Security news

What just happened, and what to check.

Recent incidents and policy changes in the parts of security the outside world can see: certificates, DNS, email authentication, exposed services and domain ownership. Each post sticks to the sourced facts, then turns them into a short list of things to verify on your own domains.

Microsoft 365 Was Down for 67 Hours. Admins Traced It to an Expired Certificate.

From August 31 to September 3, 2026, Exchange Online, Teams and SharePoint failed worldwide. Microsoft blamed a core authentication configuration; admins saw an expired certificate thumbprint in the errors. What to check on your own domains.

Read article →

CISA Adds Seven Exploited Flaws in One Day. Two Score a Perfect 10, All Sit on Internet-Facing Software.

On September 2, 2026 CISA added seven actively exploited CVEs to its KEV catalog, including a CVSS 10 SonicWall SMA 1000 flaw and a CVSS 10 Kestra bug. Under BOD 26-04, publicly exposed assets get three days. How to know what you expose.

Read article →

One in Five New Domain Registrations Is Someone's Expired Domain, and Criminals Are Paying Millions for Them

Infoblox Threat Intel found about 65,000 expired domains re-registered every day in the first half of 2026, and one actor, Sable Squirrel, holding 10,000 of them for malware C2, gambling and piracy. Why your lapsed domains are an attack surface.

Read article →

As of June 15, Every Public TLS Certificate Goes Into a Transparency Log. Your Hostnames Are Now Public.

Chrome Root Program Policy v1.8 requires every CA to log every TLS precertificate and certificate to Certificate Transparency from June 15, 2026. DigiCert enforced it June 1. The opt-out is gone: what that exposes, and how to use it.

Read article →

Let's Encrypt Stopped Issuing for Two and a Half Hours. Did Your Renewals Notice?

On May 8, 2026 Let's Encrypt halted all issuance for about 2.5 hours after its new Generation Y cross-signed intermediates shipped without the serverAuth EKU. Renewals failed with serverInternal. What a quiet renewal failure looks like on your side.

Read article →

CoW Swap Lost $1.2 Million to a Domain Hijack That Never Touched Its Servers

On April 14, 2026 attackers took over cow.fi through the .fi registration process using forged identity documents, pointed swap.cow.fi at a wallet-draining clone and stole about $1.2M. Backend untouched. What the DNS and certificate signals looked like.

Read article →

Microsoft: Phishing Crews Are Spoofing Domains That Have DMARC, Through Gaps in Mail Routing

Microsoft's January 6, 2026 report shows Tycoon2FA phishing campaigns sending mail as an organization's own domain and getting through despite SPF and DMARC, because third-party routing broke enforcement. Microsoft blocked 13M such emails in one month.

Read article →