top of page

Blog


Rapid7 InsightVM | Vulnerability Management Series Issue #01 | You Know the Date of Your Next Pentest. What About Your Next Critical Vulnerability?
New CVEs don't wait for your next pentest. Discover why continuous vulnerability management with Rapid7 InsightVM keeps the time between two tests under control.
Sep 29


BlueCat Wednesday | Enterprise LiveAction Series Issue #13 Is the VoIP Problem in the Network or the Application?
Teams calls cut out, yet every link looks healthy. Discover how BlueCat LiveAction shows what the network was doing when voice and video quality dropped.
Sep 29


BlueCat Monday | Enterprise DNS Series Issue #13 DNS Governance
As DNS grows across teams and clouds, control gets harder. Discover how DNS governance balances central policy with delegated operations through RBAC, standards and audit.
Sep 29


BlueCat Wednesday | Enterprise LiveAction Series Issue #10 Where Is the Traffic Going?
A link at 80% utilization tells you how full it is, not why. Discover how BlueCat LiveAction flow analytics reveals who is generating traffic, where it goes and whether it is normal.
Sep 28


Tufin Tuesday | Network Security Policy Management Series Issue #01 | Your Firewall Rule Gets Hits. But Is It Really Right?
A firewall rule that gets traffic every day can still allow far more access than needed. See how Tufin SecureTrack+ uncovers overly broad and shadowed rules.
Sep 28


BackBox Series #01 | You Have Backups. But Can You Really Recover?
Your backup job says Success, but can you actually restore from it? Why network configuration backups fail when you need them most, and how BackBox turns backups into real recovery readiness.
Sep 28


Cybersecurity Threat Intelligence Summary: Twitch Extension OAuth Leak
A malicious cross-store browser extension named "Twitch Enhanced Viewer | JeetBot" has successfully compromised the Twitch OAuth tokens of approximately 31,000 users. Distributed via the Google Chrome Web Store (30,000 installations) and Mozilla Firefox Add-Ons store (604 installations), the tool masquerades as a quality-of-life utility that bypasses regional constraints and provides 1080p streaming. In reality, it acts as a mechanism to harvest bearer credentials for a comme
Sep 21


Canva Data Breach: Corporate Documents of 424 Organizations in Türkiye Exposed
The Turkish Personal Data Protection Authority (GDPR) issued a statement regarding a data breach involving Canva. The breach reportedly exposed employees’ names, business email addresses, workplace locations, phone numbers, as well as certain corporate documents. A significant data breach occurred at online graphic design platform Canva. According to the notification published by the Turkish Personal Data Protection Authority (GDPR), data associated with 424 organizations in
Sep 21


You May Soon Have to Verify Your Age Just to Use Your Computer
Age verification requirements are moving beyond websites. New laws in the United States are set to require operating systems such as Windows to determine the age of their users. Age verification and biometric data-sharing practices, which are rapidly being introduced under the premise of protecting children from the risks of the digital world, have raised growing concerns that they could end online anonymity and ultimately contribute to a surveillance society. Recent developm
Sep 21


Cybersecurity Threat Intelligence Summary: CISA KEV Additions
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. Threat actors are actively weaponizing these vulnerabilities in the wild to bypass authentication, escalate privileges, and compromise critical infrastructure. Vulnerability Breakdown and Exploitation Activity JFrog Artifactory (CVE-2
Sep 21


The ’80s Trend May Not Be So Innocent: Warning from the GDPR !
The rapidly spreading #80sChallenge trend on social media has also caught the attention of the Personal Data Protection Authority (GDPR). The Authority warned that biometric data may be processed through users’ photos. In recent days, a trend on Instagram has encouraged users to transform their photos with artificial intelligence into nostalgic images resembling photographs from the 1980s. The trend has also drawn the attention of the GDPR, which highlighted the importance of
Sep 14


