Security Observatory Blog
Latest cybersecurity news, incidents and AI-model developments — observed and analyzed daily by the Kotoba Cloud research team.
-
Volexity observed the BlueMoon chain — Chrome V8 sandbox read/write, sandbox escape, and Windows ALPC abuse — shared by multiple China-nexus clusters. The upstream Chromium fixes had not yet shipped in stable Chrome, creating a dangerous "patch gap". We unpack the implications.
-
Daily observation and analysis of cybersecurity news, incidents and AI-model developments, published here.
-
CVE-2026-76461 (CVSS 9.8) is being actively exploited and was added to CISA's KEV catalog. We break down the recurring "root compromise of a boundary appliance" pattern — and what it means when the appliance's own logs can no longer be trusted.
-
A $900M AUM, operator-led fund built by former CISOs and founders. We map its two funds and ~40-company portfolio against kotoba.cloud's position.