Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
F5 BIG-IP APM Linux Rootkit: Detecting Fileless PHP Web Shell Injection and Defending the Edge
Executive summary A reported campaign is breaching F5 BIG-IP APM environments and deploying a Linux rootkit that intercepts PHP file loading...
CISA KEV Flash: 12 CVEs Added — Microsoft, SonicWall, N-able & Adobe Commerce Under Active Attack
CISA KEV Flash: 12 CVEs Added — Microsoft, SonicWall, N-able & Adobe Commerce Under Active Attack CISA has added twelve vulnerabilities to t...
OneTouchPoint Data Breach Settlement: Ransomware Defense Lessons for Healthcare Third-Party Vendors
Introduction OneTouchPoint Corp., a Wisconsin-based mailing and printing vendor serving healthcare organizations, has agreed to a multi-mill...
Trezor–ShipMonk Supply-Chain Breach Hits 81,000 Customers: Defending Against the Coming Phishing Wave
Introduction Trezor has disclosed that the August data breach at its shipping and logistics provider, ShipMonk, is significantly larger than...
Mathspace Breach via Metabase: How Attackers Looted 1M+ Records Through an Exposed BI Platform — Detection and Hardening Guide
Introduction Online mathematics learning platform Mathspace disclosed over the weekend that attackers gained access to its Metabase internal...
Rhysida Ransomware Leaks 6TB of Berlin State Data After 30 BTC Ransom Refusal — Detection and Hardening Guide
Berlin's Rhysida Breach: When Refusing the Ransom Means Losing the Data Berlin refused to pay a 30 Bitcoin ransom. The Rhysida ransomware gr...
Debian DSA-6486-1: libde265 H.265 Codec Flaws Enable DoS and Arbitrary Code Execution — Patching and Detection Guide
Debian libde265 Denial of Service and Code Execution Risk (DSA-6486-1) Debian has issued security advisory DSA-6486-1 addressing two securit...
Why Dependency Modernization in Security Tools Matters: Lessons from Malwarebytes' Engineering Overhaul
The Security Product Itself Is Part of Your Attack Surface Malwarebytes recently published a candid look inside its own engineering organiza...
Infostealers Target Claude AI Sessions, Fire Ant Hits Hypervisors, ValleyRAT Poses as Adware: Defender's Guide to Round 113 Malware Campaigns
Introduction The latest Security Affairs malware roundup (Round 113) reads like a snapshot of where attacker tradecraft is heading in 2026 —...