Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cl0p-Linked Activity Targets PTC Windchill and FlexPLM in Data Theft Campaign

Foresiet reviewed a batch of 42 masked victim listings associated with the Cl0p extortion operation. The listings describe alleged exposure of project repositories, databases, CAD files, engineering drawings, backups, software and Windchill-related files. Those references recur with unusual consistency across the batch. The pattern resembles the type of information commonly managed within product lifecycle management (PLM) environments more than the contents of a general file share.

Understanding unfixed Kubernetes CVEs: What you can and can't detect

On June 1, 2026, the Kubernetes Security Response Committee updated the records for four older CVEs that remain unfixed. The corrections may cause vulnerability scanners to report these CVEs in clusters where they weren’t previously detected. But an affected version doesn’t necessarily mean that a cluster is exposed. Each unfixed Kubernetes CVE depends on a particular combination of permissions, cluster features, and network access.

Serving the most critical missions: Cloudflare for Government achieves FedRAMP Class D (High) Certified status

We believe the Internet must be a force for good, and that it requires a foundation of trust. Nowhere is that trust more critical than in public service. Government agencies are the stewards of a nation’s most sensitive data. They protect national security, critical infrastructure, and the personal information of every citizen. Cloudflare’s mission is to help build a better Internet.

Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS

Autonomous AI attacks have definitively moved from the research demos everyone's been awed by to standard operating procedure. For anyone paying enough attention, this is not necessarily news: the Five Eyes Alliance warned everyone back in June that AI will bypass cybersecurity in months, not years, with adversary breakout times that can now be measured in seconds. Gartner itself predicted something similar, expecting the window to exploitation to be cut in half as early as next year.

What Mythos Means for Your Vulnerability Management Team

Modern exposure management has evolved beyond vulnerability scanning and alert volume into a discipline focused on measurable risk reduction. As the exposure management market matures, security leaders are adopting cyber exposure management platforms that unify signals across vulnerability, cloud, application, and attack surface tools to prioritize what truly matters.

You've Been Running a Kubernetes Security Model in NSX and Didn't Even Know It

One of the blockers to moving VMs off vSphere and onto Kubernetes is losing NSX and the protection it provides. Security teams that have spent years building out distributed firewall policy look at Kubernetes and are, quite understandably, alarmed by the flat network and the fact that any workload can reach any other by default. How will they enforce east-west traffic controls? Will they be able to replicate NSX distributed firewall rules with the same granularity?

How Two Small Bugs Led to a Critical Vulnerability and a Cryptography Audit of Go's SSH Library

Last summer we found a critical vulnerability in Teleport, our first in a decade. It was assigned CVE-2025-49825. This vulnerability allowed Teleport SSH certificates, issued to users of a cluster, to sign other SSH certificates which would then be incorrectly accepted by Teleport as valid. Once you can sign your own certificates, you can escalate privileges and bypass authentication controls. This is why we classified it as a critical vulnerability.