A curated dispatch from GajShield

The GajShield Gazette

Lead story
Also today
In brief

Novocure data breach affects more than 1,400 cancer patients

The Novocure breach ultimately provides a more nuanced lesson than many healthcare cyberattacks. Unauthorized access occurred and patient-r…

Sep 01, 2026

When HTTPS Isn’t Enough: BGP Hijacking Turns Virtualizor Updates Into a Supply-Chain Attack

The BGP hijacking attack used to distribute a malicious Virtualizor update is an unusually important supply-chain incident because it demon…

Sep 01, 2026

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

The discovery that nearly 22,000 internet-exposed Microsoft Exchange servers remain vulnerable to CVE-2026-62911 is particularly concerning…

Sep 01, 2026

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

The argument that threat actors do not necessarily want “better” attacks but instead want attacks that can be repeated reliably is one of t…

Sep 01, 2026

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

The disclosure by METR of two security incidents during 2026 is particularly important because it demonstrates how quickly experimental AI …

Sep 01, 2026

Fake Income Tax Notice - The Borrowed Signature

A fake Income Tax notice was received by a honeypot mailbox operated by GajShield Labs on 1 September 2026. Four hops later, the delivery c…

Sep 01, 2026

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

The active exploitation of critical vulnerabilities in Langflow and Ruby on Rails deserves particular attention because the two incidents d…

Sep 01, 2026

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA’s addition of CVE-2026-81578 and CVE-2026-82078 to the Known Exploited Vulnerabilities catalog should be treated as a significant esca…

Sep 01, 2026

Berlin confirms data theft after Rhysida ransomware attack claims

The ransomware attack affecting Berlin’s state administrative network is particularly significant because it demonstrates how modern ransom…

Sep 01, 2026

Microsoft warns of TerminalFix attacks deploying reverse tunnels

The TerminalFix campaign documented by Microsoft is particularly important because it shows how ClickFix-style social engineering is evolvi…

Sep 01, 2026

Cronos blockchain restarts after $74 million Tectonic exploit

The approximately $74 million Tectonic exploit on the Cronos blockchain is particularly important because it demonstrates that decentralize…

Sep 01, 2026