Removing PLCs from the internet means finding the ones on cellular modems first
The FBI water-sector alert names no CVE. Initial access was the vendor programming software talking to an exposed PLC on a cellular modem.
Read →Notes on running security work with agents — what we have tried, what held up, and what did not.
The FBI water-sector alert names no CVE. Initial access was the vendor programming software talking to an exposed PLC on a cellular modem.
Read →N-central 2026.2 fixed a critical auth bypass in April and named no CVE. The CVE arrived 95 days later, after the incomplete fix was exploited.
Read →CareCloud reported an eight-hour outage to the SEC. Its breach notice, four months later, described six days of database access nobody saw.
Read →Operation PAR detected the intrusion in four days and took 380 more to notify 145,714 people. The gap is a data inventory problem, not a legal one.
Read →Operation PAR detected the intrusion on day one and needed 365 more days to determine PHI was involved. The 60-day clock only starts at determination.
Read →