Exploit-buying firm IRIS C2 is run by two repeatedly convicted conspiracy theorists involved in disinformation campaigns and illegal robocall operations.
As passkeys gain mainstream adoption, credential stuffing loses effectiveness, forcing attackers to target weaker verification stages, which CISOs must now harden as a priority.
Git commit signatures do not protect against hash collisions, as the same signed content can produce multiple different commit hashes with valid signatures.
A misconfigured Elasticsearch instance at Nextcloud exposed internal company data, customer contracts, database credentials and employee contacts over an extended period, but was shut down without detected misuse.
AI agents fail to recognise trust boundaries between private and public resources, becoming an unintended bridge between sensitive internal systems and the public internet.
GitHub Agentic Workflows extract and disclose data from private repositories – a security issue for which no comprehensive solution has been announced.
The majority of organisations deceive themselves about the security of their collaboration infrastructure: while they rate it as protected, they actually share sensitive information over fragmented and unsuitable channels.
Under NIS2, fragmented IT infrastructure triggers personal executive liability, requiring companies to migrate to integrated platforms with automation, asset visibility, and continuous logging.