Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The State of Ransomware 2026: Payments are dropping but encryption is climbing

The State of Ransomware 2026: Payments are dropping but encryption is climbing Insights from 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit by ransomware in the past year. This year's data has a few eyebrow-raising departures from the patterns of past State of Ransomware reports. Exploited vulnerabilities lost their three-year grip on the top root-cause spot. Median ransom demands and payments both dropped, yet the average recovery bill still climbed.

Emerging Threat: (CVE-2026-56164) SharePoint Server Privilege Escalation via Missing Authentication

CVE-2026-56164 is a privilege escalation vulnerability in on-premises Microsoft SharePoint Server, caused by a missing authentication check on a critical function (CWE-306). An unauthenticated attacker can exploit it over a network, with no credentials and no user interaction required. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium), and Microsoft rates it Moderate.

GitProtect 2.4.0: Complete QA Protection in Azure DevOps, FIPS-Compliant Encryption, and More

The new 2.4.0 release delivers complete protection for your entire Quality Assurance (QA) workloads in Azure DevOps. Teams on platforms hosted locally in Windows can now secure them with the AES encryption compliant with the federal, enterprise-grade FIPS standards. This release also packs other notable upgrades, including seamless Active Directory integration, a smarter repository exclusion mechanism, and full German language support. Dive into the full breakdown below.

AI Man-in-the-Middle: The Trust Problem Hiding in Plain Sight

I remember the days when merely saying “AI” was enough to earn glares for bringing up such a taboo subject, almost equivalent to saying “Voldemort.” Now, AI is at the center of many people’s daily lives and certainly at the center of business operations. I find myself using AI for everyday tasks. Unfortunately for security teams, the bad guys are using it too.

Is Internxt Safe? A Look at Our Zero-Knowledge Security

If you're asking is Internxt safe for your cloud storage, it's natural to ask whether it's safe enough to trust with your personal or business data. Security is one of Internxt's biggest selling points, and privacy for everyone is Internxt’s mission. With features like post-quantum and zero-knowledge encryption, independent security audits, and GDPR and other compliance certifications, Internxt is designed to keep your files private and accessible to nobody but you. In this article, we'll explain.

From SAP to Identity Manager by One Identity - use FASTlane

The end of an era is upon us, as SAP has announced the end of life for their identity governance and administration (IGA) platform — a platform that supported several SAP products. Without this pivotal identity management tool, where are customers to go to protect the digital identities of their organization? And how can they know that any new platform will be trustworthy? SAP hasn’t left their customers in a lurch.

Monitor Apigee X API traffic and security with Datadog

Apigee X is Google Cloud’s API management platform. Software and platform teams use it to secure, publish, and govern the APIs that internal services, partners, and external developers depend on. Apigee X sits in the request path for that traffic, so a latency spike or a rise in policy errors reaches API consumers before most other signals do. Watching proxy traffic, latency, and security posture usually means jumping between Apigee analytics and separate infrastructure tools.

The Permission Boundary Myth: Why Authorized Doesn't Mean Appropriate for Coding Agents

Coding agent security has a framing problem. Most security conversations around these tools center on the wrong question. 'Did the agent have permission to do that?' is a reasonable place to start, but in the context of autonomous AI systems, it's not where the risk actually lives. In Zenity Labs' research into the coding agent threat model, the pattern that keeps surfacing isn't that agents are doing things they aren't allowed to do.