The purpose of a vendor management policy is to identify which vendors put your organization at risk and then define controls to minimize third-party and fourth-party risk. It starts with due diligence and assessing whether a third-party vendor should have… Read More "Creating a Vendor Management Policy and Why You Need One"
Critical Orkes Conductor Vulnerability Exploited in Attacks
A critical-severity vulnerability in Orkes Conductor that can be exploited without authentication has been in attackers’ crosshairs for at least a month. Conductor is an open source unified enterprise framework that allows organizations to orchestrate microservices, workflows, and AI agents.… Read More "Critical Orkes Conductor Vulnerability Exploited in Attacks"
Strong fundamentals make next-gen security possible
2. Manage your identities more effectively Security leaders have been saying “identity is the new perimeter” for almost a decade, but identity management is still overlooked or taken for granted. That’s a real problem, because the average organization now manages… Read More "Strong fundamentals make next-gen security possible"
Beware the SparroWock: The backdoor that bites, the commands that catch
ESET Research’s ongoing monitoring of FamousSparrow has borne fruit once again. Our previous public report on FamousSparrow revealed that this China-aligned APT group had developed two new versions of its custom backdoor named SparrowDoor. This time, we discovered that FamousSparrow… Read More "Beware the SparroWock: The backdoor that bites, the commands that catch"
Manufacturing Accounts for 22% of all Ransomware Victims
Manufacturing organizations made up over a fifth (22%) of all ransomware victims in the period from April 2025 to March 2026, according to new Black Kite study. This made the industry the most targeted by ransomware attacks for the fifth… Read More "Manufacturing Accounts for 22% of all Ransomware Victims"
Vendor Offboarding: Best Practices for Ensuring Security
When organizations hear “third-party risk management,” they often consider the processes needed to mitigate risks when working with a third-party vendor. These can include procurement risks and risks associated with starting new vendor relationships, often referred to as “onboarding,”—but what… Read More "Vendor Offboarding: Best Practices for Ensuring Security"
MIND Secures $72 Million for AI-Powered DLP
Data loss prevention (DLP) startup MIND has announced raising $72 million in a Series B funding round that brings the total raised by the company to $112 million. The investment round was led by Crosspoint Capital Partners, with additional support… Read More "MIND Secures $72 Million for AI-Powered DLP"
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. “HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data… Read More "Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords"
SafePal Data Breach Hits Tens of Thousands of Customers
The manufacturer of a popular cryptocurrency hardware wallet has told tens of thousands of its customers to be on the lookout for phishing attempts after it suffered a data breach. SafePal published an update on August 16 claiming that order… Read More "SafePal Data Breach Hits Tens of Thousands of Customers"
FFIEC and its Third-Party Risk Management Requirements
The Federal Financial Institutions Examination Council (FFIEC) has established cybersecurity standards to protect financial institutions from the growing threat of cyberattacks. With third-party security risks quickly becoming one of the most critical attack vectors facilitating data breaches in the financial… Read More "FFIEC and its Third-Party Risk Management Requirements"