August 2026

Threat Intelligence

A Zoom Screen-Sharing Bug Could Take Over Every Device on the Call. Nobody Had to Click Anything.

Three critical zero-click vulnerabilities in Zoom's annotation feature allowed any meeting participant to remotely execute code on every other device in the call — no click required, no warning displayed, every platform affected. The full exploit chain was developed using AI in under 24 hours. When participation is the attack surface, vendor dependency is the risk.

Read More
August 2026

Infrastructure

676 Million Identity Records Were Sitting on an Open Server. Nobody Needed a Password.

A misconfigured Elasticsearch cluster exposed 676 million US identity records — including full Social Security numbers — to anyone who found its IP address. No authentication required. No exploitation necessary. The incident is not an anomaly. It is the infrastructure custody problem made visible at scale, and it applies to every backend your communications touch.

Read More
August 2026

Threat Intelligence

Eight Breaches in Eight Months. The Spearphishing Campaign Against Europe's Senior Officials.

CERT-EU has confirmed eight significant spearphishing incidents targeting EU government officials over Signal and WhatsApp in the first half of 2026 alone. The attacks exploited no software vulnerability. They used no malware. They simply asked people for their credentials — and it worked, because consumer messaging apps have no institutional defence against it.

Read More
August 2026

Analysis

France Built a Sovereign Messaging App. It Got Breached Anyway.

France mandated Tchap as the exclusive government messaging platform, banning Signal and WhatsApp from official use. Two months later, attackers socially engineered a single account and allegedly exfiltrated over 640,000 messages spanning three years of government communications. Sovereignty was the right instinct. Architecture was the failure.

Read More
April 2026

Threat Intelligence

End-to-End Encryption Cannot Protect Compromised Endpoints. That's Where the Attacks Are.

FBI and CISA warnings about Russian hackers hijacking Signal and WhatsApp accounts confirm what security professionals have known for years: the encryption is not being broken. The devices and accounts at either end are being compromised — and end-to-end encryption was never designed to address this threat.

Read More
April 2026

Analysis

The EU Shut Down Its Signal Group Chats. The Lesson Is Bigger Than Signal.

The European Commission ordered senior officials to stop using Signal after Russian-linked phishing attacks targeted their accounts. Twelve months after the US Signalgate scandal exposed classified military plans shared on the same app, the pattern is unmistakable: consumer encrypted messaging was never designed to be government communications infrastructure.

Read More
March 2026

Threat Intelligence

The FBI Director's Personal Email Was the Attack Surface

An Iran-linked hacking group breached FBI Director Kash Patel's personal email and published years of private correspondence. The incident exposes the structural vulnerability every senior official shares: personal communications that can be weaponized for blackmail, manipulation, or coercion live in infrastructure nobody is protecting.

Read More
March 2026

Regulatory

Bill C-26 and the New Communications Security Obligation

Canada's landmark cybersecurity legislation creates enforceable obligations for critical infrastructure operators — including requirements to secure communications systems and manage third-party risk. For organizations whose most sensitive conversations travel through foreign-jurisdiction platforms, the compliance question is also a sovereignty question.

Read More
March 2026

Threat Intelligence

Harvest Now, Decrypt Later: The Attack That Already Happened to You

Nation-state actors are not waiting for quantum computers to become publicly available. They are collecting your encrypted traffic today, storing it against a future decryption capability. This is not a theoretical future threat. It is an active, documented collection program. Here is what you need to understand about the timeline, the actors, and what it means for communications you are sending right now.

Read More
February 2026

Regulatory

NIST PQC Standards Are Final. The Clock Is Running.

In August 2024, NIST finalized the first post-quantum cryptographic standards — FIPS 203, FIPS 204, and FIPS 205. For government agencies, defense contractors, and any organization subject to federal procurement requirements, this is not guidance. Migration timelines are being set now. The organizations that begin transition today will be compliant when mandate arrives.

Read More
February 2026

Infrastructure

Who Owns the Wire Your Secrets Travel Through?

Every communication your organization sends travels through infrastructure operated by someone else. A carrier. A cloud provider. A SaaS platform's data center. In most cases, multiple of these simultaneously. The question of who has custodial access to that traffic, in what jurisdiction, under what legal framework, is the central communications security question of our era.

Read More
January 2026

Analysis

Why Signal Is Not Enough for Your Organization

Signal is a well-engineered consumer application. Its encryption is legitimate. Its open-source protocol has been peer-reviewed. But the threat model facing a government agency, a defense contractor, or a major legal institution is categorically different from what Signal was built to address. Here is exactly where the gap is — and why it matters for your organization specifically.

Read More
January 2026

Quantum Timeline

The Quantum Timeline Is Not a Prediction. It Is a Planning Horizon.

Debates about when quantum computers will break RSA-2048 miss the point entirely. Nation-state adversaries operating classified quantum programs are under no obligation to make public announcements. The question for your organization is how long your most sensitive data needs to remain confidential — and what is being collected against that timeline right now.

Read More
December 2025

Supply Chain

The Software Supply Chain Is the Communications Attack Surface

SolarWinds. XZ Utils. 3CX. The pattern is consistent: sophisticated attackers compromise the software you trust because it is more efficient than compromising your network. The 3CX attack targeted a communications platform specifically — providing access to the conversations of its users. When the tool is the weapon, your perimeter is irrelevant.

Read More

Stay Informed

Register to receive dispatches when new analysis is published.