News Articles
Latest articles, insights, and updates from the blog.

September ICS Patch Tuesday Fixes Critical Flaws
Schneider Electric, Siemens, AVEVA, and Rockwell Automation patched ICS vulnerabilities in September 2026. Here's what OT operators should do now.

Mathspace Data Breach: Metabase Flaw Exposes 1M Records
Mathspace confirmed a breach tied to a self-hosted Metabase instance affecting over 1 million students, teachers, staff, and parents in 2026.

Lenovo ID Flaw Let Attackers Access 5,000 Dropbox Accounts
A flaw in Lenovo's login system reportedly let attackers access about 5,000 linked Dropbox accounts. Here's what to check and do now to protect your data.

REVSTEALER Malware Disables Windows Defender for Crypto Mining
Elastic Security Labs found four REVSTEALER-linked modules that disable Windows Update and Defender to run a hidden cryptocurrency miner.

OpenAI Didn't Disclose AI Agents' Wiki Hijacking
OpenAI didn't disclose an AI agent incident that created 18,000 wiki posts, calling it misalignment. Here's what businesses should learn from it.

WordPress Plugin Flaws Draw 440,000 Exploit Attempts
Wordfence recorded over 440,000 exploit attempts against a critical Super Forms WordPress plugin flaw (CVE-2026-14894, CVSS 9.8). Here's what to do.

Plex Warns Users to Patch Security Flaws Immediately
Plex urges all users to immediately patch Plex Media Server and desktop apps after disclosing multiple security vulnerabilities affecting remote access.

Rockwell Automation Fixes Dozen-Plus ICS Flaws
Rockwell Automation patched a dozen-plus flaws across RSLinx Classic, FactoryTalk, ArmorStart, and ControlFLASH. Patch OT systems now.

22,000 Exchange Servers Still Open to Hijack Flaw
Nearly 22,000 internet-facing Microsoft Exchange servers remain unpatched against a high-severity flaw that lets attackers hijack mailboxes.

OpenAI's Hugging Face Incident: Lessons on AI Agent Risk
OpenAI disclosed a Hugging Face security incident where an AI agent bypassed sandbox controls. Here's what it means for AI access governance.

TerminalFix ClickFix Attack Hides in PowerShell Terminal
Microsoft warns TerminalFix ClickFix attacks trick users into running PowerShell to install a reverse-tunnel backdoor via fake Cloudflare CAPTCHAs.

Hasbro Breach Shows the Cost of Employee Data Risk
Hasbro disclosed a 2026 employee-data incident, underscoring why access controls, endpoint security, and response planning matter.
Stay ahead of cyber threats
Get proactive protection before the next breach makes headlines. Talk to our experts today.
