vendor
20 articles
CISOs are feeling the security burden of accelerated AI use
Chinese espionage groups swarm to exploit triple-link chain of zero-days
The state of AI for security: Measuring what matters most for building trust
Security teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response, an...
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence,...
Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it
If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them. Every scan begins with the s...
The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords
The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April.
Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s w...
How we rebuilt Cloudflare Workers’ module registry for Node.js compatibility
Workers now enables Node.js compatibility by default, supports applications up to 64 mebibytes, and adds a URL-based module registry with import.
Proofpoint 2026 Voice of the CISO Report Finds Cyber Resilience Improving, While AI Expands the CISO Mandate
Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes...
Proofpoint SOC Analyst Agent Uses OpenAI Cyber Models
Microsoft Patch Tuesday, September 2026 Security Update Review
Microsoft kicks off September with its monthly Patch Tuesday release, delivering fixes for security vulnerabilities affecting its products. The security upda...
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
104Critical 860Important 0Moderate 0Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates incl...
Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”
Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Man...
4 Questions to Ask When Evaluating an Exposure Management Platform
Executive Summary Exposure management platforms are increasingly evaluated based on post-detection actions rather than detection itself.
StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited ...
Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)
Automatic Key Exchange probes TLS 1.3-capable customer origins to learn which key agreement algorithms they support.
CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)
Overview While conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulner...