Threat Intelligence & Security News

Threat Intelligence & Security News

CyberDesserts covers the threat landscape as it happens, ransomware campaigns, vulnerability disclosures, and emerging attack techniques. Written for security practitioners who need to understand what's happening, why it matters, and what to do about it. No vendor noise. No recycled press releases. Just analysis grounded in 20+ years of defending real organisations.
31
Mar
A ginger cat viewed from behind, sitting in front of a blurred monitor displaying code

What Censys's OpenClaw Count Reveals That February's Headlines Did Not

31st March 2026 OpenClaw's internet-facing exposure has fallen sharply since the February 2026 peak. Public scrutiny, repeated
9 min read
18
Mar
Targeting Firewalls And VPN Appliances

Why Ransomware Groups Are Targeting Firewalls and VPN Appliances

Updated July 2026: Adds the FortiBleed credential-harvesting campaign, the largest current example of the firewall-as-ransomware-entry pattern,
10 min read
16
Mar
Microsoft Intune Security Hardening

Microsoft Intune Security: Hardening Privileged Access

Updated March 2026: Based on the Stryker incident and Microsoft's official hardening guidance published 13 March 2026. LinkedIn
9 min read
13
Mar
he Dead Internet Is a Security Problem

The Dead Internet Is a Security Problem: What Digg's Collapse Teaches Us

Published March 2026 Digg launched in January 2026 to challenge the idea that the internet is full of bots, by
4 min read
12
Mar
SOC Analyst Role is changing ?

Will AI Replace SOC Analysts?

March 2026 LinkedIn Post Copy Link Large language models cannot yet be trusted to make autonomous security decisions. That is
10 min read
01
Mar
Concrete brutalist structure where four beams meet at a central junction that has cracked and fractured, showing how AI agent supply chain risk concentrates at the connection points.

AI Agent Security Risks in 2026: The Incident Landscape and Hardening Framework

In February 2026, the supply chain threat model arrived in AI agent infrastructure all at once. The Model Context Protocol is the connective tissue across every major incident. Here's what practitioners need to know.
20 min read
01
Mar
Government Attack Surface Reduction

How the UK Government Slashed Cyber Fix Times by 84%

Published March 2026 The UK government has slashed cyber vulnerability fix times by 84%. Through a new nationwide scanning service,
7 min read
12
Feb
Notepad CVE-2026-20841

Two Notepad Attacks in One Week: Your Tools Are the Target

Software supply chain attacks more than doubled in 2025, with developer workstations identified as high-value targets across multiple industry
5 min read
05
Feb
OpenClaw security risks concept showing hidden keyboard under torn paper, representing malicious skills, exposed instances, and system-level vulnerabilities in AI agents.

OpenClaw Security Risks: Malicious Skills, Exposed Instances and Real Exploits

Latest updates (March 2026): NemoClaw announced, CVE count now 60+, and independent analysis using Censys identified 63,070 live instances
20 min read
04
Feb
Notepad++ update server compromise

Notepad++ Compromised for 6 Months: Check Your Version Now

Updated May 2026 Notepad++ update servers were compromised from June through December 2025 by a Chinese state-sponsored threat group.
4 min read