Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Shai-Hulud Infostealer Now Scans 469 Credential Locations: Detection and Remediation Guide for Dev and CI/CD
Shai-Hulud Infostealer Now Scans 469 Credential Locations: Detection and Remediation Guide for Dev and CI/CD In early August, GitGuardian re...
CREST AI-Enabled Penetration Testing Accreditation: What the First Cohort Means for Security Buyers and Defenders
CREST Accreditation for AI-Enabled Pentesting Arrives — and Buyers Need a New Playbook CREST, the international not-for-profit accreditation...
Breeze Comet (UNC5669): Defending Brazilian Payment Systems Against a Fraud-Focused Intrusion Actor
Introduction Google Threat Intelligence Group (GTIG) and Mandiant have published attribution on a financially motivated intrusion actor trac...
CVE-2026-9586: Sangoma Switchvox SQL Injection Under Active Exploitation — Detection and Remediation Guide
CVE-2026-9586: Sangoma Switchvox SQL Injection Under Active Exploitation Sangoma Switchvox — the on-premises Unified Communications / VoIP P...
CVE-2026-82329: JFrog Artifactory Auth Bypass Under Active Exploitation — Detection and Remediation Guide
A Critical Artifactory Flaw Is Being Exploited — And Your Build Pipeline Is the Prize Within days of public disclosure, threat actors began ...
Wiz Continuous Vulnerability Assessment (CVA): Closing the Gap Between CVE Publication and Exploitation
Wiz has introduced Continuous Vulnerability Assessment (CVA), a capability designed to detect organizational exposure to newly published vul...
CVE-2026-76060: ZoneMinder OS Command Injection via Event Export — Detection and Remediation Guide
Introduction CISA published ICS advisory ICSA-26-237-02 disclosing CVE-2026-76060, an authenticated OS command injection vulnerability in Zo...
WhatsApp Multiple Passkeys and Stronger Two-Step Verification: A Defender's Configuration and Hardening Guide
WhatsApp Raises the Bar on Account Security — What Defenders Need to Do Now WhatsApp has begun rolling out a set of account security enhance...
Operation QUICSILVER: Detecting and Defeating the QUICAgent Go Backdoor Targeting Myanmar Government and IT
Introduction Seqrite Labs has disclosed an active cyber espionage campaign, codenamed Operation QUICSILVER, targeting Myanmar's government a...