Subtitle Icon
Latest Security Insights

Security Blog

Expert insights, threat intelligence, and best practices from our security team

Latest Articles

Blog Meta Icon
June 21, 2026
Blog Meta Icon
11 minute read

Amazon's One Medical Confirms a "Limited" Breach. ShinyHunters Claims 8.8 Terabytes and a Deadline. Only One of Those Is Verified.

On June 13, One Medical disclosed unauthorized access to a third-party file storage system holding archived records from its legacy Iora Health and One Medical Seniors patients, describing the scope as a limited subset of files at nine named clinics. Days earlier, on June 18, ShinyHunters posted One Medical to its dark-web leak site, claimed 8.8 terabytes of stolen data, and gave the company until June 22 to begin negotiating before publication. ShinyHunters has released no sample data, so the claim is unverified. This is the same actor, the same playbook, and the same trust gap Cloudskope documented in the Canvas/Instructure breach: a company describing the smallest defensible version of events while a threat actor describes the largest. For boards in healthcare and any regulated-data business, the lesson is not which number to believe. It is to treat both as unproven until the evidence settles it, and to plan for the larger one.

No items found.
Blog Meta Icon
June 19, 2026
Blog Meta Icon
15 minute read

Drift. Gainsight. Now Klue. And This Time, It Wasn't ShinyHunters.

For the third time in ten months, attackers drained Salesforce data through a trusted app. The first two were ShinyHunters. This one wasn’t — and that is why it matters.

Blog Meta Icon
June 6, 2026
Blog Meta Icon
11 minute read

Five Warnings in Sixty Days: The Keys to America's Infrastructure Are Not Being Held

Five infrastructure-security stories broke in sixty days, each reported alone. Read together, they say the keys to America's critical systems are not being held.

Blog Meta Icon
May 21, 2026
Blog Meta Icon
22 minute read

Instructure's Own Documents Don't Add Up

A document-by-document reconstruction of the Canvas/Instructure breach, where the company's own SOC 2 renewal, incident page, and containment claims do not reconcile with what it later admitted.

No items found.
Blog Meta Icon
May 5, 2026
Blog Meta Icon
10 minute read

Microsoft Edge Stored Every Password in Cleartext

Microsoft Edge has been storing saved passwords in cleartext on disk. Any process with disk access can read them. What it means for enterprise password hygiene.

Blog Meta Icon
May 5, 2026
Blog Meta Icon
11 minute read

Russia Harvested 18,000+ M365 Tokens Without Malware

Russia harvested 18,000+ Microsoft 365 OAuth tokens through compromised home routers — no malware, no detectable footprint. Inside the campaign.

Blog Meta Icon
May 5, 2026
Blog Meta Icon
10 minute read

April's 167 CVEs Were a Governance Failure

April Patch Tuesday shipped 167 CVEs with 14 critical exploitable bugs. The problem isn't patching capacity — it's the governance framework deciding priority.

Blog Meta Icon
May 1, 2026
Blog Meta Icon
6 minute read

ADT 2026 Breach: Customer Trust Was the Breach

The ADT 2026 breach didn't compromise the alarm systems. It compromised the customer data underneath — and the vishing campaign that followed showed the real risk.

Blog Meta Icon
April 27, 2026
Blog Meta Icon
6 min read

White House Correspondents' Dinner: Perimeter Failure

The White House Correspondents' Dinner breach: insider risk, badge cloning, and the slow failure of trust-by-credential perimeter models.

Blog Meta Icon
March 4, 2026
Blog Meta Icon
13 min read

AI Tools With Company Keys: The Vercel Breach

When AI tools get the keys to your company: the Vercel breach exposed the API credentials AI agents need to function — and how attackers chained that access.

Blog Meta Icon
June 7, 2026
Blog Meta Icon
6 minute read

Five Cyber Questions That Change What a Deal Is Worth.

Cyber due diligence is usually a checkbox near the end of the process. Five specific questions turn it into a deal-pricing input, surfacing the risks that actually move valuation and post-close cost.

Blog Meta Icon
June 7, 2026
Blog Meta Icon
6 minute read

Acquisition Agreements Get Signed on Cyber Reps Nobody Verified. That Becomes the GC's Problem.

Acquisition agreements get signed on cyber reps no one independently verified. When the deal closes, the gap between what was repped and what's true becomes the buyer's liability and the GC's problem. What deal counsel should require first.

Blog Meta Icon
June 7, 2026
Blog Meta Icon
7 minute read

The First 100 Days After Close Decide Your Cyber Risk for the Whole Hold.

Cyber due diligence is a screen, not a clean bill of health. The day a deal closes, every undetected weakness becomes the sponsor's problem, and the first 100 days are the only window with the leverage to fix it.

Blog Meta Icon
June 7, 2026
Blog Meta Icon
6 minute read

Your Cyber Budget Is a Number. Your Cyber Risk Is a Distribution. CFOs Keep Confusing the Two.

Global cyber spending hit a record $219 billion in 2025, the same year breaches set their own record. The disconnect exposes the core CFO error: treating cybersecurity as a budget number instead of a loss distribution to reshape.

Blog Meta Icon
June 7, 2026
Blog Meta Icon
9 minute read

Four Breaches in Six Weeks. One Extortion Group. Your Portfolio Is the Target List.

