Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
€30M Commerzbank Fraud via Service Provider Exploit: Third-Party Detection and Hardening Guide
A €30M Reminder That Your Perimeter Includes Your Providers Law enforcement in Brazil arrested four cybercriminals, and three additional sus...
Clop Claims 89GB Data Theft from Shell: Defending Against Mass Extortion-Style Exfiltration
Shell Investigates Clop's Claim of 89GB Data Theft — What Defenders Must Do Now Shell has confirmed it is investigating a potential security...
Trivy Supply-Chain Compromise: How a Poisoned GitHub Action Exposed 2,500 Organizations — Detection and Remediation Guide
The Real Patient Zero: Trivy, Not LiteLLM When the LiteLLM supply-chain attack broke, the initial narrative pointed at poisoned PyPI package...
Insider Data Theft and Extortion: Lessons from the Brightly Software Contractor Sentencing — Detection and Prevention Guide
A former data analyst contractor for Brightly Software has been sentenced to two years in federal prison for stealing his employer's data an...
Ukraine Dismantles 94 Fraudulent Call Centers: Defending Your Organization Against Vishing and Investment Scam Operations
Ukraine's Takedown of 94 Fraudulent Call Centers: What Defenders Need to Know Ukrainian law enforcement, in coordinated raids across the cou...
Kimwolf v7 Android/IoT Botnet: Detecting and Defending Against HTTP/2 DDoS Attacks That Mimic Legitimate Browsing
Introduction Palo Alto Networks Unit 42 has disclosed a significant evolution of the Kimwolf/AISURU botnet — version 7 — discovered in Febru...
Zoom Annotation Tool Flaws Enable Zero-Click Client Takeover: Detection, Patching, and Hardening Guide
Introduction Zoom has disclosed a set of serious vulnerabilities in its annotation feature — the tool that lets meeting participants draw, h...
CVE-2026-58231: SAP Commerce Cloud Data Hub RCE (CVSS 10.0) — Detection, Hardening, and Remediation Guide
Introduction SAP's August 2026 Security Patch Day release includes a fix for CVE-2026-58231, a maximum-severity vulnerability in the SAP Com...
CVE-2026-59310: Actively Exploited VMware vCenter Directory Traversal — Detection and Remediation Guide
CVE-2026-59310: VMware vCenter Under Active Attack Broadcom's VMware vCenter Server is once again in the crosshairs. Security researchers at...