Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Inside the ECB's AI Cyber Directive: What EU Banks Need to Know

A bank isn’t just a vault holding money. It is an engine powered by implicit public trust, sustained by the continuous confidence that funds remain secure and accessible on demand. When operational risks fail, whether through cyber breaches, system outages, or third-party vulnerabilities, that trust shatters, threatening not just an individual institution, but the stability of the entire financial network. This is why regulatory oversight goes beyond standard compliance.

Is Yahoo Email Secure?

Yahoo email may not be the most popular email option in 2026, but it is still an active service with millions of users. If it is on your list of potential email providers, this article will cover: If you’re looking for an end-to-end encrypted email specifically, you can try Internxt Mail, now with an 85% discount on all Ultimate monthly and annual plans, which includes 5TB of encrypted storage and access to all of Internxt's features. Get 85% off all Internxt plans.

Redefining Client Expectations in Cybersecurity: From IT Support to Strategic Partner

Organizations are increasingly turning to third-party providers to navigate a cybersecurity landscape marked by expanding attack surfaces, fragmented technologies, and growing operational complexity. MSPs deliver specialized capabilities, round-the-clock protection, and multi-environment expertise, helping internal teams mitigate risks that are difficult to manage on their own.

EDR and MDR for SMBs: enterprise-grade protection without an enterprise SOC

EDR (endpoint detection and response) is no longer an enterprise-only technology. SMBs face many of the same attacker techniques as larger organizations, but generally have fewer security and recovery resources available to contain the impact. Modern EDR platforms, especially when delivered through MDR (managed detection and response) and extended where needed with XDR (extended detection and response), make enterprise-grade protection operationally feasible for MSPs to deliver to SMB clients.

Certificate Transparency Monitoring is now generally available

Since we launched Certificate Transparency Monitoring in public beta in 2019, we've been emailing subscribers whenever a new TLS certificate appears in a public Certificate Transparency (CT) log for one of their domains. Today, it's turned on for more than 650,000 customer domains. It's an early warning that someone, somewhere, has issued a certificate for a hostname in your zone, giving you a chance to spot a mis-issued certificate early.

We built an AI PR reviewer. The hard part was teaching it to say nothing.

Most AI code review tools fail the same way. They work, in the sense that comments appear on the pull request. Then you read the comments and they are 80% “consider extracting this into a helper”, “missing test coverage”, “this variable name could be clearer”, and within a couple of weeks everyone has learned to scroll past anything the bot wrote. These are not false positives. They are true and irrelevant, which costs the same attention and is harder to argue with.

Emerging Threat: (CVE-2026-26035) FortiWeb Admin Authentication Bypass via RADIUS Admin Groups

CVE-2026-26035 is an improper authentication vulnerability (CWE-287) in Fortinet FortiWeb, disclosed by Fortinet on August 12, 2026 in advisory FG-IR-26-158 under the title “Broken access control in the RADIUS type admin group.” The flaw sits in FortiWeb’s remote RADIUS administrator authentication path, where the appliance fails to correctly validate an administrative login before granting access.

Emerging Threat: (CVE-2026-71362) Adobe Commerce Account Takeover via Session Identity Flaw

CVE-2026-71362 is an incorrect authorization vulnerability (CWE-863) in Adobe Commerce and Magento Open Source, caused by the platform failing to correctly bind a customer identity to an account session. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical). Exploitation requires no authentication. Adobe’s advisory states that the flaw is exploitable without credentials, does not require administrator privileges, and does not require user interaction.

Google Cloud KMS Adds Generally Available Quantum-Safe Digital Signatures

As quantum computing develops, cybersecurity professionals are getting ready for a breakthrough in the protection of digital information. The conventional public-key cryptographic algorithms that ensure the security of digital signatures may, in the long run, be compromised by the revolutionary power of quantum computers. To minimize that risk, Google Cloud has announced general availability of the quantum-safe digital signature feature in its Google Cloud Key Management Service (Cloud KMS).