Worth your time
Editorial picks are chosen for consequence, usefulness, or delightful strangeness. For the newest reporting, use the live desk directly above.
01 / FEATUREDCisco’s Network Manager Has an Admin Bypass
Cisco confirms attackers are exploiting an SD-WAN Manager flaw. Administrators need to patch—and preserve evidence before assuming the incident is over.
All stories

Sony Brings AI Upscaling to the Standard PS5
QSSR arrives in Wolverine and Ghost of Yōtei without requiring a PS5 Pro. Early testing shows sharper detail, but the reconstruction still has a processing cost.

MetaMask Pulls Validators After Infrastructure Breach
MetaMask is exiting affected Ethereum validators while it investigates an infrastructure incident. Lido warns that restoring the stake to service could take weeks.

Cisco’s Network Manager Has an Admin Bypass
Cisco confirms attackers are exploiting an SD-WAN Manager flaw. Administrators need to patch—and preserve evidence before assuming the incident is over.

AI’s Safety Pledge Meets an FTC Probe
A federal inquiry puts AI safety promises under scrutiny. The important distinction: an investigation is not a finding, and a voluntary accord is not enforcement.

France’s Tax Breach Outlasted a Password Reset
France’s newly published investigation shows why resetting a stolen password is not the same as removing an intruder. An active session kept the data flowing.

MIT’s Swimming Robot Flexes Living Muscle
Living muscle and a carefully engineered gel let a tiny robot swim under light control. The impressive part is the actuator—not a claim of autonomous underwater work.

Apple’s Small Update Closes a Serious Security Hole
Apple has patched a file-processing flaw across older iPhone, iPad and Mac software. Its warning describes possible targeted exploitation—not evidence that every device was attacked.

Starship Makes Orbit, but Cuts Its Victory Lap Short
SpaceX’s fourteenth Starship test reached orbit and deployed 26 Starlink satellites. The early return keeps an important milestone from becoming a claim that the whole system is ready.

Citrix’s Gateway Has Two Doors Attackers Can Open
Two NetScaler flaws are being exploited globally. Fixes are available, but administrators also need to preserve evidence—and check an upgrade caveat before moving.

Arista’s VeloCloud Has Another Exploited Zero-Day
Arista says attackers are exploiting a maximum-severity flaw in the on-premises VeloCloud Orchestrator control plane. Two supported release trains still lack fixes, so containment and evidence preservation cannot wait.

Check Point Zero-Day Needs a Manual Hotfix
Check Point says attackers exploited a management-server zero-day before disclosure, while a separate VPN flaw is now drawing a global wave of attempts. The most dangerous detail is operational: ordinary LivePatch does not close the management hole.

F5’s BIG-IP APM Zero-Day Is Already Under Attack
F5 says attackers are already exploiting a critical BIG-IP APM flaw that can turn malicious OAuth traffic into unauthenticated code execution. The affected configuration is narrow; the response window is narrower.