This website uses cookies
Read our Privacy policy and Terms of use for more information.
malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 37/2026 - The Fourth Incident](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Sep 11, 2026
•
6 min read
Plus: Microsoft's September Patch Tuesday fixed 966 flaws and two zero-days, ShinyHunters claimed the Florida DMV database, and Chrome is now shipping updates every two weeks

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 36/2026 - The Trust Layer Got Compromised.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Sep 5, 2026
•
7 min read
Plus: U.S. strikes on Iran pushed federal agencies to warn about retaliatory attacks on water and utility systems, the Sality botnet was disrupted after 23 years, and Pegasus found its way onto Serbian activists' phones

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 35/2026 - They Didn't Steal the Data. They Turned Off the Lights.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Aug 29, 2026
•
7 min read
Plus: TeamPCP finally got two arrests in Australia, Slovak traffic cameras came with a Russian backdoor pre-installed, and SharePoint exploit chains are being actively weaponized

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 34/2026 - The Agents Disagreed. Then They Deployed Malware.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Aug 22, 2026
•
7 min read
Plus: Cl0p's PTC Windchill zero-day is hitting 40+ companies with GE, Philips, and Shell named so far, Oracle shipped 943 patches in one update, and US agencies warn AI is generating Siemens PLC exploits

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 33/2026 - The Guardrails Are Real. So Is the Precedent.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Aug 15, 2026
•
7 min read
Plus: Microsoft patched 398 flaws with AI finding more than humans can review, ransomware took down a hospital's doors and HVAC in Winnipeg, and three research teams bypassed passkeys without breaking FIDO2

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 32/2026 - Autonomous, Malicious, and Technically Not Illegal](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Aug 8, 2026
•
9 min read
Plus: Iran-linked hackers hit water utilities in seven U.S. states, Storm-2945 harvested M365 credentials from hotel Wi-Fi, and Samsung banned smart TV apps secretly running residential proxies

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 30/2026 - The Model Decided the Sandbox Was Optional.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Jul 25, 2026
•
7 min read
Plus: Iran-linked hackers targeted Siemens, Schneider, and Rockwell ICS devices, the EU fined Google €890M for DMA violations, and Operation Offsides seized 1,000+ illegal World Cup streaming sites

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 29/2026 - They Didn't Hack the Military. They Hacked the Phone Network.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Jul 18, 2026
•
8 min read
Plus: Microsoft patched a record 622 vulnerabilities, asyncapi npm packages delivered a botnet loader via GitHub Actions, and ShinyHunters spent a year inside Salesforce via OAuth abuse

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 28/2026 - The Agent Ran the Attack. The Human Just Aimed.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Jul 11, 2026
•
8 min read
Plus: The DHS threat intelligence network got breached, a 16-year-old Linux KVM flaw lets guest VMs crash the host, and Canada's spy agency confirmed it hacked drug traffickers and a ransomware gang last year

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 26/2026 - Project Glasswing Proved the Point Nobody Wanted Proved](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Jun 27, 2026
•
8 min read
Plus: North Korea poisoned 141 npm packages in 45 minutes, FortiBleed exposed 430,000+ FortiGate credentials, and a 1997 Squid Proxy bug finally got a CVE

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 25/2026 - Client-Side Authorization Is Not Authorization](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Jun 20, 2026
•
7 min read
Plus: The SocGholish botnet is down after nine years, Texas leaked 3M driver's licenses and passports, and dozens of cybersecurity vets are calling the Anthropic ban dangerous

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 24/2026 - npm v12 Is the Apology. The Malware Section Is the Receipt.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Jun 13, 2026
•
8 min read
Plus: Microsoft patched 200 flaws and three zero-days, Cisco's SD-WAN hit its seventh exploited zero-day of the year, and ShinyHunters went after Oracle PeopleSoft at 100+ universities

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 23/2026 - Built Broken, Patched by Others](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Jun 6, 2026
•
8 min read
Plus: Palo Alto GlobalProtect auth bypass is actively exploited, Weil Gotshal reportedly paid $20M to keep client files quiet, and the EU is moving to limit U.S. cloud in sensitive infrastructure

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 22/2026 - The Patch Is Scaling. So Is the Attack.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
May 30, 2026
•
8 min read
Plus: ShinyHunters hit Carnival, Charter, and Mytheresa, the Dutch blocked a U.S. takeover of their national ID infrastructure, and Iran-linked actors are coding backdoors with AI assistance

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 21/2026 - The Supply Chain Didn't Break. It Was Walked.](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
May 23, 2026
•
7 min read
Plus: fast16 predated Stuxnet and corrupted nuclear simulations quietly, Pwn2Own Berlin paid $1.3M for 47 bugs, and Bluesky got hijacked for Russian propaganda

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 20/2026 - The Platform Is the Attack Surface](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
May 16, 2026
•
7 min read
Plus: ShinyHunters got paid, TeamPCP hit 170 packages across npm and PyPI, and Cisco's SD-WAN zero-day count hit six for the year

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 19/2026 - Offense Just Got a Co-Pilot](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
May 9, 2026
•
8 min read
Plus: A 64-day cPanel zero-day window, ShinyHunters hits an ed-tech giant, and Europe blocks Huawei from its solar grid.

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 18/2026 - ShinyHunters' Week Off (They Didn't Take One)](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
May 2, 2026
•
10 min read
Plus: Supply chain attackers found the path of least resistance, OpenSSH patched a bug older than most junior devs, and Europe is done pretending U.S. cloud is a neutral choice

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 17/2026 - Bolt-On Security Won't Cut It](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Apr 25, 2026
•
7 min read
Plus: Scattered Spider pleads guilty, a ransomware negotiator on the wrong payroll, and a China-linked backdoor in US federal Cisco firewalls.

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 16/2026 - Faster Bugs, Same Backlog](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Apr 18, 2026
•
8 min read
Plus: AI vishing platforms hit the cybercrime market, NIST quietly caps CVE coverage, and Russia goes after a Swedish power grid.

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 15/2026 - Budgets Cut, Breaches Climbing](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Apr 11, 2026
•
15 min read
Plus: REvil's alleged leader unmasked, Adobe Reader zero-day since December, and the most uncomfortable job interview you'll watch this week

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 14/2026 - The Pipeline Is the Attack Surface](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Apr 6, 2026
•
13 min read
Plus: Stryker back online, $285M drained in 10 seconds, CERT-EU cloud breach, and quantum crypto's accelerating threat window

malware
+5
![🕵🏻♂️ [InfoSec MASHUP] 13/2026 - RSA Week, Real World Problems](https://media.beehiiv.com/cdn-cgi/image/format=auto,fit=scale-down,onerror=redirect/uploads/publication/thumbnail/ab407690-3f0c-4109-add5-5e9bf75e0e54/landscape_infosecMASHUP-substack-banner.png)
Mar 28, 2026
•
17 min read
Plus: TeamPCP's worm, Iran's hacked cameras, and a Tycoon 2FA that just won't die. The real RSA keynotes.
