Air Gaps and OT Security in the Zero Trust Era

OT security — air gap trust assumptions, removable media risks, and supply chain integrity in ICS environments

OT security has always rested on a core assumption: if a system is physically separated, it is safe. For years, the air gap represented real certainty. No routable path, no shared infrastructure, no logical bridge — and no external attack surface to speak of. In safety-critical industrial environments, that clarity mattered. But the industrial world…

Read More

Your Windows is fully patched. And there’s a public exploit on GitHub that gives attackers SYSTEM on it right now.

Your Windows is fully patched. And there’s a public exploit on GitHub that gives attackers SYSTEM on it right now. On June 10 — hours after Microsoft shipped its June Patch Tuesday update — researcher Nightmare Eclipse published a working exploit called RoguePlanet. It targets a race condition in Microsoft Defender’s quarantine pipeline. Defender runs…

Read More

Your ERP system has no patch. Hackers are already inside.

Your ERP system has no patch. Hackers are already inside. Oracle issued an emergency out-of-band security alert yesterday for CVE-2026-35273 — a critical unauthenticated remote code execution vulnerability in PeopleSoft PeopleTools 8.61 and 8.62. No password required. An attacker with HTTP access to the Environment Management Hub runs arbitrary code on your ERP server. ShinyHunters…

Read More

Top 5 Cybersecurity News Stories June 12, 2026

Cybersecurity News Stories June 12, 2026

The five stories in this week’s Cybersecurity News Stories June 12, 2026 do not describe organisations that ignored known risks or failed to apply available controls. They describe organisations — and security architectures — whose valid assumptions have been invalidated by conditions that changed without obvious warning. A compliance control that certified “data at rest”…

Read More