95% of Security Teams Blindsided by Vulnerabilities Between Tests
The vast majority of enterprise security teams are being blindsided by vulnerabilities that scheduled testing never catches, according to new research from Synack, which describes…
The vast majority of enterprise security teams are being blindsided by vulnerabilities that scheduled testing never catches, according to new research from Synack, which describes…
As modern cars have evolved into multi-ton computers on wheels, drivers are beginning to learn they need to install security updates for their vehicles’ code,…
Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams…
You expect all kinds of apps on Apple’s App Store and Google’s Play Store, from weather monitors to home automation apps and games. What you…
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable…
The UK financial services regulator took enforcement action against 74 “finfluencers” last year, as it continues to target unregulated individuals who use social media to…
The Estée Lauder data breach has prompted the global cosmetics company to notify affected individuals after hackers exploited a vulnerability in Oracle E-Business Suite, a platform used…
Healthcare technology company Clover Health Investments has disclosed a data breach impacting customers’ personal and health information. Discovered on July 4, the incident was the…
Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875 Pierluigi Paganini July 21, 2026 Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on…
The ever-widening blast radius of AI testing Local AI testing environments are becoming a dangerous security blind spot that information security leaders often overlook. Rapid…
What are CVE-2026-63030 & CVE-2026-60137? These vulnerabilities comprise a critical pre-authentication remote code execution (RCE) chain in WordPress Core, dubbed “wp2shell”, discovered by Searchlight Cyber…
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. Last…