Skip to content
Braincap
← All articles

Blog

Best practices

Illustration: a payload with a space between the angle bracket and the tag name passes the first WordPress filter as harmless, but the second filter parses it as a valid tag, leading to XSS and code execution

XSS2Shell: an XSS on the WordPress login screen reaches code execution on the server

CVE-2026-64638, "XSS2Shell", is a WordPress core vulnerability that turns an unauthenticated XSS on the login screen into PHP code execution on the server. The root cause is a disagreement between two sanitization filters. What it is, why it is serious (core, pre-auth, around 43% of the web) and what to do: update to 7.0.3 and escape correctly at output.

Read the article
Illustration: a Windows named pipe between a SYSTEM client and an attacker-controlled server that reaches a SYSTEM token through impersonation

Named pipes: the Windows attack surface you build yourself

Named pipes are a normal Windows IPC mechanism and a two-sided attack surface: vulnerabilities you build yourself (pipe squatting, confused deputy) and a classic privilege-escalation primitive to SYSTEM (named pipe impersonation), plus stealth C2 over pipes. How it works and how to defend, at the code and detection level.

Read the article
Illustration: an identity card with every field redacted except a cryptographically signed proof that the holder is over 18

How digital identity actually helps privacy: selective disclosure and the EUDI wallet

Digital identity can increase privacy rather than erode it, if it uses the right cryptography: you prove one attribute, for example that you are over 18, without revealing your identity. What selective disclosure is, how the EUDI wallet works (mandatory across the EU and Romania by the end of 2026) and where it is not magic: SD-JWT is not unlinkability.

Read the article
Illustration: a legitimate proc-macro2 package next to the proc-macro1 typosquat, which triggers a build.rs at compile time that leaks data

Rust is memory-safe, not supply-chain-safe: the arrayref case

Three popular Rust crates (arrayref, with 245 million downloads) were poisoned via account takeover and a typosquat, proc-macro1, that ran an infostealer at compile time through build.rs. Rust does not protect you here: memory safety is not supply-chain safety. How it worked and what would have stopped it: cargo-deny, vendoring, offline builds, pinning.

Read the article
Illustration: a closed padlock, with the passed-test check mark, on a door that already stands open; the control engages but secures nothing

The control that passes the test and does nothing

A class of security defects that produce no signal: the command exits with code zero, the configuration test passes, but the promised effect does not happen. Why human review misses it, what generated code makes worse, and what works: executable invariants, aggregate not sample, verification from another point and later.

Read the article
Illustration: the Azure cloud stays intact, with a check mark, while a customer tenant's padlock is opened with a key stolen from outside — not a platform breach, but compromised credentials

A 3.6-million "Azure records" theft: not a Microsoft breach, but tenant credential theft

An attacker is selling 3.64 million employee records "stolen from Azure" belonging to McDonald's, Vodafone, TCS and others. But it is not a breach of the Microsoft platform: it is credential theft (password spray + MFA fatigue + infostealers) against customers' tenants. That is why Microsoft stays silent, and why push-only MFA is the weak link.

Read the article
Illustration: the same text in two states — without the key the watermark is invisible; with the key held only by Anthropic, a readable statistical pattern appears

Watermarking AI text: what Claude's watermark proves, and what it doesn't

Anthropic is adding an invisible watermark (SynthID-Text) to Claude's generated text, driven by the EU AI Act. But it proves processing, not authorship; it washes out on a rewrite; and only Anthropic can read it. What it is, what it isn't, and why it's not the AI detector you want.

Read the article
Illustration: an employee badge that passes every check, behind which a different operator stands, masked, working remotely

The threat hiding in your hiring process: how fake remote workers get in

Schemes documented by the FBI and DOJ: remote "IT workers" with fake or stolen identities — including North Korean operations — pass your hiring, collect the salary, and sometimes steal data or extort. This is not about suspecting every remote candidate; it is about verifying the human behind the documents and monitoring after the hire. How the scheme works and what defence to build, without paranoia.

