Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
JFrog Artifactory Chained Exploit Grants Admin Access: Detection, Hunting, and Remediation for Self-Hosted Servers
Chained JFrog Artifactory Flaws Hand Attackers the Keys to Your Build Pipeline Between August 15 and September 8, researchers at Wiz observe...
Trezor Third-Party Email Provider Breach: Defending Hardware Wallet Users Against Targeted Phishing and Social Engineering
Trezor Warns of Email Provider Breach Fueling Social Engineering Attacks Trezor has disclosed that threat actors breached its third-party em...
CVE-2026-84361: openSUSE php-composer2 Moderate Fix — Patch, Verify, and Hunt Guide
CVE-2026-84361: openSUSE php-composer2 Moderate Fix — Patch, Verify, and Hunt Guide openSUSE advisory openSUSE-2026-11689-1 ships php-compos...
Securing Edge AI in Customer-Owned Environments: Attestation, Trust Verification, and Defensive Architecture (2026)
Introduction Microsoft's recent guidance on securing edge AI in customer-owned environments surfaces a problem I've watched grow steadily th...
Why Dependency Modernization in Security Tools Matters: Lessons from Malwarebytes' Engineering Overhaul
The Security Product Itself Is Part of Your Attack Surface Malwarebytes recently published a candid look inside its own engineering organiza...
Trezor–ShipMonk Third-Party Breach: 67,000 U.S. Customers' 'Deleted' Data Exposed — Detection and Response Guide
Introduction On Friday, hardware wallet manufacturer Trezor disclosed that a breach at its shipping provider, ShipMonk, has exposed the pers...
H1 2026 Malware & Vulnerability Trends: Defending Against Trusted Tool Abuse, AI-Driven Attacks, and Supply Chain Compromise
The Threat Landscape Has Shifted — And Your Detections Need to Shift With It Recorded Future's H1 2026 malicious software and vulnerability ...
CVE-2026-82329: JFrog Artifactory Auth Bypass Under Active Exploitation — Detection and Remediation Guide
A Critical Artifactory Flaw Is Being Exploited — And Your Build Pipeline Is the Prize Within days of public disclosure, threat actors began ...
llm-anthropic 0.27 and the anthropic-sdk-python v1.0.0 Breaking Change: A Defender's Guide to Managing the httpx-to-httpx2 Dependency Shift
Introduction On August 24, 2026, Simon Willison released llm-anthropic 0.27, an update to the Anthropic plugin for his LLM command-line tool...