Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Reporting a Vulnerability in Somebody Else's Code

A vulnerability in an open-source library inside your product is your vulnerability to report. The duty follows the product to market rather than the code to its author, so integrating somebody else's component transfers the obligation to whoever ships it. ‍ The reporting is the visible half. The harder consequence is that the same regulation requires remediation across the product in its entirety, and the party who wrote the component may have no obligation to help you. ‍

Evidence for One AI Framework Does Not Count for the Next

An organization assembles an evidence package for one AI framework, passes, and discovers that almost none of it transfers to the next instrument applying to the same system. The frameworks agree on the principles and disagree on what proves them. Three frameworks defining risk differently is the same problem one layer earlier. ‍ The common response is to look for a crosswalk and treat the mapping as a reuse plan.

Emerging Threat: (CVE-2026-78006) The Events Calendar Remote Code Execution via PHP Object Injection

CVE-2026-78006 is a deserialization of untrusted data vulnerability (CWE-502) in The Events Calendar, a WordPress plugin published by StellarWP, that allows an attacker to achieve remote code execution on the underlying host. The flaw sits in the is_safe_widget_instance function, whose guard against unsafe object data can be bypassed.

Introducing the CyCognito MCP Server: Full Exposure Context, On Demand

Today we are happy to announce the beta release of the CyCognito MCP server, which makes your external attack surface data consumable by any AI client that speaks the Model Context Protocol, including Claude, Cursor, and ChatGPT. The server runs on CyQL, the proprietary query language behind advanced search in our platform. CyQL is designed to ask precise questions about an attack surface, using operators suited to each type of asset, issue, and relationship.

AI Agent Security Readiness: The Federal Standard You Should Get Ahead Of

Here's the uncomfortable part first: in August 2026, researchers found AI agents connected to Hugging Face running loose inside enterprise networks. No owner, no audit trail, nobody who could tell you they existed until something broke. If that sentence made your stomach drop a little, good, because it should. It's the same blind spot most security teams are sitting on right now. They just haven't had their version of the incident yet.

Good Security Rating? Your Dark Web Exposure Says Otherwise

Ask a security leader how secure their company is, and most will point to a number. A rating, maybe a grade, or a score out of some maximum that a vendor calculated for them. That number only measures half the problem. It tells you about your infrastructure: your email configuration, your encryption, what's visible on the internet. It tells you much less about whether your employees' credentials are already exposed to an attacker.

AI is learning to control machines...but can it trust them?

Anthropic’s new Model Hardware Standard (MHS) could mark an important step in the evolution of agentic AI. Currently in research preview, MHS provides a standardized way for AI agents to discover, understand and operate physical equipment. Anthropic is already demonstrating the concept with laboratory and manufacturing equipment including robotic arms, microscopes, liquid handlers and laser systems. The objective is compelling.

The Cybersecurity Visibility Gap: What You Can't See Can Still Hurt You

Most security programmes are built to watch the inside of the network, but the threats that do the most damage often start outside it: leaked credentials, impersonated domains, dark web chatter, and vulnerabilities under active discussion. This post looks at why the visibility gap exists, what the data says about it, and what closing it involves.

Best Nonprofit Workflow Management Software: 5 Platforms to Consider

Nonprofit organizations often manage far more than donations. Teams may be coordinating client services, grant applications, events, volunteers, internal approvals, reporting, and day-to-day project management at the same time. The best nonprofit workflow management software should reduce that operational friction, give staff a clearer view of responsibilities, and help information move between people without relying on scattered spreadsheets.

Can Journaling Your Crypto Trades Create Better Results?

Crypto trading can be fast-moving, emotional, and difficult to evaluate objectively. When prices shift quickly, traders may focus on wins and forget the decisions that led to losses. A trading journal offers a practical way to slow down and examine those decisions. By recording the reasoning behind each trade, along with market conditions and the eventual outcome, traders can identify patterns that may otherwise go unnoticed.