Topic
Risk & Security

Critical Netlogon RCE on domain controllers (CVE-2026-41089)
A critical, unauthenticated remote code execution vulnerability in Windows Netlogon (CVE-2026-41089, CVSS 9.8) lets a remote attacker run code as SYSTEM on a domain controller. Patch all domain controllers in the same maintenance window with the May 2026 security updates.

World Cup ’26: What it takes to secure the world's biggest sporting event
For cyber defenders, the work is invisible by design. For fans, a little awareness goes a long way.

Tanium at the Gartner Security & Risk Management Summit 2026
As security leaders prepare to tackle the industry’s most urgent priorities, Tanium will bring the real-time intelligence and agentic AI capabilities needed to close the gap between insight and execution.

May 2026 GitHub breach: Extension hygiene is still a challenge–so what can we do about it?
On May 20, 2026, GitHub disclosed that an employee device was compromised through a malicious VS Code extension, with attackers claiming to have exfiltrated roughly 3,800 internal repositories.

Mini Shai-Hulud supply chain attack: Why this campaign changes how defenders should think about trusted software
The Mini Shai-Hulud supply chain attack compromised more than 170 packages across npm and PyPI, including packages from TanStack, Mistral AI, and Guardrails AI, by hijacking legitimate CI/CD publishing workflows to distribute malicious versions that still carried apparently valid provenance signals.

Copy Fail (CVE-2026-31431): What Linux administrators need to know now
Copy Fail, or CVE-2026-31431, is a Linux kernel local privilege escalation vulnerability that can let an unprivileged local user corrupt page-cache-backed file data under specific conditions and potentially escalate privileges. Exposure depends on the running vendor kernel and backported fixes. Installing a vendor-provided kernel fix is the primary remediation, with temporary mitigations available in some environments if patching is delayed.

Vercel security incident: What the breach reveals about OAuth trust, supply chain risk, and response speed
Public reporting suggests the incident involved abuse of a third-party application that had been granted OAuth access to a Vercel employee account, enabling unauthorized access to some internal resources. Certain customer‑related tokens, environment variables, or other access artifacts may have been exposed, though Vercel has not stated that password theft was part of the initial access path. The breach illustrates how trusted SaaS integrations and delegated access have become a significant attack surface for enterprises with interconnected developer workflows, even when no software vulnerability in production infrastructure is exploited.

Understanding shadow AI in your endpoint environment
Learn how shadow AI appears on endpoints, from local models to MCP servers, and why visibility, governance, and secure configuration matter now.

Why our AI world demands a remediation-first approach to exposure management
Explore how a remediation‑first model turns exposure data into meaningful risk reduction in an AI world.

Why EDR isn't enough on its own
Security teams don’t struggle because they lack tools. Most have plenty. What they struggle with is confidence. Confidence that they’ve seen the full scope of an incident, that nothing was missed, and that the threat is truly eliminated.

The CISO Is Leaving – Now What? These 5 Succession Plan Tips Will Keep Orgs Safer
Increasing compliance demands, regulatory mandates, and a host of other stressors can mean a pretty short tenure for the average CISO. Don’t get caught scrambling to fill the role: Follow these best practices to keep the transition smooth and your organization safe.

What Is Multifactor Authentication (MFA)?
Learn what multifactor authentication is, how it works, common types, and why it's critical to modern cybersecurity.