top of page

Weekly INK
Each week we compile an advisory on the latest threats, trends and newsworthy topics from the cyber security industry affecting small and medium enterprises. Join our subscribers below and help us prevent cybersecurity breaches.

Issue #216 - September 14, 2026
CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot Source: SecurityWeek CISA will retire its weekly vulnerability bulletin on September 28 as it shifts federal vulnerability management toward real-world risk. The agency says BOD 26-04 emphasizes active exploitation, exposure, and the Known Exploited Vulnerabilities catalog, helping defenders prioritize urgent fixes instead of sorting thousands of entries primarily by severity. Link to article Cyber Op Targets Sout

Weekly INK
5 days ago2 min read
Â
Â
Issue #215 - September 7, 2026
Critical NetScaler Vulnerability Exploited in Attacks Source: SecurityWeek CISA warned that attackers are exploiting CVE-2026-19490, a critical authentication-bypass vulnerability affecting NetScaler ADC and Gateway appliances configured as gateways or AAA virtual servers. Citrix patched the flaw in August, but observed exploitation began shortly after public exploit code appeared. Organizations should treat remediation as an emergency priority. Link to article OpenAI Agents

Weekly INK
Sep 72 min read
Â
Â
Issue #214 - August 31, 2026
Hackers push malicious Virtualizor update in BGP hijacking attack Source: BleepingComputer Attackers diverted Virtualizor update traffic by hijacking BGP routes associated with Softaculous infrastructure, then delivered a malicious package to a small number of servers. The vendor restored routing, released a security analyzer, and advised administrators to check for a suspicious service, rotate credentials, and audit systems for unauthorized access. Link to article Attackers

Weekly INK
Aug 312 min read
Â
Â
Issue #213 - August 24, 2026
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Source: The Hacker News Researchers demonstrated GPUThor, a Rowhammer technique that produced multi-bit errors on several NVIDIA Ampere workstation GPUs and bypassed the protection expected from ECC. With unprivileged CUDA execution, the team achieved denial of service and host privilege escalation. Defenders should limit untrusted GPU workloads, avoid cross-tenant sharing, and monitor ECC errors.

Weekly INK
Aug 242 min read
Â
Â
Issue #212 - August 17, 2026
'Grandoreiro' Malware Resurfaces With Mexico Campaign Source: Dark Reading The Grandoreiro banking Trojan has returned in a campaign aimed primarily at Mexican users. Operators disguise malicious archives as invoices, abuse a legitimate file-management application for DLL sideloading, and deploy a heavily protected loader with extensive sandbox, security-tool, and analysis checks before downloading the credential-stealing payload. Link to article New Cryptographic Context Inj

Weekly INK
Aug 172 min read
Â
Â
Issue #211 - August 10, 2026
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access Source: BleepingComputer Researchers demonstrated that Windows Plug and Play can install exploitable vendor packages as SYSTEM when presented with emulated USB hardware. Some chains required no user interaction, while another worked through RDP USB redirection without physical hardware. Recommended protections include restricting device installation and disabling unnecessary Plug and Play redirection. Link to

Weekly INK
Aug 102 min read
Â
Â
Issue #210 - August 3, 2026
AI Sends Global Crime Syndicates Into Fraud Nirvana Source: Dark Reading Organized crime groups are industrializing fraud with AI-powered voice cloning, real-time deepfake video, synthetic identities, automated translation, and persona-management tools. These capabilities help gangs defeat identity verification and scale convincing scams across borders, increasing pressure on financial institutions to strengthen identity proofing, liveness checks, behavioral defenses, and int

Weekly INK
Aug 32 min read
Â
Â
Issue #209 - July 27, 2026
SE Asian Cybercriminal Syndicates Become a Global Power Source: Dark Reading Dark Reading reports that Southeast Asian cyber-fraud syndicates have evolved into global service-based crime networks, enabled by cryptocurrency, secure messaging, AI, satellite connectivity, trafficking, and corruption. The story highlights how enforcement pressure has displaced operations rather than dismantled them, creating a resilient ecosystem with major regional economic impact. Link to artic

Weekly INK
Jul 272 min read
Â
Â
Issue #208 - July 20, 2026
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover Source: Dark Reading Attackers are exploiting two critical WordPress flaws chained as WP2Shell to achieve unauthenticated remote code execution on default installations. The article reports widespread exploit attempts, public proof-of-concept activity, forced security updates, and guidance to inspect sites for backdoor accounts, malicious plugins, and suspicious files even after patching. Link to article Critical

Weekly INK
Jul 202 min read
Â
Â
Help us Prevent Breaches.
Subscribe to our Weekly INK newsletter. We will never share your information.
bottom of page

