Category Archives: Security & Privacy
Grafana Security Breach: Codebase Stolen and Extortion Attempt
A significant Grafana security breach occurred on May 17, 2026, when an attacker used a stolen GitHub token to exfiltrate the company’s entire codebase and demand a ransom. Continue reading
Microsoft Exchange Zero-Day (CVE-2026-42897) Exploited in the Wild
A critical Microsoft Exchange Zero-Day vulnerability, tracked as CVE-2026-42897, is currently seeing active exploitation against on-premises Outlook Web Access users. Continue reading
Passkey Portability: Android Adopts New FIDO Credential Exchange Standards
Android is finally addressing platform lock-in by enabling Passkey Portability through the FIDO CX standard, allowing users to securely migrate credentials between managers. Continue reading
2026 Thales Data Threat Report: Addressing AI Risks and Identity Gaps
The 2026 Thales Data Threat Report identifies artificial intelligence as a primary threat catalyst, revealing that 70% of security professionals now rank AI as their top concern. Continue reading
CalPhishing Campaign: Hijacking M365 via Outlook Calendar Invites
Security researchers have identified the CalPhishing campaign, a new threat using Outlook calendar invites and the EvilTokens kit to bypass MFA and hijack accounts. Continue reading
Password Statistics 2026: Passkey Adoption and AI Cracking Risks
The latest Password Statistics 2026 report reveals a major shift toward passkeys as legacy credentials face increased vulnerability from AI-driven brute-force attacks. Continue reading
NIST Authentication Standards 2026: New Rules for Passwords and MFA
Discover the updated NIST authentication standards for 2026, which mandate phishing-resistant MFA, 15-character minimum password lengths, and the elimination of mandatory rotation. Continue reading
Cisco SD-WAN Zero-Day CVE-2026-20182 Exploited by UAT-8616
Cisco has issued emergency patches for a critical Cisco SD-WAN zero-day vulnerability, CVE-2026-20182, which is being actively exploited by the threat actor UAT-8616 to bypass authentication. Continue reading