The Case for Zero Standing Privileges
The principle of least privilege is one of the best known laws of information security: and it’s often the most difficult to put into practice. The principle demands that a…
The principle of least privilege is one of the best known laws of information security: and it’s often the most difficult to put into practice. The principle demands that a…
Research by: Jaromír Hořejší (@JaromirHorejsi) Key points StopAndProtect is a newly identified operation that combines file encryption with data theft. The criminals abuse thousands of hacked WordPress websites as their…
In this article Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare…
This release has something for everyone: scanner modules, payloads, and exploits. This release’s scanners cover Drupal, PanOS, WordPress, and SCADA; this release’s exploits cover Tenable, Flowise, CheckPoint, Langflow, Ruby, and…
Last month, on our second Content Independence Day, we announced a couple of features designed to give website owners more visibility and control over automated traffic: BotBase added a searchable…
Two Australian men have been charged for their alleged roles in TeamPCP, a cybercrime group linked to software supply chain attacks that compromised organizations worldwide. Australian Federal Police (AFP) arrested…
CVE-2026-19490: Critical Citrix NetScaler Authentication Bypass Exposes Enterprise Gateways Cloud Software Group has released critical security updates to address CVE-2026-19490, an authentication bypass vulnerability (CWE-288) in NetScaler ADC and NetScaler…
Security teams must extend the same controls to the agent’s interactions with internal systems and agents. Restricting what it can access on the internet, or disabling internet access entirely, does…
At the 2026 Executive Partner Summit, Palo Alto Networks President BJ Jenkins made one thing clear: the AI era is the platform era — and above all, the AI era…
A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. It is the shared attack surface where…