Reactor core systems were untouched, but a multi-tenant engineering document store became a single point of failure for the Kudankulam project's supplier graph.
Latest news
Latest cybersecurity dispatches
Fresh reporting on active vulnerabilities, security patches, incident response, and threat research for defenders.
When every participant on the call except the victim is synthetic, conventional MFA and human verification stop being controls. Assurance has to move upstream.
September 2026 is not full CE compliance. It is the first continuous, enforceable duty to detect and report actively exploited vulnerabilities.
Accenture confirms an isolated Azure DevOps breach after 35GB of source code, PATs, keys and credentials were listed for sale—raising major supply-chain risk for clients.
Authorization gaps, hard-coded secrets and invented package names are reaching production repositories faster than human review can absorb them.
Service accounts, CI/CD runners, workload certificates and AI-agent principals form a sprawl traditional joiner-mover-leaver programs never governed.
*A conceptual view of Jenkins as the high-privilege control plane of the software factory—and of plugins as the supply-chain links that can break it.*
The chain moves from Safari RCE through sandbox escape to kernel read/write, exfiltrates data within minutes, then cleans up and exits with no user interaction.