A user tries to start their workday, but their laptop is stuck in a “blue screen of death” loop. Halfway across the world, someone tries to post on X, but nothing loads. These are the real-world ripple effects of a… Read More "CISA Calls for More Guidance, Less Spin, as Outages Escalate"
Top Vendor Risk Monitoring Solutions for Continuous Oversight
Most vendor risk programs still rely on periodic assessments that capture a single snapshot of a vendor’s security posture, then go silent for months while that posture changes. Attackers exploit those same gaps between scheduled reviews, and the numbers prove… Read More "Top Vendor Risk Monitoring Solutions for Continuous Oversight"
280,000 Impacted by Premier Medical Group Data Breach
New York healthcare provider Premier Medical Group (PMG) is notifying over 280,000 patients that their personal and medical information was stolen in a data breach. PMG offers in-depth patient care across cardiology, dermatology, gastroenterology, neurology, plastic surgery, gynecology, and internal… Read More "280,000 Impacted by Premier Medical Group Data Breach"
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Ravie LakshmananSep 16, 2026Vulnerability / Linux Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8),… Read More "Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks"
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Artificial intelligence (AI) is enabling threat actors to send unholy volumes of fraudulent emails, personalized to a degree that mass emailers of old couldn’t have touched. Last month, Microsoft researchers tracked a phishing campaign in which an unattributed threat actor… Read More "Threat Actor Generates 1M Personalized Fraud Emails in 3 Days"
Key Vendor Risk Assessment Criteria and How to Apply Them
Vendor risk assessments need to be tailored to the unique cyber risk criteria of third-party vendors. This post explains how to determine which risk criteria apply to each vendor and how to measure their severity. Those criteria sit inside a… Read More "Key Vendor Risk Assessment Criteria and How to Apply Them"
Hackuity Raises $19 Million for AI-Powered Vulnerability Management
Vulnerability management company Hackuity has raised $19 million in a funding round led by Forgepoint Capital, bringing its total funding to $38 million. The Lyon, France-based company plans to use the investment to accelerate development of its vulnerability operations platform,… Read More "Hackuity Raises $19 Million for AI-Powered Vulnerability Management"
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can’t Install Fix
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine… Read More "Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can’t Install Fix"
LinkedIn fights for the right to tell customers when the feds want their data
Privacy now a ‘data stewardship obligation’ Jeff Valdes, a director at Acceligence, noted, “there is definitely some irony here.” “If Microsoft wants customers to view it as a steward of their privacy when the government comes asking for their information,… Read More "LinkedIn fights for the right to tell customers when the feds want their data"
‘Sandworm’ Chains Cisco Flaws to Deploy Cyclops Blink
A likely Russian threat actor is deploying a sophisticated malware implant capable of harvesting credentials, scanning internal networks, and capturing live traffic on compromised devices by chaining two vulnerabilities in Cisco’s Firewall Management Center (FMC) technology. In separate reports, Sophos… Read More "‘Sandworm’ Chains Cisco Flaws to Deploy Cyclops Blink"