Vulnerability ManagementHow the ‘Lethal Trifecta’ sets the conditions for stealing data on commandGabe JacksonDecember 12, 2025Combine untrusted human input, access to sensitive data, and a path to exfiltrate information – and AI agents become dangerous.
Vulnerability ManagementNorth Korea-linked ‘EtherRAT’ backdoor used in React2Shell attacksLaura FrenchDecember 11, 2025The malware retrieves C2 addresses from Ethereum smart contracts to avoid takedowns.
AI/MLGoogle addresses ‘GeminiJack’ exploit affecting Gemini EnterpriseLaura FrenchDecember 10, 2025An indirect prompt injection could have exfiltrated data from emails, documents or calendars.
Vulnerability ManagementReact2Shell lands on CISA’s KEV list: patch right away!Steve ZurierDecember 9, 202510.0 RSC flaw actively exploited in the wild by China-based threat groups within hours of public disclosure leads the pack for December's Patch Tuesday.
AI/MLSeven ways to develop a governance framework for AI browsersGuy Waizel December 8, 2025Govern with identity-first controls, data-aware policies, session isolation, and continuous validation.
Application securityFrom admin-led maintenance to policy-as-code: Re-architecting Salesforce governance for securityPaul WagenseilDecember 7, 2025In many companies, Salesforce instances are chaotic, unsecured messes. Here's how to tame them with proper governance and security controls.
Vulnerability ManagementReact2Shell bug exploited by China-linked groups, fix briefly disrupts CloudflareSteve ZurierDecember 5, 2025React2Shell shows patching must be immediate — attackers now weaponize flaws within hours.