Security 101: Virtual Patching
What happens to an unpatched or vulnerable application or organization’s IT infrastructure? Here's how virtual patching helps enterprises address vulnerability and patch management woes.

What happens to an unpatched or vulnerable application or organization’s IT infrastructure? Here's how virtual patching helps enterprises address vulnerability and patch management woes.
Sovereign AI places responsibility for every layer of the security stack in the operator's hands, and this article examines the threats that accompany that shift alongside the practical controls that keep nationally owned AI systems trustworthy.
TrendAI™ Research's investigation of ICS protocols near U.S. data centers uncovered thousands of vulnerable devices controlling critical cooling, power, and environmental infrastructure. These systems—designed for operational efficiency, not security—were accessible from the public internet.
This final installment of our trilogy on Pwning Agentic AI covers defenses against the return-to-tool (RTT) attacks—read-only Postgres bypass, support-ticket ransomware, and KYC passport exfiltration—demonstrated in Part II. Here we take a look at what works and what doesn’t against this new class of attack.
A lot of best practices teach users how to prevent or defend against phishing attacks, but how can organizations actively detect and thwart them before users even see them?
Vulnerable enterprise servers are being compromised by individuals or groups looking for resources to mine cryptocurrency. The latest victims are automobile-maker Tesla and users of Jenkins servers.
In a security alert posted on its website on January 31, The South Korean Computer Emergency Response Team (KR-CERT) warned of a zero-day vulnerability in Adobe Flash player that could be maliciously exploited.
Activists have traditionally used physical signs and catchy slogans to promote their political agenda, but the internet offers a significantly broader audience, so these activities have since moved online.
We looked at BEC-related incidents over a span of nine months to see emerging and present trends from BEC incidents, examine the tools and techniques used by cybercriminals, and analyze the data to give us an overall picture of what BEC looks like today.
Microsoft, Linux, Google, and Apple started rolling out patches addressing design flaws in processor chips that security researchers named Meltdown and Spectre. What are they, and how can they affect users?
A year that saw major data breaches, including some notable ones from companies like Uber and Equifax, just saw another breach that will likely rank as among 2017’s most notable incidents.
Several threat actors are actively exploiting CVE-2017-11882 to deliver a plethora of threats, including the information-stealing Loki, Pony/FAREIT, and a lockscreen with a ransom note that resembles Bad Rabbit's.
Western European, UK, French, German, and US cities exposed. Are your connected devices searchable on the internet? Find out what you are risking.
In a highly publicized data breach incident, rideshare application Uber announced that the personal information of 57 million customers and drivers were potentially compromised in October 2016.