Security 101: Virtual Patching
What happens to an unpatched or vulnerable application or organization’s IT infrastructure? Here's how virtual patching helps enterprises address vulnerability and patch management woes.

What happens to an unpatched or vulnerable application or organization’s IT infrastructure? Here's how virtual patching helps enterprises address vulnerability and patch management woes.
Sovereign AI places responsibility for every layer of the security stack in the operator's hands, and this article examines the threats that accompany that shift alongside the practical controls that keep nationally owned AI systems trustworthy.
TrendAI™ Research's investigation of ICS protocols near U.S. data centers uncovered thousands of vulnerable devices controlling critical cooling, power, and environmental infrastructure. These systems—designed for operational efficiency, not security—were accessible from the public internet.
This final installment of our trilogy on Pwning Agentic AI covers defenses against the return-to-tool (RTT) attacks—read-only Postgres bypass, support-ticket ransomware, and KYC passport exfiltration—demonstrated in Part II. Here we take a look at what works and what doesn’t against this new class of attack.
The DRBControl campaign attacks its targets using a variety of malware and techniques that coincide with those used in other known cyberespionage campaigns.
Over 30K records of US inmates were inadvertently exposed through a leaky AWS S3 cloud storage bucket.
Researchers discovered a vulnerability in smart light bulbs that can allow hackers to install malware and infect other IoT devices.
Cybercriminals were found selling over 30 million credit card details from around 40K U.S. states and 100 countries.
An unsecured Amazon S3 bucket was found leaking the data of more than 30,000 individuals. It was discovered to have exposed 85,000 files that included records with sensitive personally identifiable information (PII).
Over 2,000 WordPress sites were compromised by a malicious script that redirects visitors to scam sites, gains admin access, and installs fake plugins.
A recent BEC campaign targets organizations by sending them emails with IMG (disk imaging) file attachments hiding a NetWire remote access trojan.
A new sextortion scheme threatens to expose nude videos supposedly captured via victims' mobile phones and home cameras.
To determine threat actors' degree of knowledge in compromising a smart factory, we deployed our most elaborate honeypot to date. The incidents we observed show the kinds of attacks that can easily affect poorly secured manufacturing environments.
The cryptocurrency-miner, a multi-component threat comprised of different Perl and Bash scripts, miner binaries, the application hider Xhide, and a scanner tool, propagates by scanning vulnerable machines and brute-forcing (primarily default) credentials.