Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Risk Acceptance Has a Shelf Life: Notes from the Aviation ISAC Cybersecurity Summit

The first Aviation ISAC summit, a little over a decade ago, was about forty people in a room in Miami, hosted by the Health ISAC. This year’s conference in Vancouver hosted more than five hundred: airlines, airports, OEMs, suppliers, and government, all in one place for three days. Many in the audience were new to the conference. One of the opening speakers asked first-timers to raise their hands, and a lot of hands went up around the room.

Critical Bookly IDOR Leads to Booking Disclosure and Deletion (CVE-2026-93399)

During independent security research conducted as part of the Wordfence Bug Bounty Program, we identified an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in Bookly, a WordPress appointment booking plugin used to manage online scheduling, services, staff availability and customer appointments.

CrowdStrike and Anthropic Give Critical Infrastructure Defenders the AI Advantage

Critical infrastructure is where cyber risk becomes real-world risk. The environments powering energy, water, manufacturing, and transportation are among the most complex to defend as they often combine decades-old operational technology (OT) with modern IT. Downtime is not an option, and patching isn’t always possible. Now, AI is raising the stakes. Adversaries are using AI to move faster and operate at greater scale, compressing the time defenders have to respond to attacks.

ASOS Cyber Incident: CYJAX on the Third-Party Risk Facing UK Retailers.

On 6 October 2026, ASOS customers received an extortion message through the retailer's own app claiming its Snowflake instance had been compromised. CYJAX looks at what happened, why third-party and cloud platform risk sits at the centre of the incident, and how organisations can monitor their extended supply chain before attackers do. By now, most people in the UK will have heard about the cyber incident that hit ASOS on 6 October 2026.

Two Systems, One Truth: Unifying Training Records Across SAT and LMS

Somewhere in your security and compliance stack, there are records that prove your employees completed their security awareness training. But when these records need to serve as evidence, would they actually hold up to scrutiny? For many companies, the answer is no, and that’s becoming a major risk. Following steadily rising claims over the years, insurers have narrowed their coverage definitions and requiring stricter adherence to security standards.

MSP Icons Share Their Perspectives on the Future of the Channel | WatchGuard IMPACT 2026

Hear directly from some of the industry's most influential MSP leaders as they share their perspectives on the future of managed services and the evolving cybersecurity landscape. From AI and security services to profitability, customer expectations, and business growth, discover how leading MSPs are adapting to change, navigating new challenges, and preparing for what's next.

Bell Integration Steps Up for The Cyber Helpline to Support Victims of Cybercrime

The Cyber Helpline is pleased to welcome Bell Integration as a new partner, supporting our work to help people affected by cybercrime, digital fraud and online harm. The partnership launched during Cybersecurity Awareness Month, with Bell employees supporting The Cyber Helpline through volunteering and fundraising throughout the year.

Cybersecurity Awareness Month 2026: Securing the Next 250 Years

This year, the United States of America celebrated their 250th birthday, but Cybersecurity Awareness Month is already looking toward the future with the goal of securing the next 250 years together. It’s an ambitious theme that leads us all to wonder, “what does it actually take to build security that lasts?” The Cybersecurity & Infrastructure Security Agency (CISA) 2026 Cybersecurity Awareness Month guidance begins with four familiar practices.

FIPS 140 2 End of Life: Impact on HSMs and Cryptographic Modules

The shift from the FIPS 140-2 standard is significant for organizations making use of HSMs, software-based cryptographic modules, VPN equipment, secure communications, and other items depending on validated crypto. That being said, it does not mean that the existing FIPS 140-2 modules will start malfunctioning or will become insecure. The transition has implications for how businesses will be appraising validated crypto devices, especially when purchasing or employing them in the new systems.