A vulnerability in Microsoft’s Active Directory Certificate Services (AD CS) could allow a low-privilege domain user to impersonate a Domain Controller, security…
Date Archives July 2026
OpenAI not part of the new Open Secure AI Alliance
OpenAI is noticeably absent from the list of initial supporters of a new industry initiative to promote the creation of strong, safe,…
The containment paradox: Why your ransomware playbook has the wrong people in charge
I have sat in on a version of the same incident post-mortem in three sectors over the past two years. The script…
When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk
In cybersecurity, defenders sometimes naively assume that threat actors operate from secure, resilient infrastructures insulated from the very chaos they inflict on…
How CISOs can rise to the business resilience challenge
CISOs have quietly become their organizations’ de facto chief resilience officers as the role has evolved from its primary prevention roots to…
Top AIs invent same fake PyPl and npm package names
Enterprise software developers continue to be in danger of falling victim to slopsquatting, where AI coding tools hallucinate the existence of nonexistent…
Tycoon2FA takedown reshapes the phishing landscape
Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a…
Ransomware groups are hammering your vulnerable VPNs
Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain….
AgentForger proves AI agents can become persistent insider threats
A new attack method found by Zenity Labs reveals that AI agents are becoming persistent insiders that attackers can recruit, rather than…
Check Point hole grants unauthenticated attackers full SmartConsole admin privileges
Check Point has confirmed that a critical security hole in its SmartConsole management tool, one that allows unauthenticated attackers to assume full…