(Adobe Stock) Fortinet FortiMail bug exploited in the wild, added to CISA KEV listSteve ZurierOctober 2, 2026Exploited FortiMail flaw lets attackers turn email security gateways into persistent footholds.
For Cybersecurity Awareness Month, it’s time to rethink zero-trust for the AI eraDanny JenkinsOctober 1, 2026
Okta: The Blueprint Alliance AI-agent framework isn’t ours, but everybody’sPaul WagenseilSeptember 30, 2026
From Data to Decisions to Action: Why Exposure Management’s Next Chapter Runs Through ValidationAnne SaitaSeptember 25, 2026
LeadershipMimecast’s Beth Miller: Leading others to make the right decisionsSC StaffOctober 2, 2026The Mimecast Field CISO says true leadership is empowering people to decide properly without your input.
Vulnerability ManagementCisco Catalyst SD-WAN Manager flaw added to CISA’s exploit listSteve ZurierOctober 1, 2026CISA flags actively exploited Cisco SD-WAN Manager authentication bypass flaw.
MalwareFake Zoom installer delivers new CloudSyncD macOS backdoorLaura FrenchOctober 1, 2026The malware uses a unique Unicode-based method to hide the user’s password in a fake Zoom configuration file.
Malware2 new forms of malware exploited Citrix Netscaler devices one month before patchSteve ZurierSeptember 30, 2026Google report focuses on exploit of CVE-2026-88772, which executed lateral movement a month before a patch existed.
MalwareMalicious ChatGPT Custom GPTs lead to ClickFix attackLaura FrenchSeptember 30, 2026Instructions to visit a malicious website were delivered through the real ChatGPT site.
SC AwardsSC Awards Celebrate 30 Years of Recognizing the People and Technology Advancing Cybersecurity Kelley DamoreSeptember 29, 2026
Training57% of security execs report challenges with onboarding entry-level staffSteve ZurierSeptember 29, 2026SkillBit survey says security teams struggle to find and train new staff as AI compresses the time they have to patch new bugs.
Threat IntelligenceShinyHunters targets Oracle PeopleSoft in new campaign amid FBI attack claimsLaura FrenchSeptember 29, 2026Google says ShinyHunters found a way to bypass WAF rules to reach vulnerable endpoints.