(Adobe Stock) Critical Atlassian flaw exposes files across eight productsSteve ZurierOctober 6, 2026Unauthenticated attackers could steal credentials and gain access to CI/CD systems.
MCP fixed secret handling. URL elicitation moved the phishing risk into the browserSunil GentyalaOctober 6, 2026
Why it will take strong public-private partnerships to fight AI-based threatsDerek MankyOctober 6, 2026
Okta: The Blueprint Alliance AI-agent framework isn’t ours, but everybody’sPaul WagenseilSeptember 30, 2026
From Data to Decisions to Action: Why Exposure Management’s Next Chapter Runs Through ValidationAnne SaitaSeptember 25, 2026
Network SecurityNew Citrix Netscaler zero-day exploited just days after recent attacksSteve ZurierOctober 5, 2026Third exploited NetScaler flaw in a week signals attackers are moving faster than patch cycles.
Active DirectoryWhen identity becomes the outageSC Editorial Intelligence , expert reviewedOctober 5, 2026
Vulnerability ManagementFortinet FortiMail bug exploited in the wild, added to CISA KEV listSteve ZurierOctober 2, 2026Exploited FortiMail flaw lets attackers turn email security gateways into persistent footholds.
LeadershipMimecast’s Beth Miller: Leading others to make the right decisionsSC StaffOctober 2, 2026The Mimecast Field CISO says true leadership is empowering people to decide properly without your input.
Vulnerability ManagementCisco Catalyst SD-WAN Manager flaw added to CISA’s exploit listSteve ZurierOctober 1, 2026CISA flags actively exploited Cisco SD-WAN Manager authentication bypass flaw.
MalwareFake Zoom installer delivers new CloudSyncD macOS backdoorLaura FrenchOctober 1, 2026The malware uses a unique Unicode-based method to hide the user’s password in a fake Zoom configuration file.
Malware2 new forms of malware exploited Citrix Netscaler devices one month before patchSteve ZurierSeptember 30, 2026Google report focuses on exploit of CVE-2026-88772, which executed lateral movement a month before a patch existed.
MalwareMalicious ChatGPT Custom GPTs lead to ClickFix attackLaura FrenchSeptember 30, 2026Instructions to visit a malicious website were delivered through the real ChatGPT site.