Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Shadow AI: What Clients Aren't Telling Their MSPs

MSPs are expected to understand their clients’ technology environments. They know which endpoints are managed, which applications are business-critical, which systems require patching or maintenance, where sensitive data resides and who has access to it. Increasingly, however, critical technology decisions are now being made without IT or MSP involvement. Across client environments, this can take many forms: And each instance can occur without the MSP ever knowing.

CYJAX Intelligence Now Lands Directly Inside Google SecOps and Microsoft Sentinel

CYJAX intelligence is now built directly into Google SecOps SIEM and Microsoft Sentinel, giving analysts structured, normalised threat data inside the platforms they already use. Four feeds are live in Google SecOps and eight endpoints are available in Microsoft Sentinel's Content Hub.

Emerging Threat: (CVE-2026-81891) elFinder Remote Code Execution via ZIP Extraction MIME Bypass

CVE-2026-81891 is an unrestricted file upload vulnerability in Studio 42 elFinder, an open source web file manager embedded in a wide range of PHP applications and content management systems. The flaw sits in the checkExtractItems() function in php/elFinderVolumeDriver.class.php, which calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize().

Recruitment-Themed Phishing Campaign Targets Enterprise Users

Researchers at Zimperium are tracking widespread phishing campaigns that use Browser-in-the-Browser (BitB) attacks to trick users into handing over their enterprise credentials. The attackers impersonate real HR employees at major companies and target job seekers with extremely realistic interview processes.

New Phishing Kit Uses AI to Fully Automate Vishing Attacks

A new phishing kit is using generative AI to fully automate voice phishing (vishing) attacks, according to researchers at Group-IB. The phishing platform, called “Balonx,” includes a module dubbed “CallFlow” that the researchers say “represents a fundamental evolution” in the phishing-as-a-service market.

CVE-2026-49481: Vulnerability in UpSnap

On 26/05/2026, a security researcher at Astra Security found a critical Remote Code Execution (RCE) vulnerability in UpSnap, a web-based wake-on-LAN(WoL). The root cause is an OS Command Injection vulnerability(CWE-78) that exists in UpSnap’s device management functionality due to unsafe template interpolation of the IP and MAC fields.

How to Detect Shadow AI: 8 Key Steps

Security teams have spent years building visibility into unsanctioned SaaS apps, cloud services, and other forms of shadow IT. But shadow AI raises the bar. Discovering an unsanctioned AI app or autonomous agent is only the beginning. Teams also need to determine which identities it authenticates with, what credentials and permissions it relies on, what data it can access, which systems it integrates with, and what downstream actions it performs. The scale of the challenge is already becoming apparent.

Response Options: Multiple Methods to Mitigate Risk

Seemplicity’s new Response Options feature gives teams multiple ways to respond to a confirmed finding, not just a single full-fix recommendation. AI Analysts surface and rank fix, neutralization, and mitigation paths based on security impact, deployment risk, and effort, helping teams reduce exposure faster while making safer, more informed remediation decisions. Every exposure management program eventually hits the same wall.

Why security questionnaires can't measure vendor risk

“Friends don’t send friends security questionnaires. “If you hang around me long enough, you will hear me say it. It gets a laugh, but the point underneath it is serious. Are security questionnaires enough to manage third-party risk? No. A questionnaire tells you what a vendor is willing to claim on a given day. It does not tell you whether the control behind that claim is working. Those are two very different things, and most third-party risk programs are still built on the first one.

How to Build a More Flexible and Connected AV Setup

A boardroom gets used for a client demo on Monday, a town hall on Wednesday, and a hybrid interview on Friday. It was built for one of those. It's now handling all three, badly. That mismatch is what flexible AV design fixes. Not by cramming in more gear, but by rethinking how the room, the network, and the equipment connect to each other in the first place.