Blog
-
Microsoft Makes the First Move Toward a Passwordless Future
A desire to replace the password as the world’s default authentication method has been circulating in the tech world for some time, but there have been almost no moves to force the issue to date. That has changed with Microsoft’s new passwordless policy for new accounts, though it is still far from the “death of…
-
AI Emerges as Panacea for Third-Party Security Issues, but Chase CISO Warns It Won’t Save SaaS Models
Organizations also increasingly can’t avoid SaaS models, and sometimes are even stuck with those that do not have a satisfactory security track record. That substantially increases the broader risk of some sort of major catastrophe that could harm an entire national economy stemming from just one third-party security breach.
-
New Prompt Injection Attack Compromises All AI Models
All of the big LLMs are vulnerable to a new type of prompt injection attack that targets their safety policies, according to security firm HiddenLayer. The attack essentially fully jailbreaks the AI models, exposing the system prompt as well as enabling all different types of dangerous requests.
-
75 Zero-Days Exploited in the Wild in 2024, Spyware Remains Common
When it comes to zero-days and spyware, China and North Korea’s hacking teams head up the leaderboard with five 2024 incidents each. Russia had three, and South Korea one; another three were likely the work of APT groups but a specific nation was not pinned down.
-
California Health Insurance Provider Blue Shield’s Misconfiguration Exposed Most of Its Customer Health Data to Google Ad Network for 3 Years
The size of the health insurance breach, 4.7 million of about 6 million Blue Shield California customers, is not the only point of concern. The breach window was reportedly open from April 2021 to January 2024, nearly three continuous years. And the loss of health data was also only detected in February of this year.
-
Verizon’s 2025 DBIR Finds Major Spikes in Third-Party Cyber Attacks, Exploitation of Edge Devices
Of all the cyber attacks examined in the 2025 DBIR, 22% kicked off with credential abuse. Vulnerability exploitation has been making a strong push to take the lead over the last two years, however, with its most recent surge putting it at 20% (and ahead of phishing at 16%).
-
Senators Rally to Save Cybersecurity Law, Information Sharing Programs Set to Expire in September
The 2015 Cybersecurity Information Sharing Act is set to expire this September. The programs the cybersecurity law authorizes not only facilitate information sharing, but also offer legal protections to private partners that might otherwise be hesitant to engage with the government for fear of repercussions.
-
Inside Source Says Chinese Government Has Privately Admitted to Ordering Volt Typhoon Cyber Attacks
China made the seeming admission at a secret meeting taking place in Geneva in December. The WSJ source said that the admission of Volt Typhoon cyber attacks was not entirely direct, rather “somewhat ambiguous” in nature but still enough to “startle” US officials.
-
MITRE CVE Program Safe Until Early 2026, But What Happens Then?
After an abrupt notice of the end of funding for the Common Vulnerabilities and Exposures (CVE) program caused a small panic in the cybersecurity world, it appears that a contract extension option exercised by CISA will keep it safe at least until March 2026.
-
Years-Long Security Breach at National Bank Regulator Leads to 150,000 Stolen Emails
During the roughly year-and-a-half that the security breach was active, about 100 email accounts were monitored by the attacker and it is estimated that they viewed about 150,000 messages in total.