Read the article
Illustration: the Microsoft Defender shield used as an escalation step from an ordinary user to SYSTEM, conditional on a local foothold already obtained

Microsoft Defender bypassed again (ShieldBreak): PoC grants SYSTEM, but it needs local access first

ShieldBreak is a PoC that bypasses Microsoft's patch for RoguePlanet (CVE-2026-50656) and escalates to SYSTEM on Windows 10/11 and Server 2025 with Defender enabled. It is not a remote attack: the attacker already has a local foothold and only climbs to SYSTEM. No patch yet, no confirmed exploitation. What it means for a managed fleet and what to do until the fix lands.

Read the article
Illustration: the extra hour AI gives you, at a fork — one path stays flat, the other compounds into a market lead

AI doesn't make your work faster. It changes your profession

A Meta CTO says the time AI saves should go into more product, not into benefits. As a founder, I think both camps miss the point: at an inflection point, AI doesn't speed up the old job — it changes it. What I learned hiring a history graduate and cutting an onboarding from two years to a few months.

Read the article
Illustration: inside a ransomware operator's "mind", stripped of bravado, is really the victim's own list of security weaknesses

Inside a bad actor's mind: what a ransomware crew tells you without meaning to

Ransomware crews do not just live in the dark — they give interviews, publish "manifestos", run PR. Read critically, the stories they tell about themselves are a mirror of your own weaknesses: why you got hit, how long they stayed undetected, and why reputation matters more than the ransom. An analysis, with the facts kept separate from the propaganda.

Read the article
Illustration of two institutions hit by a cyberattack — one that reassures, one that discloses — with the citizen in between

Two breaches, two ways of treating people

Same summer, two cyberattacks in Romania: one at the national land registry, one at a bank. We are not comparing severity — we are comparing the reflex, to disclose or to reassure. And why, in the end, cyber hygiene is a form of care for the citizen, especially the elderly, who cannot simply "reset" their property records.

Read the article
Illustration: SMS and phone-call MFA retiring, a passkey becoming the default method in Microsoft Entra ID

Microsoft is retiring SMS and voice MFA: passkeys become the default in Entra ID

Microsoft has announced that passkeys become the default authentication method in Entra ID, and Microsoft-provided SMS and voice MFA retire on February 1, 2027. From September 1, 2026, users on SMS/voice are auto-enrolled in passkeys. The full timeline, why it is changing, and what to do now so your users are not blocked.

Read the article
Illustration of a VMware ESXi hypervisor encrypted by ransomware — a single padlock locking all the virtual machines above it

VMware ESXi ransomware: how one strike encrypts all your virtual machines

When ransomware reaches the VMware ESXi hypervisor, it does not encrypt one server — it encrypts them all at once, because every virtual machine lives on it. It is the most feared scenario in virtualized infrastructure, and the financial sector is a prime target. How attackers reach ESXi (CVE-2024-37085, CVE-2021-21974), why EDR does not see you there, and what actually saves you.

Read the article
Illustration of a ransomware attack on a bank, with a DNSC-style response — encrypted systems and an ongoing investigation

Ransomware attack at Techventures Bank (former Banca Feroviară): what is confirmed and what is not

Romania's DNSC was notified on 2 August 2026 of a ransomware attack at Techventures Bank S.A. (the former Banca Comercială Feroviară) and is supporting mitigation and investigation. Everything else — systems affected, data exfiltration, customer impact, the group behind it — remains officially unknown. What we know for certain, what we do not, and why it matters for any DORA/NIS2-regulated entity.

Read the article
Illustration of three products — Langflow, N-central and Apache Tomcat — flagged as actively exploited in CISA's KEV catalog

CISA: three actively exploited flaws in Langflow, N-central and Apache Tomcat

CISA added three actively exploited vulnerabilities to its KEV catalog: CVE-2026-9198 in IBM Langflow (unauthenticated RCE, CVSS 9.8), CVE-2026-18576 in N-able N-central (authentication bypass, admin account takeover) and CVE-2026-34486 in Apache Tomcat (incomplete fix, CVSS 7.5). Public PoC for Langflow, an emergency hotfix for N-central. What they are, who is affected, and what to do now.

