(Adobe Stock) IPMI bug in BMCs found after 22 years, exposes 24,000-plus serversSteve ZurierJuly 28, 2026Decades-old IPMI bug leaves thousands of internet-facing servers exposed.
Define a Minimum Viable Business for disaster recovery — before the next incidentAharon TwizerJuly 28, 2026
When sensitive data moves everywhere, security attestations become a liabilityJustin Beals July 27, 2026
Arista patches critical command injection flaw in VeloCloud Orchestrator exploited in attacksSC StaffJuly 28, 2026
Operation Cronos dismantled LockBit ransomware group by undermining affiliate trustSC StaffJuly 28, 2026
German government report details Windows Hello for Business biometric security limitationsSC StaffJuly 28, 2026
Cut to the chase: How to save time and effort through validation in exposure managementPaul WagenseilJuly 17, 2026
Inheriting trust: Why unified identity fabrics are becoming essential for agentic AIPaul WagenseilJuly 13, 2026
Vulnerability ManagementCheckPoint authentication bypass bug exploited, added to CISA listSteve ZurierJuly 27, 2026CISA orders rapid patching as Check Point auth bypass faces active attacks.
Critical Infrastructure SecurityRep. Bacon warns CISA cuts weaken U.S. cyber defensesSC StaffJuly 24, 2026House Armed Services Committee member urges faster cyber investments as China, Russia threats grow.
Critical Infrastructure SecurityUS warns of Iran-linked attacks on critical infrastructureSteve ZurierJuly 24, 2026Iran-linked hackers target Siemens, Schneider, Rockwell OT.
Application securityAI is overwhelming patch management. Here’s how teams adaptSteve ZurierJuly 23, 2026AI is overwhelming patch teams, forcing a shift to smarter, automated remediation.
AI/MLHugging Face ‘attacker’ revealed to be OpenAI agents that escaped testing sandboxLaura FrenchJuly 22, 2026OpenAI said GPT-5.6 Sol and a pre-release model exploited vulnerabilities to “cheat” on ExploitGym.
IdentitySharePoint vulnerability steals machine keys; fourth recent exploitSteve ZurierJuly 22, 2026New SharePoint flaw exploited as attackers steal machine keys for lasting access.
Application securityJADEPUFFER agentic ransomware returns, targets AI assets with ENCFORGE payloadLaura FrenchJuly 22, 2026The agent abused the victim’s Docker daemon to access and encrypt AI-related files.
RansomwareQilin exploits Palo Alto Networks GlobalProtect VPN firewallsSteve ZurierJuly 21, 2026Qilin exploited a patched Palo Alto VPN flaw, highlighting the cost of delayed patching.