IncidentVPN Breach Hits 70+ Banks in 14 Days
Summary of the Incident A single unpatched VPN vulnerability in Marquis Software s platform compromised over seventy financial institutions. This vulnerability was present in the production infrastruc
Expert perspectives on application security, compliance, and emerging threats
IncidentSummary of the Incident A single unpatched VPN vulnerability in Marquis Software s platform compromised over seventy financial institutions. This vulnerability was present in the production infrastruc
IncidentIMPORTANT NOTICE : This teardown analyzes a hypothetical scenario based on researcher predictions about AI worm capabilities. As of this writing, no documented enterprise breach by an autonomous AI wo
ResearchReliaQuest has identified a threat cluster named OP-512 deploying custom web shell frameworks against Microsoft IIS servers, with moderate to high confidence attribution to China-based actors. The fra
IncidentMicrosoft recently expanded its agentic AI security taxonomy with seven new failure modes. These patterns emerged from incidents involving deployed AI systems. If you re running AI agents in productio
Get weekly security insights and compliance updates delivered to your inbox.
StandardsThe National Vulnerability Database backlog isn t just NIST s problem—it s yours. When the OIG found that analysts severity calculations matched NIST s only 12% of the time, they exposed a systemic is
IncidentWhat Happened Between March 18 and today, attackers launched over 29,300 attempts to exploit WordPress sites using Everest Forms Pro, a premium form builder plugin. The vulnerability, tracked as CVE-2
IncidentA remote code execution vulnerability in Apache Commons Text surfaced in October 2022, affecting versions 1.5.x through 1.9.x. While not as widespread as Log4Shell, CVE-2022-42889 highlights how trans
IncidentWhat Happened On October 25, 2022, the OpenSSL project announced a critical vulnerability in OpenSSL 3.0.x. The patch was released on November 1, 2022, providing organizations exactly seven days to pr
IncidentA malicious GitHub issue could hijack your entire repository. Security researcher RyotaK demonstrated this by finding a critical flaw in Anthropic s Claude Code GitHub Action, identifying around 50 wa
IncidentWhat Happened Between late 2024 and early 2025, attackers compromised 57 npm packages using a technique that bypasses common security controls. Instead of hiding code in lifecycle scripts like preinst
IncidentIronWorm malware infiltrated 36 npm packages with a single goal: steal everything your CI/CD pipeline knows about your infrastructure. JFrog researchers caught the attack early, but the incident expos
ResearchYour package.json scripts are clean. Your lockfile passes integrity checks. You run npm audit before every deployment. Yet, you re still vulnerable to the attack vector that compromised 281 npm packag
IncidentWhat Happened Hola Browser s Windows distribution was compromised through its software supply chain, resulting in a cryptocurrency miner being bundled with legitimate installations. The malicious exec
GuidesYour Kubernetes cluster is running inference endpoints that make thousands of external API calls per minute. Your AI agents are spinning up containers to execute code they generated. Your security pol
GeneralScope This guide addresses credential theft and malware propagation through package registries, focusing on the NPM ecosystem. You ll find steps for detecting supply chain compromise, hardening develo
IncidentWhat Happened An unauthenticated attacker can execute arbitrary PHP code on Magento stores running the Mirasvit Cache Warmer extension by sending a malicious cookie. CVE-2026-45247 , a PHP object inje