Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Oops, OpenAI Hacked Australia's Health System

30,000+ devices compromised. 7,000+ crypto wallets targeted. Roughly $10M stolen. And that’s only one story. This week on The 443: Security Simplified, Marc Laliberte and Corey Nachreiner unpack a new wave of security incidents where identity, access, and AI collide. They cover: WaterPlum activity spanning 100+ countries More than 7,000 cryptocurrency wallets impacted, worth roughly $10M ShinyHunters’ claimed theft of 3 TB of FBI-related data An AI agent reportedly accessing Australian government health data beyond its intended permissions.

Stop digging, just ask: get renewal-ready AI and SaaS reports in seconds

The information you need before a renewal meeting usually exists in SaaS Manager. Getting to it is another matter, because you have to know which report holds it, how to filter it, and whether the results actually answer the question you were asked. For an IT admin who works in the product daily, that's a minor detour. For a colleague in finance who opens SaaS Manager a few times a quarter, it can be the reason the question goes back to IT instead.

A Strategic Framework for Third-Party App Risk Management

Third-party code now accounts for 66% of the most dangerous, long-lived vulnerabilities across application portfolios, according to Veracode’s 2026 State of Software Security Report. For AppSec and engineering leaders, that stat tells a familiar story: shrinking release cycles, expanding open-source dependency footprints, and mounting regulatory pressure.

AI Agent Security: The Hidden Threat Your Firewall Can't Stop

If your AI security strategy is focused on stopping copy-pastes into chatbots, you're fighting yesterday's war. AI agent security is now the real endpoint challenge — autonomous agents operating with your users' credentials. Traditional firewalls, CASBs, and DLP weren't built for agentic AI. They can't see delegated credentials, multi-step tool calls, or live runtime execution across IDEs, browsers, and local apps.

Copy, Paste, Compromised: How ClickFix Attacks Work and How CrowdStrike Stops Them

Consider this hypothetical scenario: An employee tries to join what looks like a routine video meeting. The page loads, but instead of the meeting, they see an error message along with a helpful fix: Copy the provided command, open the Windows Run dialog, paste it, and press Enter. The meeting never starts. The command does something else entirely. This is ClickFix, a social engineering technique that turns the victim into the mechanism for executing an attack.

What Is VMware vSphere Proactive HA? | Proactive Host Monitoring Explained

What Is VMware vSphere Proactive HA? What if you could identify potential VMware host hardware issues before they lead to a failure? vSphere Proactive HA helps improve availability by monitoring the health of ESXi hosts and taking action when potential hardware problems are detected. In this video, learn: What VMware vSphere Proactive HA is How Proactive HA monitors host health How it helps prevent workloads from running on unhealthy hosts How Proactive HA works with VMware DRS The difference between proactive host management and traditional High Availability.

Critical Citrix NetScaler ADC and Citrix NetScaler Gateway Vulnerabilities

On September 27th 2026, Citrix disclosed multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. Arctic Wolf tracking indicates that CVE-2026-88771 and CVE-2026-88772 have been exploited in attacks against NetScaler devices as zero-days. Additional CVEs are also disclosed in the Citrix Security Bulletin. CVE-2026-88771 is an unauthenticated remote code execution vulnerability caused by improper input validation that can allow arbitrary command execution.

Gen's Curtis Koenig on treating AI agents like human users to prevent security failures

Your backlog of low and medium severity vulnerabilities just became a real threat. AI can now chain them into critical exploits, and the window between exploit discovery and active use is around eight hours. Curtis Koenig, Head of Application Security at Gen, joins the show to explain why treating AI agents like human users is the single most important step security teams can take this year. CHAPTERS.