top of page

Blog


Zero News | The Caller ID Shows Your Company, But It Isn't You Calling
Attackers spoofed Astrana Health's own phone number to talk employees into granting access. Here is why vishing works and how to stop it.
21 hours ago


Zero News | A Fake "I'm Not a Robot" Check Steals Every Password in Your Browser: Lunex Stealer
A fake CAPTCHA tricks users into running a command, then Lunex blinds antivirus with a vulnerable AMD driver and steals browser passwords and cookies.
21 hours ago


Zero News | AI Is Guessing Your Bank Balance: The RatHat Android Banking Trojan
RatHat uses Google's Gemini to estimate victims' bank balances from stolen SMS and target the richest ones. See how it works and how to protect your phone.
21 hours ago


Zero News | Update Your iPhone Now: Apple Zero-Day Used in Targeted Attacks (CVE-2026-86950)
Apple patched a CoreGraphics zero-day already used in targeted attacks. Here is who is affected, which versions fix it and what to do now.
3 days ago


The Credential Layer Is Expanding Faster Than Security Teams Can See It
Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and what they can access. This is the first of three articles we are releasing that explain the
4 days ago


New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to denial-of-service under specific deployment conditions," Citrix said. "The issue affects cust
4 days ago


Rapid7 InsightVM | Vulnerability Management Series Issue #04 | Can You Manage a Vulnerability from Start to Finish in Your Own Environment?
"Do we have it?" is only reliable if you know what you can see. Discover how to manage a vulnerability from visibility to verified remediation in your own environment.
Sep 29


Rapid7 InsightVM | Vulnerability Management Series Issue #03 | The Priority Is Clear. But Who Will Fix It, and By When?
The ticket is closed but the vulnerability is still there. Discover how ownership, due dates, ITSM integration and verification turn priorities into proven outcomes.
Sep 29


Rapid7 InsightVM | Vulnerability Management Series Issue #02 | Finding 10,000 Vulnerabilities Is Not Success
A long vulnerability report is not a plan. Discover how Active Risk and solution-based remediation show which action reduces the most risk, and why now.
Sep 29


GEODI Discovery Series | Issue 16 | Discover Your Data. Understand It. Protect It. Create Value.
Data is more than a file path. Discover the full journey from finding and understanding data to protecting, governing and creating value from it.
Sep 29


GEODI Discovery Series | Issue 15 | Data Governance: From Discovery to Governance
Visibility alone is not governance. Discover how data ownership, shared classification and policies tied to real data turn discovery into governance.
Sep 29


GEODI Discovery Series | Issue 14 | AI-Ready Data: Do You Trust the Data You Give Your AI?
Your AI may answer correctly from the wrong document. Discover why data quality, versions and access decide how trustworthy enterprise AI really is.
Sep 29


GEODI Discovery Series | Issue 13 | Data Retention: Should We Keep Every Piece of Data Forever?
Old files, duplicate copies and forgotten archives keep costing money and risk. Discover how visibility turns data retention from theory into informed decisions.
Sep 29


RSA Thursday | Identity Security Series Issue #16 | Identity-First Security: The New Starting Point for Modern Cybersecurity
Behind every access request is an identity. Discover why identity-first security has become the starting point of modern cybersecurity, for people, machines and AI agents.
Sep 29


RSA Thursday | Identity Security Series Issue #15 | Identity Security in the AI Era: How Is AI Transforming Identity Security?
AI is changing both sides of identity security. Discover how attackers use it to scale social engineering and how defenders use it to evaluate identity risk continuously.
Sep 29


RSA Thursday | Identity Security Series Issue #14 | Account Takeover: What If the Right Credentials Are in the Wrong Hands?
Attackers don't always break in; sometimes they log in with a trusted identity. Discover how account takeover works and why trust must be evaluated beyond the login.
Sep 29


RSA Thursday | Identity Security Series Issue #13 | Machine & Non-Human Identities: Who Manages Non-Human Identities?
Service accounts, APIs, workloads and AI agents often outlive the projects that created them. Discover why non-human identities need the same lifecycle and least privilege as people.
Sep 29


BlueCat Wednesday | Enterprise LiveAction Series Issue #16 From Visibility to Predictability
Mature network operations do more than fix problems faster. Discover how trends and historical telemetry help teams anticipate issues before users feel them.
Sep 29


BlueCat Wednesday | Enterprise LiveAction Series Issue #15 The Problem Happened. But What Was the Network Doing at the Time?
Intermittent problems vanish before teams can see them. Discover how historical network forensics lets you revisit what the network was doing when users were affected.
Sep 29


BlueCat Wednesday | Enterprise LiveAction Series Issue #14 How Did a Change Affect the Network?
A change can pass every test and still degrade performance. Discover how comparing network behavior before and after a change turns assumptions into evidence.
Sep 29
bottom of page