Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Introducing LimaCharlie Email Security: One Phish, Start to Finish

Introducing LimaCharlie Email Security. It connects to Microsoft 365 or Google Workspace through the provider's API, with no MX change and nothing in the delivery path, and shows the signals behind its verdicts. This walkthrough follows one malicious email from its 94/100 verdict through how the score compounds, a benign contrast with its measured processing timeline, the evidence, link analysis, response at the provider, hunting across the organization, groups and campaigns, user reports, the rule that caught it, policy, and email as telemetry for detection and response rules.

Emerging Threat: (CVE-2026-84411) MikroTik RouterOS Unauthenticated Root RCE via Web Management

CVE-2026-84411 is an integer underflow in the web management service of MikroTik RouterOS, classified as CWE-191. The flaw sits in the service’s HTTP request body handling and is reachable before authentication. A single crafted request lets an unauthenticated network attacker execute arbitrary code as root, or crash the device. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical).

How to Choose an Application Security Solution

Most teams need a combination of application security tools rather than a single one. Common categories are SAST, DAST, IAST/RASP, SCA, API and container security, and ASPM, and each covers a different stage of development. When you evaluate options, look for coverage that matches your stack, integration with developer workflows, accurate findings, risk-based prioritization, and actionable remediation guidance.

A Short History of Crypto Customer Data Leaks, and What They Teach

In August 2026, Trezor told about 13,700 US customers that their names, email addresses, phone numbers and shipping addresses had been stolen in a breach at ShipMonk, a logistics company that had once handled its orders. Weeks later the number rose to roughly 80,700, after the company found the stolen records also covered orders placed between late 2019 and mid-2021. Customers who had bought a wallet five years earlier, and long since forgotten the delivery, were suddenly on a list in the hands of an extortion group.

Open-Source Intelligence Tools for Security Teams

Attackers rarely start with an exploit. They start with a search: which subdomains a company runs, which staff email addresses sit in breach dumps, which forgotten server still answers on the internet. MITRE ATT&CK treats this stage as a tactic of its own, Reconnaissance, and most of it runs on public data.

The Year the Vulnerability Backlog Changed Shape

As we enter the AI era, few among us have found themselves so entrenched in the throes of the shifting landscape as CISOs. With the threat landscape shifting, they are up against increasing rates of vulnerabilities and exploits alongside rapidly scaling demands for ever more secure environments. As CISOs, with our role as the protectors of an organization, we are expected to deliver guidance and security visibility. This is not a vision of the future, it’s today’s reality.

Cyber Loss in Rail and Signalling

Cyber risk in transport is usually framed around a collision. Signals manipulated, a train sent onto occupied track, an accident caused deliberately. ‍ Signalling is built to make that outcome unavailable. Any failure forces the system into its most restrictive state, so a compromise produces a halt rather than a crash. The loss is the halt, and rail is unusual in already having a published price for one. ‍

Reading AI Use From the Browser When the Network Sees Nothing

A session to a sanctioned AI provider looks the same on the network whichever account it ran under and whatever was in it. Transport encryption means a proxy sees a connection to an approved domain and a payload size. ‍ Which is fine until somebody asks whether an exposure is reportable. The question turns on three facts the network never held, and none of them can be reconstructed from a log afterward. ‍

Why academic selfie fraud benchmarks fail in the real world

Academic deepfake datasets rarely static: generate an image, label it real or fake, done. Real-world fraud doesn't hold still. Zhaofeng Si, a PhD student at University at Buffalo and research scientist intern at Persona, breaks down the gap. Public academic datasets are mostly typical face swaps and diffusion-model-generated images with a fixed label. In the real world, there's an attack-and-defense loop. Fraudsters actively probe for ways to bypass detection, so defenses have to keep adapting instead of training against a static benchmark.