Microsoft Warns of Fake Passkey and CEO-Impersonation Phishing Campaigns Targeting Corporate Accounts
Microsoft has disclosed two social engineering campaigns observed in 2026 that targeted corporate payment workflows and Microsoft cloud identities. The activity combines CEO impersonation, fraudulent invoices and ACH payment requests with phone and SMS phishing built around urgent passkey, MFA and SSO updates. Key Details: Between August 3 and August 5, 2026, more than one million fraudulent emails targeted corporate users in the United States. Attackers impersonated company
Sep 14


Four New REVSTEALER-Linked Modules Disable Windows Updates and Defender
Elastic Security Labs security researchers have uncovered four previously undetected secondary programs linked to the REVSTEALER information-stealer malware targeting Windows systems. It was determined that these programs persist on the system even after the primary malware deletes itself from the victim's device. Key Details: Primary Malware Function: The core REVSTEALER malware steals browser passwords, cookies, cryptocurrency wallets, gaming accounts, and messaging data, n
Sep 7


BlueCat Monday | Enterprise DNS Series Issue #11 Service Discovery
As Applications Change, How Will Services Find One Another? Enterprise infrastructures were once more predictable. An application ran on a specific server, the server's IP address remained unchanged for long periods, and connections between services could largely be managed statically. Today, the situation is entirely different. Virtual machines are created and removed within minutes. Containers are continuously restarted. Workloads move between different nodes in Kub
Sep 7


BlueCat Wednesday | Enterprise LiveAction Series Issue #11 Is Your SD-WAN Really Working as Expected?
The Policy May Be Correct. But What About the Actual Traffic? The promise of SD-WAN is compelling: identify the application, select the best connection, route traffic along the right path, and switch to an alternative link when performance degrades. But a correctly defined policy does not mean application traffic will always take the path you expect. What matters is not seeing the configuration, but seeing the configuration's actual effect on traffic. MPLS, Internet, LT
Sep 7


MikroTik Routers Compromised via Internet-Exposed SSH
Cyber attackers are compromising internet-exposed MikroTik RouterOS routers without requiring any password or valid authentication, gaining full administrative privileges on the devices. Key Details: The National Cyber Security Incident Response Team of Poland published an urgent security advisory on September 5, 2026. Investigations indicate that attacks exploiting this method have been actively used since at least September 2, 2026. This vulnerability chain, dubbed "MikroTr
Sep 7


BlueCat Wednesday | Enterprise LiveAction Series Issue #12 Where Is the Path to the Cloud Slowing Down?
End-to-End Network Visibility Across Hybrid and Multi-Cloud Environments The application is in the cloud, and the user is in the office. Between them are the corporate LAN, WAN, SD-WAN, internet, security layers, cloud gateways, and service-provider infrastructure. When a user says, “The cloud application is slow,” the issue is not a single system but an end-to-end service chain. In modern hybrid and multi-cloud environments, the real challenge is not connecting to the
Sep 7


BlueCat Monday | Enterprise DNS Series Issue #10 DNS Threat Protection
Detect Threats Through DNS Behavior, Not Their Consequences The impact of an attack is often easy to recognize. An endpoint generates an alert. An account is compromised. A system begins generating suspicious traffic. A data exfiltration attempt is detected. By the time this happens, however, the attacker has often already begun operating within the enterprise network. Yet there is an important trace left behind during the earlier stages of an attack: DNS behavior.
Sep 7


BlueCat Monday | Enterprise DNS Series Issue #12 API & Integration
Making DNS an Active Part of the IT Ecosystem In modern IT infrastructure, almost no system operates in isolation anymore. Cloud platforms, virtualization environments, Kubernetes clusters, ITSM tools, CI/CD processes, and Infrastructure as Code platforms continuously create, modify, or remove resources. When a new server is deployed, it requires an IP address. When a new application is released, a DNS record is created. When a workload moves to another environment, its
Sep 7


BlueCat Wednesday | Enterprise LiveAction Series Issue #9 See the Bottleneck Before It Forms.
Most capacity problems are noticed only after users complain. Discover how LiveAction trend analysis reveals links nearing their limits so you can act before the bottleneck forms.
Sep 7
bottom of page