Microsoft Windows file archival tool WinRAR exploited worldwideSteve ZurierJanuary 28, 2026Vulnerability lets threat actors drop malware into the Windows Startup folder.
Note to US Senate: End the petty squabbles and confirm Sean Plankey as CISA directorBob Ackerman January 27, 2026
From change prevention to continuous improvement: Automating patch cycles with guardrails, rings, and proofBill BrennerJanuary 6, 2026
Bouncing back better: Submit your nominations for the Resilient CISO AwardPaul WagenseilJanuary 5, 2026
A serial entrepreneur’s journey from marketing to cybersecurity: Founder StoriesPaul WagenseilDecember 24, 2025
Application securityMost organizations had a third-party breach in the last yearLaura FrenchJanuary 28, 2026Respondents report third party risk assessments take several months and only cover a fraction of vendors.
Security OperationsSix JavaScript zero-day bugs lead to fears of supply chain attackSteve ZurierJanuary 27, 2026Tools used to protect users in the aftermath of Shai-Hulud may no longer work, security pros say.
Application securityResearchers find 16 browser extensions stealing ChatGPT session tokensLaura FrenchJanuary 27, 2026One of the malicious ChatGPT “mods” has a featured badge on the Chrome Web Store.
Security OperationsVMware vCenter Server bug added to CISA list of exploited vulnerabilitiesSteve ZurierJanuary 26, 2026CVE-2024-37079 has a 9.8 rating and was originally patched in 2024.
Data SecurityMillions of Gmail, Facebook and other account credentials exposedLaura FrenchJanuary 23, 2026The dataset included email accounts, social media accounts, financial accounts and more.
IdentityOkta warns of multiple vishing attacks that can defeat MFASteve ZurierJanuary 23, 2026Experts say we’ve seen similar attacks in recent Salesforce vishing campaigns tied to ShinyHunters.
Security OperationsHundreds of vulnerable test environments exposed, targeted by crypto minersLaura FrenchJanuary 22, 2026Misconfigurations turn apps meant for security training into cloud attack vectors.
Security OperationsPatched FortiGate bug targeted in new wave of automated attacksSteve ZurierJanuary 22, 2026Fortinet plans to update a FortiGate patch it first issued last month in the coming days.