Skip to content
root notes — live feed

whoami

Breaches, patches and the infrastructure underneath — in five minutes.

tail -f headlines.log

Most news sites re-package yesterday's press releases. This one doesn't — every post is capped at five minutes, opens with what actually changed, and tells you why it matters before it tells you what happened.

Latest analysis

The host key check ran, and passed, on a curve the attacker chose for it

2026-10-08Security

wolfSSH never verified that the elliptic curve in a server's host key matched the algorithm both sides had just negotiated. A machine-in-the-middle could swap in a key on a different curve, sign with its own private key, and be accepted with no error. Fixed in 1.6.0 — and it needs one more condition that is common in embedded code.

The botnet's command channel is the protocol that exists to tell a machine its own public address, and nobody can block it

2026-10-07Security

Cling takes routers and DVRs through vulnerabilities going back to 2014, then talks to its operator over STUN — the NAT-traversal service every video call depends on. Its traffic looks like a device keeping a connection alive, because that is literally what the packets are. It is the third campaign this fortnight to put its command channel somewhere undeletable.

The NetScaler appliances restarting after the patch were not a patch bug — they were a third zero-day, and the sixth crash is the trigger

2026-10-06Security

On 3 October we wrote that Citrix customers were watching their gateways reboot after installing the emergency build, with no CVE and no root cause published. Citrix disclosed it on the 4th: CVE-2026-88779, a memory overflow reached through SAML, exploited in targeted attacks. Each attempt crashes the authentication service, and the sixth restarts the appliance.

Coverage

subscribe --daily

One email each morning. No filler.