The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) have issued final guidance for protecting cloud identity tokens and assertions from theft, forgery and misuse, aimed at federal agencies, cloud service providers and… Read More "CISA and NIST Issue Guidance to Protect Cloud Identity Tokens"
What is a Third-Party Risk Assessment in Cybersecurity?
A third-party risk assessment pulls vendor risk data to help cybersecurity teams understand how to best mitigate supplier risks. Though the field of Third-Party Risk Management (TPRM) is evolving to prioritize compliance, security, and supply chain risk, third-party risk assessments… Read More "What is a Third-Party Risk Assessment in Cybersecurity?"
AIUC Raises $40 Million to Certify Enterprise AI Agents
AIUC (Artificial Intelligence Underwriting Company) has announced raising $40 million in a Series A funding round that brings the total raised by the company to $55 million. The investment round was led by Ribbit Capital, with additional support from First… Read More "AIUC Raises $40 Million to Certify Enterprise AI Agents"
Threat Intelligence Alone Won’t Close the Exploitation Gap
The Hacker NewsSep 16, 2026Threat Intelligence / Security Validation A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have… Read More "Threat Intelligence Alone Won’t Close the Exploitation Gap"
Reducing Supply Chain Security Risks with Vendor Segmentation
Security teams often spend the same assessment effort on a commodity SaaS tool as they do on a critical enterprise resource planning integration. That mismatch leaves high-exposure suppliers under-watched while low-stakes vendors consume the queue. Vendor segmentation isolates which third… Read More "Reducing Supply Chain Security Risks with Vendor Segmentation"
Pixel Modem Zero-Day Exploited in Targeted Attacks
Google on Tuesday informed Pixel phone owners that it has patched a zero-day vulnerability exploited in targeted attacks. The zero-day is tracked as CVE-2026-58704, and Google said it’s aware of “limited, targeted exploitation”. The vulnerability has been rated high severity… Read More "Pixel Modem Zero-Day Exploited in Targeted Attacks"
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a… Read More "N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security"
Major Cyber Threat Detection Vendors Turn to New UK Testing Program
UK-based security testing and advisory provider SE Labs is launching a new testing program to help buyers evaluate cybersecurity vendors – and has attracted some prestigious names. The six-month testing program, called PIVOT, was unveiled by SE Labs on September… Read More "Major Cyber Threat Detection Vendors Turn to New UK Testing Program"
Creating a Vendor Risk Summary Cybersecurity Report
A vendor risk report provides stakeholders with a snapshot of your Vendor Risk Management (VRM) performance. With concerns over the threat of supply chain attacks growing, cybersecurity reporting is evolving towards an increased focus on Vendor Risk Management program performance.… Read More "Creating a Vendor Risk Summary Cybersecurity Report"
ATM Flaws Reveal Key Weaknesses in the Software Supply Chain
For the past five years, security researcher Matt Burch has immersed himself in the esoteric and high-stakes world of ATM security, in which small software flaws can sometimes expose cold, hard cash. As Burch has bored deeper into the computers… Read More "ATM Flaws Reveal Key Weaknesses in the Software Supply Chain"