AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security
Securing software-as-a-service (SaaS) apps is hard. The standard cybersecurity controls are not designed for SaaS. The difficulty is the software doesn’t belong to the user…
Securing software-as-a-service (SaaS) apps is hard. The standard cybersecurity controls are not designed for SaaS. The difficulty is the software doesn’t belong to the user…
Malware Found in Laravel-Lang Composer Packages After Git Tag Poisoning Attack Pierluigi Paganini May 26, 2026 Attackers have poisoned four Laravel-Lang Composer packages by rewriting…
We are launching the Detectify MCP Server to deliver real-time vulnerability data and attack surface insights directly into your AI-powered workflows. Built for developers and…
The packages were designed to steal developer secrets, including AWS credentials, GitHub tokens, SSH keys, browser data, environment variables, crypto wallets, and local development configuration…
Cyber-physical systems (CPS) protection company Claroty announced an integration with Corsha, a Machine Identity Provider (mIDP). The collaboration unites Claroty’s Continuous Threat Detection (CTD) with…
Researchers at Check Point Research detailed that the Iranian Islamic Revolutionary Guard Corps (IRGC)-affiliated threat actor known as Nimbus Manticore resurfaced during the ongoing Iran…
The new year brings new beginnings, new perspectives and a whole trove of new trends to look out for. We recently hosted our first Tradecraft…
CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS)…
Windows administrators are facing a disruptive bug in Windows Server 2016 following Microsoft’s May 12, 2026, security update KB5087537. The update introduced a critical flaw…
In the wake of attacks on CEOs, a nationwide protest movement targeting data centers, and increasing concerns about AI job replacement, federal intelligence agencies and…
China-linked hackers are conducting a stealthy infrastructure-centric espionage campaign across Southeast Asia by compromising Linux-based edge routers with a custom ELF implant and pairing it…
Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the SharePoint…