Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

New Phishing Kit Gives Threat Actors Live View Into Attacks

A new phishing platform called “JWR” gives attackers real-time control over social engineering attacks, according to researchers at Cisco Talos. The kit livestreams the phishing page to the attacker as the victim is entering information, allowing the attacker to steer the victim’s experience and maximize the damage.

The .vu Surge: How Threat Actors Are Exploiting Vanuatu's Domain Extension

Phishing infrastructure is built to be thrown away. When a domain gets blocklisted, scrutinized, or too hot to handle, the attackers don't stop. They just move. To them, a domain extension is just a cheap tool. They go wherever it is easiest to strike. That pattern is visible in our own telemetry. In late 2024 and early 2025, KnowBe4 Threat Lab documented a 98% spike in phishing campaigns abusing.ru domains. 1,500 unique domains, over 13,000 malicious emails, with an average domain age of just 7.4 days.

Warning: Replying to a "Wrong Number" Text Marks You as a Target for Scams

Attackers are using “wrong-number” texts to identify potential targets for scams, according to researchers at Malwarebytes. These texts appear to be harmless messages meant for another person, such as “Are we still on for dinner tomorrow?” or “Where’s the PowerPoint?” Recipients often try to be helpful by replying to let the person know they’ve got the wrong number.

How Medical Dictation Technology Can Save You Time Without Creating New Risks

Healthcare professionals spend countless hours documenting care, often long after the patient interaction has ended. Between clinical notes, treatment plans, referrals, and compliance requirements, documentation can become one of the most time-consuming parts of the job. Medical dictation technology offers a way to reduce that burden by turning spoken information into structured records. However, saving time only matters when accuracy, privacy, and workflow compatibility remain intact.

How Owners Can Protect Their Time While Growing Their Investments

Owning rental property is one of those wealth-building moves that sounds simple from the outside. Buy the property, rent it out, collect checks, repeat. Then reality shows up with a leaking faucet, a late rent payment, three vendor texts, and a lease renewal you forgot was due Friday.

ESP32 Marauder tutorial for WPA2 deauthentication and handshake capture

Wireless networks are often assumed to be secure once WPA2 is enabled. In practice, that assumption is only partly true. While WPA2 remains widely used and is not inherently broken, the real security of a wireless network depends heavily on how it is configured, how client devices behave, and how strong the Pre-Shared Key (PSK) actually is. As a result, the protocol label alone can sometimes create a misleading sense of security.

The AI challenge most companies don't have

A few months ago, I attended a GC AI Summit hosted by Harvard Law School. As expected, there was plenty of discussion about AI tools, governance frameworks, emerging regulations, and the future of the legal profession. One topic of discussion stood out above the others: Most organizations only need to think about how they deploy AI, whereas we have to think about how we deploy AI and how we develop AI.

GPT-5.6 Sol Shows Why a Better Model Isn't a Uniformly Safer Model

Veracode Research’s latest secure-coding test finds GPT-5.6 Sol with a 15-point Python gain beneath modest aggregate movement, evidence that cyber capability and secure-code generation do not move in lockstep. OpenAI calls GPT-5.6 Sol its “strongest cybersecurity model yet.” Veracode’s extension test finds it scoring only two percentage points higher overall on secure-code generation than GPT-5.5, but it scores 15 points higher in Python.

The Vulnerability Tax: What CVE Response Costs at the Network Edge

Network edge vulnerabilities are accelerating. Cato’s cloud-native architecture reduces customers’ attack surface and shortens exposure to emerging vulnerabilities. The Cato CVE Exposure Calculator shows what that difference could mean for your organization. Another Known Exploited Vulnerability (KEV). Another emergency CAB. Another weekend spent upgrading firmware. You have to respond. The question is how much each response costs the business.

ServiceNow + UpGuard: Automating Risk Management Together

UpGuard connects to ServiceNow across the whole platform. Vendor risk findings, breach alerts, and user risk signals all land in the same ticket queue your team already works from, not a separate, siloed risk dashboard. With this integration, you can: Risk Automations makes this possible. You define the events that matter: a monitored vendor picks up a new risk, a risk score drops below a threshold you set, a credential breach turns up on a watched domain, or a questionnaire response comes in.