Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Why Asset Visibility Alone Isn't Enough

Knowing a device exists is only the first step. In this clip, David Clapp explains why effective risk management requires more than asset inventory. Factors like device type, ownership, business role, network location, communication patterns, and reachability all contribute to understanding risk and making informed security decisions.

Living Off the Land Attacks: Detection and Response Guide

The most popular advice about living off the land attacks is also the least useful when it stands alone: hunt for suspicious PowerShell, block LOLBins, and alert whenever a signed Microsoft binary behaves unexpectedly. Those controls have value, but they don't solve the operational problem. PowerShell, WMI, certutil.exe, and bitsadmin.exe are legitimate administrative utilities, and attackers abuse them precisely because security teams can't remove them without disrupting normal work.

Emerging Threat: (CVE-2026-21580) Confluence Privilege Escalation via Unauthenticated Stored XSS

CVE-2026-21580 is a stored cross-site scripting vulnerability in Atlassian Confluence Data Center and Server, which the vendor advisory groups together with a privilege escalation component and a security misconfiguration weakness. An attacker persists crafted HTML or JavaScript on a vulnerable instance, and that payload executes later in the browser of whichever user views the affected content. The vulnerability carries a CVSS 4.0 base score of 8.6.

What You Need to Know about the Microsoft Azure Employee Data Breach

A threat actor using the alias TheHatman is selling employee databases allegedly stolen from the Microsoft Azure cloud environments of some of the world's largest companies. Beginning on July 31, 2026, the cybercriminal posted a series of listings on underground forums advertising data dumps from at least nine major organizations, claiming the records were downloaded directly from corporate Azure tenants using compromised credentials.

What You Need to Know about the CareCloud Data Breach

CareCloud, Inc. is a publicly traded healthcare technology company headquartered in Somerset, New Jersey. The company provides electronic health records, medical billing, practice management, and revenue cycle services to more than 45,000 healthcare providers across the United States. Because it stores patient records and billing information on behalf of hospitals, doctors' offices, and other medical practices, CareCloud holds sensitive data belonging to millions of patients.

How to Develop Vulnerability Assessment Skills Through Cybersecurity Courses

This process is a vital part of digital protection because it helps organizations identify technical flaws before unauthorized users exploit them. Experts who develop accurate evaluation skills examine computers, networks, software and settings to determine where security upgrades are required. Cybersecurity courses offer structured information plus hands-on practice to help students learn evaluation methods, analyze results and suggest specific safety protocols.

Penetration Testing Options Worth Knowing

Penetration testing has turned into one of those services every business claims to offer, but the actual delivery varies wildly. Some firms hand you an automated scan with a logo slapped on the report. Others put a named, accredited tester on your network who explains exactly what they found and why it matters. For businesses, charities and schools weighing up who to call, the accreditation behind the tester matters as much as the report format. Here are eight providers worth knowing, starting with a CREST-accredited option built around direct access to the people doing the work.

Attribute-Based Access Control: How ABAC Works, Examples and Use Cases

Access control has become significantly more complex as enterprises adopt cloud platforms, AI applications, and distributed workforces. A user’s identity alone is no longer enough to determine whether they should access sensitive data. Factors such as device posture, data sensitivity, location, and business context all influence the right decision. This shift is driving widespread adoption of attribute-based access control, a model that evaluates multiple attributes before granting access.

They Paid Medusa's Ransom. A Second Medusa Actor Called and Demanded Half Again.

The FBI documented a Medusa ransomware victim who paid the ransom—and was then contacted by a second, separate Medusa actor, claiming the original negotiator had stolen the payment and demanding half the ransom again for the "true" decryptor. That's triple extortion, and it's the strongest argument in the whole CISA/FBI/MS-ISAC advisory (AA25-071A) against paying at all. There is no guarantee the extortion stops when the money moves.