Ransomware gangs exploit a vulnerability in Microsoft Defender to gain access to the SAM database through insufficient access controls and obtain SYSTEM privileges.
69 percent of SaaS accounts in the Kaseya study have more uncontrolled guest access than licensed users, leading to significant security and compliance gaps.
A data breach at GameStop with 54 million potentially affected customer records exposes names, addresses, phone numbers, and purchase histories for targeted phishing and social engineering attacks.
As dwell time approaches zero, a paradigm shift from detection and prevention toward preemptive resilience with recovery as a design principle becomes necessary.
Poisoned descriptions in Model Context Protocol (MCP) tools enable attackers to abuse AI agents into sharing data while security control mechanisms remain silent.
Poisoned MCP tool descriptions can trick AI agents into exfiltrating business-critical data to external systems while each individual step appears legitimate.