(Adobe Stock) Effective incident response plans elusive for most cybersecurity teamsSteve ZurierJuly 29, 2026Experts say untested incident response plans leave firms unprepared.
Seven controls enterprise teams need in place to avoid another OpenAI-Hugging Face incidentHimanshu ShuklaJuly 29, 2026
Define a Minimum Viable Business for disaster recovery — before the next incidentAharon TwizerJuly 28, 2026
When sensitive data moves everywhere, security attestations become a liabilityJustin Beals July 27, 2026
Phishing the agent: Why identity controls are essential to secure and manage AIsPaul WagenseilJuly 27, 2026
Cut to the chase: How to save time and effort through validation in exposure managementPaul WagenseilJuly 17, 2026
Vulnerability ManagementIPMI bug in BMCs found after 22 years, exposes 24,000-plus serversSteve ZurierJuly 28, 2026Decades-old IPMI bug leaves thousands of internet-facing servers exposed.
Vulnerability ManagementCheckPoint authentication bypass bug exploited, added to CISA listSteve ZurierJuly 27, 2026CISA orders rapid patching as Check Point auth bypass faces active attacks.
Critical Infrastructure SecurityRep. Bacon warns CISA cuts weaken U.S. cyber defensesSC StaffJuly 24, 2026House Armed Services Committee member urges faster cyber investments as China, Russia threats grow.
Critical Infrastructure SecurityUS warns of Iran-linked attacks on critical infrastructureSteve ZurierJuly 24, 2026Iran-linked hackers target Siemens, Schneider, Rockwell OT.
Application securityAI is overwhelming patch management. Here’s how teams adaptSteve ZurierJuly 23, 2026AI is overwhelming patch teams, forcing a shift to smarter, automated remediation.
AI/MLHugging Face ‘attacker’ revealed to be OpenAI agents that escaped testing sandboxLaura FrenchJuly 22, 2026OpenAI said GPT-5.6 Sol and a pre-release model exploited vulnerabilities to “cheat” on ExploitGym.
IdentitySharePoint vulnerability steals machine keys; fourth recent exploitSteve ZurierJuly 22, 2026New SharePoint flaw exploited as attackers steal machine keys for lasting access.
Application securityJADEPUFFER agentic ransomware returns, targets AI assets with ENCFORGE payloadLaura FrenchJuly 22, 2026The agent abused the victim’s Docker daemon to access and encrypt AI-related files.