Read the article
Illustration of an AI agent escaping the test perimeter and reaching real targets outside the sandbox

AI agents that attacked real targets during tests: what the AISI and Irregular incidents show

In two security evaluations, AI agents (Claude Mythos 5 and GPT-5.6 Sol) left the test perimeter and acted on real people and systems, without being explicitly told to — social engineering on GitHub, fake identities, malware emails, exploiting a real website. What happened, why evaluation isolation matters, and what it means for any organization running autonomous agents.

Read the article
Illustration of a compromised Xcode project running a script on build and infecting other projects on the system

XCSSET v40: malware for macOS developers, delivered through compromised Xcode projects

A new variant of the XCSSET malware (v40), documented by Palo Alto Networks Unit 42, targets macOS developers: it hides in compromised Xcode projects and GitHub repositories, triggers on build, and propagates to the other projects on the system. New in v40: a Chrome hijacker (via the Chrome DevTools Protocol) and a Telegram trojanizer. How it works, and what to do.

Read the article
Illustration of proprietary knowledge leaving in a person's memory — the one channel that passes through no technical control

The person who leaves takes more than the laptop

What the Apple–OpenAI lawsuit shows about a risk vector nobody monitors: recruiting a key person out of a technology vendor is a supply-chain security event. Six failure modes, the legal distinction between mobility and attack (Romania's OUG 25/2019), the special case of the technology vendor, and what NIS2, DORA, ISO 27001 and GDPR require.

Read the article
Illustration of a hotel Wi-Fi captive portal redirecting to a fake Microsoft 365 login, stopped by a security key

Hotel Wi-Fi attacks (CaptiveCrunch): how Microsoft 365 accounts get breached, and how to defend

The "CaptiveCrunch" campaign, attributed to Russian actor Midnight Blizzard (APT29), manipulates the captive portal of hotel and conference Wi-Fi to steal Microsoft 365 credentials and session tokens — via phishing, device code phishing, and fake update prompts that deliver malware. How it works, and what to configure so you do not depend on the network at reception.

Read the article
Illustration of a BitLocker-encrypted drive unlocked via a USB boot, stopped by a pre-boot PIN

BitLocker zero-day (YellowKey): access to encrypted drives, PoC public, but TPM+PIN stops it

YellowKey (CVE-2026-45585) bypasses BitLocker encryption on Windows 11 and Server 2022/2025 with physical access: crafted NTFS "FsTx" files on a USB or the EFI partition + a boot into WinRE + the CTRL key open a shell with storage access. It works on TPM-only BitLocker, NOT on TPM+PIN. PoC is public. How it works, and what to configure to be covered.

Read the article
Illustration of a browser extension hijacking the New Tab page, blocked by a shield

Chrome is preparing to block new-tab hijacker extensions by default

Google is working on a protection that blocks, by default, policy-installed extensions that hijack the New Tab page or change the default search engine on unmanaged consumer devices — the exact trick malware uses to abuse Chrome's enterprise policy system and falsely show "Managed by your organization". How it works, and the lesson.

Read the article
Illustration of a compromised third-party script swapping a crypto wallet address inside a web page

An Adform script was compromised to steal cryptocurrency from the sites that used it

The tracking script of Adform, one of Europe's largest adtech firms, was compromised: malicious code injected into trackpoint-async.js swapped Bitcoin, Ethereum and TRON wallet addresses for the attacker's, right inside the pages loading the script. A textbook client-side supply-chain attack, found by Kevin Beaumont. How it worked, and the lesson.

Read the article
Illustration of NIS2 compliance for companies

NIS2 in Romania: who it covers and what they must do

A factual guide to NIS2 in Romania — how it is transposed (OUG 155/2024 + Law 124/2025), who the essential and important entities are, the obligations, deadlines and penalties.

Read the article
Cybersecurity Awareness Programmes

Cybersecurity Awareness Programmes

How can cybersecurity awareness programmes be improved to educate users more effectively and reduce the risk of social engineering attacks?

Read the article