Threat IntelligenceLatest insight
A Russian-speaking actor deployed hundreds of AI agents to mass-exploit two chained PaperCut vulnerabilities across 440+ internet-facing instances in 10 countries. The vulnerability class is not new. The operational speed is. If your patch window is measured in weeks, you are losing the race.
9 min read · September 9, 2026
Compliance
CISA added three critical actively exploited vulnerabilities to its KEV catalog — including a CVSS 10.0 Cisco Secure Firewall Management Center auth bypass. Federal agencies have until September 12. Here is what every organization running these products needs to know about aligning patch management with exploitation reality.
8 min read · September 8, 2026
Threat Intelligence
The Aurora ransomware group used Cursor AI to plan attacks against 33 victims across the US and Europe — including a full AD CS exploitation plan written in Russian. The same tool your developers use. The detection implications are significant.
9 min read · September 2, 2026
Compliance
A China-linked espionage group compromised Cisco IOS XR routers, suppressed logging, and scanned critical infrastructure. CIRCIA's 72-hour clock starts when you become aware — but Fire Ant targeted the tools that create awareness.
8 min read · September 1, 2026
Threat Intelligence
A researcher published a working proof-of-concept exploit for Microsoft Defender on August 12. Any standard user can gain SYSTEM privileges using Defender's own scheduled tasks. No patch exists. Here is what CISOs need to detect now.
7 min read · August 27, 2026
Compliance
Two surveys published in August 2026 reveal that 96% of US defense contractors claim CMMC compliance, but only 29% can demonstrate it. The Pentagon suspended Phase 2 assessments. DFARS attestation obligations and False Claims Act liability did not pause.
7 min read · August 26, 2026
Threat Intelligence
AmnesiaStealer copies your Chromium browser profile into a hidden headless browser and gives attackers live 3fps remote control over your authenticated sessions. MFA is already cleared. Here is what enterprise security teams need to know.
8 min read · August 20, 2026
Compliance
Attackers exploited a faulty software update at a payment processor to steal €30 million from Commerzbank accounts. Seven suspects arrested in August 2026. DORA, in force since January 2025, was built to address exactly this third-party ICT risk pattern.
8 min read · August 19, 2026
Threat Intelligence
Nearly 800 malicious npm packages flooded the registry using AI-generated typosquatting names. The WEL1DROPPER campaign delivers a cross-platform RAT on Windows and Mac, and Sliver C2 on Linux. Standard SCA tools miss this because the packages had no prior malicious history.
8 min read · August 12, 2026
Compliance
Unlimited Technology Systems took 255 days to notify HHS after detecting a breach affecting 3.8 million people across 4,500 clinics. HIPAA requires 60. The gap reveals a systemic readiness problem for healthcare software vendors.
8 min read · August 11, 2026
Compliance
Levi Strauss disclosed a corporate data breach to the SEC within four business days after social engineering hit three employees. The harder question is how organizations make a defensible materiality determination under incomplete forensics and legal pressure.
8 min read · August 11, 2026
Cloud Security
Unit 42 published three attacks, called Pass-ta-key, that allow unprivileged malware to hijack Google Password Manager's cloud-synced passkeys in Chrome. No admin rights. No user interaction. The passkey cryptography is not broken. The cloud sync trust model is.
9 min read · August 5, 2026
Compliance
Microsoft confirmed APT29 (Midnight Blizzard) has been running CaptiveCrunch, a global campaign targeting hotel and conference Wi-Fi since May 2026. The attack steals M365 session tokens through compromised captive portal hardware. PCI-DSS certification did not stop it.
9 min read · August 4, 2026
Penetration Testing
Fastjson 1.x has a CVSS 9.0 RCE with no patch and active exploitation in financial services. A vulnerability scanner would not have caught it. A properly scoped penetration test would have.
9 min read · July 30, 2026
Compliance
An open-source AI agent breached Thailand's Finance Ministry this week in fully autonomous mode. No human in the loop. Here is what that means for DORA ICT risk management and financial sector detection capabilities.
9 min read · July 29, 2026
Threat Intelligence
CVE-2026-63030 and CVE-2026-60137 chain to give any anonymous user remote code execution on WordPress 6.9 and 7.0. A public proof-of-concept is on GitHub. The attack surface management team that found it wasn't running a pen test.
8 min read · July 23, 2026
Compliance
OpenSSL shipped a fix on June 9 with no CVE, no advisory, and no changelog entry. Okta's Red Team published the details 38 days later. NIS2 and DORA require patch management for known vulnerabilities. This one was deliberately invisible.
8 min read · July 22, 2026
Compliance
On August 2, 2026, EU AI Act high-risk obligations become enforceable. Fines reach 35M EUR or 7% of global revenue. 78% of organizations are not ready. Here is the 5-step CISO action plan.
8 min read · July 15, 2026
AI Security
A finance employee at Arup wired $25.6M after a deepfake video call with fake executives. The controls worked exactly as designed. The threat had already moved past them.
10 min read · July 10, 2026
AI Security
The EU AI Act starts enforcing high-risk AI system rules on August 2, 2026. Most boards don't know which of their AI systems qualify. That is the governance gap nobody is talking about.
9 min read · July 3, 2026
AI Security
Employees are pasting sensitive data into unapproved AI tools every day. This is not a future risk - it is a data breach unfolding in slow motion, and most organizations have no visibility into it.
9 min read · June 27, 2026
AI Security
Deepfake video calls, AI-cloned executive voices, autonomous phishing agents - attackers are already using AI at scale. Here is the security framework every organization needs before AI becomes a liability.
10 min read · June 26, 2026
Threat Intelligence
The Shai Hulud campaign poisoned 373–416 npm package versions - all signed, all attested, all verified. What CISOs must understand about software supply chain trust when 'signed' no longer means 'safe'.
9 min read · May 16, 2026
Threat Intelligence
CVE-2026-41940 gives attackers admin access to cPanel servers with no credentials required. It was exploited before the patch shipped. Here is what that means for your exposure.
8 min read · May 6, 2026
Threat Intelligence
MuddyWater used Microsoft Teams to steal credentials and deploy false-flag ransomware. If your attack surface map does not include Teams, Slack, and Zoom, you have a blind spot.
8 min read · May 6, 2026
Threat Intelligence
Trellix confirmed attackers accessed their source code repository. If your security vendor can be breached, how much scrutiny are you applying to the tools that sit inside your environment?
8 min read · May 3, 2026
Compliance
Security leaders spend 40% of their time on compliance admin. The GRC industry's answer was a chatbot on top of a 2019 dashboard. That is not AI. Here is what autonomous compliance actually looks like.
9 min read · April 26, 2026
Threat Intelligence
One attacker. Nine Mexican government agencies. 415M records exfiltrated using Claude Code and GPT-4.1. What CISOs and boards must change this quarter.
10 min read · April 23, 2026
Threat Intelligence
Frost Bank and Citizens Bank both lost data to Everest ransomware in the same week. No zero-days - just three doors every CISO can lock this week.
10 min read · April 22, 2026
Threat Intelligence
The average company takes 194 days to detect a breach and 64 more to contain it. Here's why detection fails - and what CISOs can do to change it.
9 min read · April 20, 2026
CISO Insights
Boards don't speak 'cyber.' They speak risk, cost, and reputation. Learn how to translate your security program into language that drives action.
8 min read · April 19, 2026
No articles match your search. Try another keyword or choose all topics.