Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Cybersecurity Directive That Reached Ten Times More Entities

The headline change in Europe's network security directive is scope. Directive (EU) 2022/2555 reaches an estimated hundred and sixty thousand entities across eighteen sectors, roughly ten times what its predecessor covered. ‍ The more consequential change is who decides. Under the previous regime a member state identified operators of essential services individually, through an assessment of criticality and dependency.

What Google Gemini's Sandbox Escape Reveals About Securing APIs Against AI Agents

Recently, Gemini was running a capture-the-flag exercise in a sandbox operated by the AI testing firm Irregular. Its task was to steal data from a fictional company. On three occasions, the fictional target shared a name with a real business. Gemini slipped past the test’s containment, reached the open internet, and broke into the real company’s systems. In one case it guessed the password. In the other two, it pulled working credentials from a public database of leaked passwords.

10 Cyber Security Tips to Follow in 2026

As businesses use more cloud services and connected devices, cyber threats have also become more sophisticated and more dangerous. The use of AI-based tools in organizations has also given attackers new ways to carry out phishing, social engineering, and other techniques used to gain access to business systems and sensitive data. At the same time, phishing, ransomware, account compromise, and data theft remain common security threats.

Attack Surface Management Vendors Compared

Most attack surface management (ASM) evaluations start with a name already on the table: a vendor from a G2 grid, an analyst shortlist, an inbound email, or a renewal conversation. Before you commit to a proof of concept (POC), you need to know how it compares. This page provides a capability matrix across 10 ASM vendors, followed by an honest section on each. UpGuard makes one of the platforms on this list, so every section, ours included, covers where the product isn't the right fit.

Find Out if You're Exposed on the Dark Web

Mistaking a lack of alerts for a lack of threats is a dangerous assumption. But in the world of dark web exposure, silence is rarely a sign of safety; it’s a blind spot. Relying on external alerts to discover your vulnerabilities means you are reacting far too late. Here are five questions you should answer that turn that assumption into something you can measure. If you answer "no" or "not sure," treat it as a blind spot that a dark web scan will address.

CVE-2026-88771 and CVE-2026-88772: Two Critical Citrix NetScaler Flaws Under Active Exploitation

Citrix disclosed two critical vulnerabilities in NetScaler ADC and NetScaler Gateway that are already being exploited in the wild. CVE-2026-88771 allows unauthenticated attackers to run commands on an affected appliance, while CVE-2026-88772 can lead to remote code execution or denial of service when DTLS is turned on. Both received a CVSS v4.0 score of 9.5, and CISA added them to its Known Exploited Vulnerabilities catalog.

Introducing the Vanta Control Framework: One lens for every framework

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Remote Employee Productivity Tracking: The Non-Invasive Playbook for Hybrid Teams

Hybrid and remote work have forever changed the way organizations structure their approach to people, technology, and performance. In Gallup’s 2026 Workplace Indicators, 52% of U.S. employees who can work remotely are in a hybrid model, and 26% are fully remote. As distributed work is here to stay, organisations need a trusted way to understand how employees use business applications, access resources, and do their work, without turning the workplace into a surveillance operation.

Next-Gen Web Filtering for Remote & Hybrid Workforces: Category Enforcement, DoH Defense & SafeSearch

Today, laptops are rarely connected to the corporate network – more often they’re connected to wifi at home, mobile wifi on the road, and a coffee shop hotspot the IT team never set up. Office perimeter firewalls have nothing to analyze when the device leaves the building, and cloud DNS filtering doesn’t work unless the DNS traffic actually reaches the cloud. That’s why more IT teams are moving web filtering to the device itself.