Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Critical macOS Screen Sharing Authentication Bypass - Under Active Exploitation (CVE-2026-65400)

On August 6, 2026, Apple shipped an emergency, out-of-band fix for CVE-2026-65400, an authentication issue in screensharingd, the daemon behind Screen Sharing, macOS's built-in remote desktop service that listens on TCP port 5900. Apple's advisory describes an attacker who could reach the service over the network and authenticate without valid credentials, then read and write files as root—enough to achieve full remote code execution.

"Endpoints running slow?" Agentic Performance Analysis in Tanium Atlas: Tanium Tech Talks #168

Performance issues can seem like a maze to navigate when you're manually correlating data. And identifying driver issues? Well, no one wants to go there without a performance SME. But what happens when you introduce agentic analysis? Jason Stough shows how Tanium Atlas gets you from fleet-wide analysis to investigating a single endpoint to a confirmed root cause, fast.

Slash Commands Bring Expert SecOps Workflows to Atlas

Security teams don't have a shortage of data. They have a shortage of time, repeatability, and senior expertise available at the exact moment an analyst needs it. That's the problem Atlas slash commands are designed to solve. With /hunt, /investigate, and /signal, Atlas turns a simple chat interaction into a guided SecOps workflow grounded in live endpoint state.

ShieldBreak: The Windows Defender 0-Day with No Patch - And What to Do About It.

In mid-June 2026, Microsoft acknowledged RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protection Engine (mpengine.dll), the scanning engine behind Windows Defender. Microsoft rated it "Exploitation More Likely" on its Exploitability Index and assigned a CVSS score of 7.8. Microsoft shipped a fix in Malware Protection Engine version 1.1.26060.3008 during its July 2026 patch cycle.

AI Is Accelerating Vulnerability Discovery. Tanium Helps You Keep Up.

Following the Mythos announcement in April 2026, organizations using AI to identify software vulnerabilities have contributed to a significant rise in newly discovered CVEs and CVE definitions. This shift reflects a broader trend across the industry: AI is helping uncover vulnerabilities faster than ever before — and security teams need the visibility, control, and speed to respond. At Tanium, we've been tracking this trend closely across customer environments.

Bringing Tanium's real-time endpoint intelligence into enterprise AI workflows with MCP

Enterprise AI is quickly moving from experimentation to day-to-day operational use. Security analysts, IT operators, and platform teams are increasingly working inside AI-native environments — from Claude and Microsoft Copilot experiences to internally built agents and automation workflows. But there is a practical challenge: AI workflows are only as useful as the enterprise systems they can safely reach.

Introducing Agentic SecOps: Live Endpoint Truth for the AI-Driven SOC

Security operations teams are being asked to move faster than ever. Adversaries are using automation, infrastructure changes by the minute, and the number of alerts, exposures, and investigative paths keeps growing. But too many SOC workflows still depend on scarce expert time. A senior analyst writes the query, translates the hypothesis, pivots across tools, validates the result, and then hands the finding off for action. The craft works.

Tanium and Google Threat Intelligence bring Google-grade threat intel to the live endpoint

Security teams are under pressure to move faster, investigate more confidently, and make better decisions with fewer resources. But even the best security operations teams run into the same problem. They often do not have a reliable place to start. Threat hunting depends on high-quality intelligence and experienced analysts who know how to turn that intelligence into useful pivots. Alert triage depends on knowing which signals matter and which ones are noise.