Security 101: Virtual Patching
What happens to an unpatched or vulnerable application or organization’s IT infrastructure? Here's how virtual patching helps enterprises address vulnerability and patch management woes.

What happens to an unpatched or vulnerable application or organization’s IT infrastructure? Here's how virtual patching helps enterprises address vulnerability and patch management woes.
Sovereign AI places responsibility for every layer of the security stack in the operator's hands, and this article examines the threats that accompany that shift alongside the practical controls that keep nationally owned AI systems trustworthy.
TrendAI™ Research's investigation of ICS protocols near U.S. data centers uncovered thousands of vulnerable devices controlling critical cooling, power, and environmental infrastructure. These systems—designed for operational efficiency, not security—were accessible from the public internet.
This final installment of our trilogy on Pwning Agentic AI covers defenses against the return-to-tool (RTT) attacks—read-only Postgres bypass, support-ticket ransomware, and KYC passport exfiltration—demonstrated in Part II. Here we take a look at what works and what doesn’t against this new class of attack.
Our two-year research provides insights into the life cycle of exploits, the types of exploit buyers and sellers, and the business models that are reshaping the underground exploit market.
Ransomware-stricken organizations grapple with multilevel extortion schemes that are advancing at an alarming rate. What exactly happens in these campaigns? We scrutinize three active ransomware families associated with these schemes to find out.
Modern ransomware like Nefilim present new challenges and security concerns for enterprises across the world. How do these new families differ from traditional ransomware? And what can organizations do to mitigate risks?
These tools were intended for use in security research and other authorized purposes. However, cybercriminals have found a way to exploit them for ransomware campaigns. What are some of these tools and how exactly are they weaponized?
We discuss the challenges that organizations face in managing endpoint and server patches.
This article zeroes in on certain security considerations that developers need to know and the ways that they can build the best defense for container-based and serverless applications through runtime application self-protection (also known as RASP).
The use of connected cars continues to grow. While the vehicles’ link to technologies such as 5G and the cloud present opportunities for improving efficiency and safety, it can also attract risks from threat actors as well.
Ransomware continues the trend of targeted attacks but with the added challenge of double extortion. Organizations need to be one step ahead of such coercive tactics to avoid potential disruptions, financial losses, and reputational damage.
This article aims to discuss the Linux threat landscape and examine how Linux has become an attractive target for attackers, as well as how it can be prone to a variety of threats and risks.
We discuss the present state of the malicious uses and abuses of AI and ML and the plausible future scenarios in which cybercriminals might abuse these technologies for ill gain.