Cisco patches 10.0 bug in leading AsyncOS email productsSteve ZurierJanuary 16, 2026CVE-20225-20393 was placed on CISA's Known Exploited Vulnerabilities (KEV) catalog on Dec. 17.
How the principles of disaster recovery can guide us with cyber resilienceSnehal AntaniJanuary 16, 2026
From quantum resilience to identity fatigue: Trends shaping print securityAurelio MaruggiJanuary 15, 2026
Bouncing back better: Submit your nominations for the Resilient CISO AwardPaul WagenseilJanuary 5, 2026
A serial entrepreneur’s journey from marketing to cybersecurity: Founder StoriesPaul WagenseilDecember 24, 2025
Alexandra Seymour to receive Excellence in Action award for advancing national cybersecurity policy at ICIT 2025 GalaBill BrennerDecember 23, 2025
Autonomous IT, real-time endpoint intelligence, and unified operations and security: Turning operations data into faster decisionsBill BrennerDecember 22, 2025
State Department CIO Kelly Fletcher to receive Impact Award for advancing secure global diplomacy at ICIT 2025 GalaBill BrennerDecember 22, 2025
Threat IntelligenceHow Gootloader uses malformed ZIP archives to evade detectionLaura FrenchJanuary 16, 20267zip and WinRAR fail to extract the archive’s contents, while the Windows default tool easily opens it.
Security OperationsMicrosoft takes down cybercrime subscription service RedVDSSteve ZurierJanuary 15, 2026Virtual cybercrime subscription service stole $40 million in the U.S. alone.
Application securityCursor vulnerability enables stealthy RCE via indirect prompt injectionLaura FrenchJanuary 15, 2026An attacker could have triggered certain shell built-in commands without user approval.
Security OperationsOnly 15% of CISOs say they have visibility into third-party riskSteve ZurierJanuary 14, 2026The Panorays survey noted that only 21% of CISOs have tested crisis response plans in place.
Security OperationsBroadcom chip software flaw affecting ASUS routers enables DoSLaura FrenchJanuary 14, 2026The exploit requires no authentication and requires a manual router reset to reconnect.
Security OperationsMagecart network targeted Amex, Diners Club, MasterCard since 2022Steve ZurierJanuary 13, 2026Experts point out that Magecart attacks exploit third-party scripts on web browsers, bypassing traditional security controls.
Threat Management‘Pig butchering-as-a-service’ provides ready-to-use kits, infrastructureLaura FrenchJanuary 13, 2026Infoblox researchers detail the offerings of entities known as UWORK and the Penguin Account Store.
Application security2026 AI reckoning: Agent breaches, NHI sprawl, deepfakesStephen WeigandJanuary 13, 2026Experts warn 2026 brings agent-driven breaches, NHI abuse and deepfake trust shocks.