Explore our latest research, insights, and guidance on emerging security threats and best practices
We regularly publish our security findings, guidance, and analysis to help organizations stay ahead of emerging threats.
Cisco confirmed active exploitation of a 10.0-rated authentication bypass in Secure Firewall Management Center. State actors and Qilin ransomware operators are in the mix. Federal agencies face a September 12 patch deadline. Here is what to check on your side.
Mathew Potter
Security Analyst
Roughly 6.4 million people show up in breach data tied to McKesson. Veradigm says a vendor credential opened an API path to patient records. If you touch PHI through third parties, your own questionnaire answers are about to get harder.
Mathew Potter
Security Analyst
Microsoft fixed nearly 1,000 CVEs on September 8, including two privilege-escalation flaws exploited in the wild. One sits in Windows Update Stack. The other is an ALPC sandbox escape. Here is how to prioritize without drowning in the bulletin list.
Mathew Potter
Security Analyst
The DOJ took down platforms tied to attacks on the Federal Reserve and other US agencies. Switzerland lost 200 government accounts through SharePoint. Meanwhile Greatness PhaaS is pushing fake RingCentral alerts. Here is what actually matters for your team.
Mathew Potter
Security Analyst
Big Law breaches this summer were less about locked servers and more about stolen files and quiet extortion. Here is what that means if you run a firm or advise one.
Mathew Potter
Security Analyst
Carriers are not asking whether you have MFA anymore. They want enrollment numbers, restore tests, and evidence that matches what you attested on the application.
Mathew Potter
Security Analyst
Subscribe to our research newsletter to receive the latest security insights directly in your inbox.
We respect your privacy. Unsubscribe at any time.