Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

After Mythos: What Cyber Insurers Should Actually Be Asking

One issue we keep hearing from insurance underwriters and portfolio managers is some version of the same question: how do you price a risk that can change between bind and the very next day? The steady stream of headlines about Claude Mythos is the latest reason why this question comes up, but it isn’t really all about Mythos. Frontier AI is collapsing the gap between vulnerability disclosure and weaponized exploit, and the numbers are no longer subtle.

How State Governments Can Navigate the Resource Crunch and Achieve Resiliency

The 2026 NASCIO-Deloitte Cybersecurity Study reveals a stark reality for CISOs in state governments: while cyber threats are growing in both sophistication and volume, the resources available to combat them are failing to keep pace. As foreign adversaries and cybercriminals weaponize AI to probe for vulnerabilities, state CISOs find themselves at a critical juncture, navigating expanding responsibilities amidst tightening budgets.

Defending the Indefensible: The Power Grid's Security Paradox

Electricity supports nearly every function of modern life: hospitals, water systems, transportation, communications, emergency services, financial systems, manufacturing, national defense, and, most importantly, streaming services. Kidding, but our most critical systems run on electricity, and that makes us vulnerable to attacks.

Amadey and StealC: Malware-as-a-Service Unavailable

On June 24, 2026, demonstrating the power of public-private collaboration, Europol and the Microsoft Digital Crimes Unit, alongside our team and other global partners, executed a coordinated disruption as part of Operation Endgame, impacting two of the most prolific commodity malware families on Windows: the Amadey loader/botnet and the StealC information stealer.

The Underground Shift: Why Declining Breach Numbers Don't Tell the Whole Story

In Bitsight’s annual State of the Underground report we discuss cyber threat trends, key players, attack vectors, and why it all matters. The key theme from the 2026 State of the Underground is that cyber risk is changing as we know it. We are starting to see threat actors pivot alongside the changing threat landscape. We also explored how the threat landscape is reacting to the ever-growing changes brought on by AI.

Threat Intelligence for prioritization

More data does not always mean better decisions. For TPRM teams, the value comes from actionable, correlated intelligence that helps identify which risks need attention first. In this clip from Three Hard Truths About TPRM, Julie Gaiaschi of TPRA and Vanessa Jankowski of Bitsight discuss how threat context can help organizations prioritize third-party risk, strengthen supply chain resilience, and support business continuity under pressure.

Real Time Risk Needs Real Time Visibility

Third-party risk doesn’t wait for annual reviews. Vendor ecosystems change constantly, and risk teams need visibility that keeps pace. In this clip from Three Hard Truths About TPRM, Julie Gaiaschi, CEO and Co-Founder of TPRA, and Vanessa Jankowski, SVP and GM of Bitsight’s TPRM solution, explore why continuous monitoring and real-time visibility are critical for stronger accountability, faster response, and better resilience across the vendor ecosystem.

Business Context Is the New Risk Filter

Not every vendor risk deserves the same level of attention. The real challenge is knowing which risks matter most to the business. In this clip from Three Hard Truths About TPRM, Julie Gaiaschi of TPRA and Vanessa Jankowski of Bitsight discuss why business context is becoming the new filter for prioritizing third-party risk — helping teams focus on continuity, revenue protection, and the vendors that truly impact operations.

Stop managing vendor lists Start mapping dependencies. #cybersecurity #mythos

Third-party risk management can’t stop at static vendor lists. In today’s interconnected business environment, organizations need to understand the dependencies behind their vendors — including subcontractors, fourth parties, and concentration risks that can affect operational resilience. In this clip from Three Hard Truths About TPRM, Julie Gaiaschi, CEO and Co-Founder of TPRA, and Vanessa Jankowski, SVP and GM of Bitsight’s TPRM solution, discuss why stronger Nth-party visibility is essential for modern third-party risk programs.

Major Security Event: Fortinet VPN Credentials and Configuration Data Exposed for 73,000 Devices

A large-scale credential compromise campaign known as FortiBleed has exposed verified administrator credentials for more than 73,000 internet-facing Fortinet FortiGate firewalls. As of mid-June 2026, the dataset is reportedly circulating within criminal underground communities. Researchers estimate that approximately 50% of all internet-reachable FortiGate devices may be affected across 194 countries, making this one of the most significant Fortinet security incidents to date.