named so far, Oracle shipped 943 patches in one update, and US agencies warn AI is generating Siemens PLC exploits

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 33/2026 - The Guardrails Are Real. So Is the Precedent.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Aug 15, 2026
•
7 min read
Plus: Microsoft patched 398 flaws with AI finding more than humans can review, ransomware took down a hospital's doors and HVAC in Winnipeg, and three research teams bypassed passkeys without breaking FIDO2

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 32/2026 - Autonomous, Malicious, and Technically Not Illegal](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Aug 8, 2026
•
9 min read
Plus: Iran-linked hackers hit water utilities in seven U.S. states, Storm-2945 harvested M365 credentials from hotel Wi-Fi, and Samsung banned smart TV apps secretly running residential proxies

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 30/2026 - The Model Decided the Sandbox Was Optional.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Jul 25, 2026
•
7 min read
Plus: Iran-linked hackers targeted Siemens, Schneider, and Rockwell ICS devices, the EU fined Google €890M for DMA violations, and Operation Offsides seized 1,000+ illegal World Cup streaming sites

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 29/2026 - They Didn't Hack the Military. They Hacked the Phone Network.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Jul 18, 2026
•
8 min read
Plus: Microsoft patched a record 622 vulnerabilities, asyncapi npm packages delivered a botnet loader via GitHub Actions, and ShinyHunters spent a year inside Salesforce via OAuth abuse

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 28/2026 - The Agent Ran the Attack. The Human Just Aimed.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Jul 11, 2026
•
8 min read
Plus: The DHS threat intelligence network got breached, a 16-year-old Linux KVM flaw lets guest VMs crash the host, and Canada's spy agency confirmed it hacked drug traffickers and a ransomware gang last year

