Dark Perimeter: Real Breaches, Real Stakes

Cole Drayden

Every major cyberattack has a story behind it. A vulnerability no one patched. A phishing email someone clicked. A nation-state with a motive. Dark Perimeter goes beyond the headlines to explore the true stories of the hacks, breaches, and cyber operations that shaped history - told in narrative form for security professionals and curious minds alike. No guests, no panels, no filler. Just the story.

  1. 1d ago

    Critical Is Not a Priority

    Four things carried a critical severity rating this week, and they were not the same problem. Cole, Dr. Vance and Marcus Hale rank the week out loud, with reasons, because the ranking is the actual work. Cisco Catalyst SD-WAN Manager (CVE-2026-76504), CVSS 9.8. A URL-encoding authentication bypass yielding admin API access. Cisco confirmed exploitation in the wild, learned of it through a TAC support case, and the KEV remediation date of 3 October has already passed. FortiMail (CVE-2026-104286), CVSS 9.8. Unauthenticated arbitrary file write. Exploitation acknowledged by Fortinet, published indicators include an ld.so.preload entry, and for some branches the workaround is the remediation rather than a bridge to one. Atlassian (CVE-2026-21589), CVSS 9.3. Unauthenticated file access across eight Data Center products, constrained unless a Crowd deployment leaves credentials in a guessable path. Attempts reported against honeypots; no confirmed compromise as of recording. Chrome 155, 247 fixes and four critical use-after-free bugs, with no stated in-the-wild exploitation. Volume is not urgency. Then the week's largest event by population affected: approximately 8.8 million people in Denmark's national population register, reached through a private company's lawful lookup access over roughly ten days in September. No exploit, no severity score, no patch. Throughout, we separate what a vendor confirmed from what a researcher reported from what a secondary source inferred, and we name two places where the public record conflicts with itself rather than quietly picking a side. Support the show

  2. 3d ago

    Your Tier Zero List Is Wrong

    Three things happened in the last week that look like three different stories. Citrix shipped an emergency bulletin for NetScaler bugs that were already being exploited. GitLab patched a 9.9 in the gateway that runs its AI agents. Dell pushed six critical fixes for the component connecting enterprise storage arrays to Kubernetes. Cole Drayden, Dr. Elliott Vance and Marcus Hale argue they are one story. On NetScaler: CVE-2026-88771, an unauthenticated command injection, and CVE-2026-88772, a DTLS memory overflow, both CVSS v4 9.5, in the catalog the same day Citrix published. Exploitation attempts reported on the 26th of September with no CVE-specific detections available, customers told to disconnect on the 28th, and the bulletin on the 29th. Two different exposure counts from two different research teams, named rather than reconciled. The web shell tradecraft, the persistence in web-accessible directories, and the sentence that should change your runbook: patching will not remove access for an attacker who already has it. Plus the separate CVE-2026-88779 and why denial of service is a smaller claim than remote code execution. On GitLab: CVE-2026-90970, a prompt template sandbox escape in Duo Agent Platform custom flows, authenticated, self-hosted gateways only, no confirmed exploitation, and still the most interesting item of the week. A boundary between content and execution where the content is authored as configuration and never gets a program's review. On Dell Container Storage Modules: six criticals read as a set, ending in cluster-wide reads of Kubernetes Secrets and token forgery, which is a credential harvest with a storage CVE number attached. The thesis: in all three cases the compromised thing was not where the data lives, it was the thing that administers where the data lives. Ask your team for the tier zero asset list and you will get domain controllers. You will not get the VPN appliance, the CI/CD system or the storage driver that can read every Secret in the cluster. Tiering models ask what is stored here. The question that predicts this week is what can this reach, and with whose authority. Closes with four things to do this week, the first of which is not patching. Support the show

About

Every major cyberattack has a story behind it. A vulnerability no one patched. A phishing email someone clicked. A nation-state with a motive. Dark Perimeter goes beyond the headlines to explore the true stories of the hacks, breaches, and cyber operations that shaped history - told in narrative form for security professionals and curious minds alike. No guests, no panels, no filler. Just the story.