ARCHIVE
Tag: supply-chain
-
Threat digest: 2026-09-16
CISA confirmed ransomware gangs have joined the exploitation of a critical VMware vCenter bug, a compromised WordPress plugin update backdoored about 1,500 sites through the vendor's own download…
-
Threat digest: 2026-09-15
CISA added an exploited remote code execution flaw in Cisco Secure Email Gateway to its KEV catalog with a three day federal deadline, Sandworm was tied to an…
-

Malicious LLM providers and APIs: the third-party risk that is not on your architecture diagram
Your architecture diagram shows your cloud, your identity provider and your SIEM. It almost certainly does not show the six or seven places where prompts, documents and API…
-
Threat digest: 2026-09-14
A mass exploitation campaign against SonicWall SMA1000 appliances exposed a UK council to Active Directory credential theft, Cl0p claimed a 270GB data haul from Harley-Davidson, and a Twitch…
-
Threat digest: 2026-09-13
Dutch authorities warned that exploitation of two critical Check Point VPN flaws is imminent, researchers tied an exploit kit that chains two Chrome V8 zero-days and a Windows…
-
Threat digest: 2026-09-12
CISA added four actively exploited flaws to its KEV catalog in a single day, including a CVSS 10.0 GitLab path traversal bug probed within hours of disclosure, while…
-

Adopting AI without losing control: the evidence on risk, and the controls that hold
Most companies are no longer deciding whether to adopt AI. They are deciding whether adoption happens inside a control framework or around one. The risk is not speculative:…
-

Why Kubernetes security is hard, and what to do about it: a deep dive beyond the interviews
Kubernetes is the operating system of modern cloud infrastructure, and it is genuinely harder to defend than the environments most security teams grew up on. Expel’s March 2026…