How to Evaluate Cyber Risk Quantification and GRC Reporting Platforms
Consider the Decision Chain, Not the Dashboard
20 articles
Consider the Decision Chain, Not the Dashboard
Most security stories start with something broken. This one starts with everything working as designed.
Deloitte has expanded AI Controls and Assurance services and solutions designed to help organizations confidently adopt, scale and govern AI across the enter...
Something shifted in security operations over the last two years: AI stopped being a pilot program and became the plan. And if you survey 500 security profes...
This month’s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took...
Threat researchers have identified an active campaign exploiting the critical VMware vCenter vulnerability CVE-2026-59310, with 361 victim IP addresses obser...
A newly disclosed vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-63520, could allow attackers to execute arbitrary code remotely on affect...
ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilit...
Microsoft has disclosed a new remote code execution (RCE) vulnerability in Outlook, tracked as CVE-2026-70329. They warn that successful exploitation could a...
In 2021, a vulnerability was revealed in a system that lay at the foundation of modern computing. An attacker could force the system to execute arbitrary code.
PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, th...
The unauthorized network, named "Delta WiFi Fast," was reportedly created by passengers attending the DEF CON hacker conference.
The group, which extorts victims by threatening to publish stolen data rather than using ransomware, has expanded its operations, according to a recent repor...
Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the sys...
The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As att...
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakn...
Amazon Web Services (AWS) is pleased to announce that the Summer 2026 System and Organization Controls (SOC) 1 report is now available. The reports cover 185...
42Critical 355Important 1Moderate 0Low Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploit...
ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity i...
When I give talks about AI genies, I use this sort of example as a hypothetical. It’s happened.