Security Education Through the Art of Storytelling
In today’s digital world, cybersecurity isn’t just a technical issue, it’s a human one. At Okta, we’ve taken a fresh approach to security education by leveraging a tool as old…
In today’s digital world, cybersecurity isn’t just a technical issue, it’s a human one. At Okta, we’ve taken a fresh approach to security education by leveraging a tool as old…
Email remains the primary vector for cyberattacks, posing significant threats like phishing, malware, and sophisticated business email compromise (BEC) schemes. For government agencies, contractors, and organizations handling sensitive or regulated…
Security teams are overwhelmed with findings but still struggle to answer a simple question: which risks matter right now? A vulnerability alone is rarely the problem. The same vulnerability running…
Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed…
Since June, developers have created thousands of third-party OAuth apps on Cloudflare, with more than a million authorizations since. OAuth makes delegated access possible. It lets applications act on a…
Overview On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0…
OpenAI is slowing parts of its frontier AI development as its newest models approach cybersecurity capabilities powerful enough to trigger the company’s highest-level safeguards. The company said Aug. 18 that…
This is Part 2 of a three-part series. Read Part 1 and Part 3. Table of Contents Introduction Artisanal Event Generation Unit Tests 1. Introduction In the previous blog in…
One of the most effective steps organizations can take to improve their defensive readiness is to move from periodic testing to cultures of constant training. To keep pace with emergent…
When Patching Isn’t Enough: What the Fairlife Ransomware Attack Says About Network Edge Risk A recent ransomware attack by the Anubis group against Coca-Cola-owned dairy company Fairlife forced a temporary…