Security 101: Virtual Patching
What happens to an unpatched or vulnerable application or organization’s IT infrastructure? Here's how virtual patching helps enterprises address vulnerability and patch management woes.

What happens to an unpatched or vulnerable application or organization’s IT infrastructure? Here's how virtual patching helps enterprises address vulnerability and patch management woes.
Sovereign AI places responsibility for every layer of the security stack in the operator's hands, and this article examines the threats that accompany that shift alongside the practical controls that keep nationally owned AI systems trustworthy.
TrendAI™ Research's investigation of ICS protocols near U.S. data centers uncovered thousands of vulnerable devices controlling critical cooling, power, and environmental infrastructure. These systems—designed for operational efficiency, not security—were accessible from the public internet.
This final installment of our trilogy on Pwning Agentic AI covers defenses against the return-to-tool (RTT) attacks—read-only Postgres bypass, support-ticket ransomware, and KYC passport exfiltration—demonstrated in Part II. Here we take a look at what works and what doesn’t against this new class of attack.
An enterprise guide on network segmentation; how it works to secure large enterprise networks, why it's needed, and examples of some of the most widely used network models for different industries.
Business Email Compromise schemes are one of the biggest threats to companies to date. One carefully crafted email sent to the right person can cost a company millions of dollars. How is it done and what makes it so effective?
Developers of the Android-based banking trojan Marcher updated the malware, adding major banks in United Kingdom to its list of targets.
Austria-based Fischer Advanced Composite Components AG (FACC), a major designer and manufacturer of aircraft components and systems, falls prey to a business email compromise (BEC) scheme that cost the company over 42 million euros in losses.
Long time users of Linkedin users may very well need to change their passwords once more as a cybercriminal puts the email addresses and passwords of 117 million users up for sale.
Research on the common technologies used by cybercriminals and terrorists to benefit their cause, from the services they abuse to the tools they’ve homebrewed to streamline activities.
Top news sites, entertainment portals, and political commentary sites were affected by a massive malvertising campaign related to the Angler Exploit Kit.
The world is now more connected than ever. Gartner predicts 25 billion connected devices will be in use by 2020. How is this increased convenience affecting our privacy and security across the globe?
A new crypto-ransomware type called Locky has been discovered riding on document-based macros and using infection techniques borrowed from the notorious banking malware DRIDEX.
Operation Pawn Storm is an active economic and political cyber-espionage operation that has targeted high-profile entities from government institutions to media personalities. Here are its latest developments.