ShinyHunters spent early 2026 running one pay-or-leak campaign through Instructure, Adobe, Match Group, and DentaQuest. The target profile is a near-perfect description of the average PE portfolio company.

Blog Meta Icon
June 5, 2026
Blog Meta Icon
14 minute read

The West Is Not Losing a Cyberwar. It's Losing an Economic War Conducted Through Cyber Means.

GCHQ's director warns of a 'narrowing window' while Russia hits Europe daily and China sits inside US telecoms. This isn't a cyberwar; it's economic coercion through digital infrastructure.

Blog Meta Icon
May 12, 2026
Blog Meta Icon
12 minute read

Phishing Statistics 2026: 20 Numbers Every Executive Should Know

20 phishing statistics from Verizon DBIR, IBM, FBI IC3, APWG, Microsoft, and Proofpoint that should change how every executive thinks about email security investment in 2026.

Blog Meta Icon
June 6, 2026
Blog Meta Icon
12 minute read

What CISA's CI Fortify Guidance Actually Means, and Why It Reads Like a Confession

CISA's CI Fortify guidance tells critical infrastructure to plan for months running cut off from its own networks, on the assumption the adversary is already inside. Why that reads like a confession.

Blog Meta Icon
June 6, 2026
Blog Meta Icon
13 minute read

Still Inside: Why the Senate Says Salt Typhoon Was Never Fully Evicted

Salt Typhoon breached at least nine US carriers and the wiretap systems built for law enforcement. The Senate now says China's hackers were never fully evicted.

Blog Meta Icon
June 6, 2026
Blog Meta Icon
13 minute read

Seven Years Inside: What Volt Typhoon Is Actually Doing in the US Power Grid

China's Volt Typhoon has held access inside US critical infrastructure for roughly seven years, using no malware. The goal isn't espionage. It's pre-positioning for disruption.

Blog Meta Icon
June 6, 2026
Blog Meta Icon
14 minute read

Nine Days After CISA Told America to Lock Down, Its Own Keys Were Sitting on GitHub

Days after CISA told America to lock down, a CISA contractor's public GitHub repo exposed federal cloud keys and the agency's software build credentials for six months.

Blog Meta Icon
June 6, 2026
Blog Meta Icon
13 minute read

AT&T Holds the Keys to Federal Surveillance. A Whistleblower Says It Hid the Break-Ins.

A whistleblower suit alleges IBM and AT&T hid repeated Chinese intrusions into a federal cloud system and made false security assurances to keep their government contracts.

Blog Meta Icon
May 7, 2026
Blog Meta Icon
13 minute read

275M Users Exposed in Canvas/Instructure Breach

275 million users exposed. 8,809 schools down. Instructure calls it 'scheduled maintenance.' Inside the Canvas breach and the EdTech disclosure failure.

Blog Meta Icon
May 9, 2026
Blog Meta Icon
11 minute read

Seven Years. Five Wells Fargo Outages. Still 'Routine.'

Seven years. Five major outages. Wells Fargo still calls it routine maintenance. What the banking outage pattern reveals about regulated comms.

Blog Meta Icon
May 11, 2026
Blog Meta Icon
9 minute read

Audited. Compliant. Hacked Anyway.

$219 billion spent on cybersecurity in 2025. More major breaches than any year on record. Why every cybersecurity plan failed in 2026.

Blog Meta Icon
May 10, 2026
Blog Meta Icon
10 minute read

Most Common Passwords in 2026: What the Data Shows

The 2026 password data: 123456 is still #1, 65% of users reuse passwords across breaches. What boards and CISOs should be doing about it.

Blog Meta Icon
May 5, 2026
Blog Meta Icon
10 minute read

Scattered Spider Plea: The Playbook Is Now Commoditized

Scattered Spider operative 'TylerB' pleaded guilty. The real threat isn't the arrest — it's that the social engineering playbook is now commoditized.

Blog Meta Icon
May 5, 2026
Blog Meta Icon
12 minute read

Shadow AI Agents Are Your New Attack Surface

Employees are running unauthorized AI agents with admin access to email, files, calendars, and CRM. The shadow AI attack surface most enterprises don't measure.

Blog Meta Icon
April 27, 2026
Blog Meta Icon
9 minute read

Copilot Doesn't Create the Data Problem. It Reveals It.

Microsoft 365 Copilot does not create a permission problem. It reveals the one you already had. Inside the SharePoint sprawl Copilot exposes.

Blog Meta Icon
May 10, 2026
Blog Meta Icon
18 minute read

Cybersecurity Acronyms Glossary 2026

70+ cybersecurity acronyms decoded for executives, boards, and PE sponsors. MFA, EDR, MDR, ZTNA, NIST CSF, SOC 2, and the rest — organized across 11 categories.

Blog Meta Icon
May 10, 2026
Blog Meta Icon
25 minute read

30 Biggest Data Breaches of All Time

Ranked by records: Yahoo, NPD, LinkedIn, Marriott, Canvas, T-Mobile, Equifax, Target, Capital One, Change Healthcare — and the regulatory fallout each produced.

Blog Meta Icon
May 5, 2026
Blog Meta Icon
10 minute read

Every MFA Tool Is Being Bypassed. Here's How.

Every MFA tool in your stack is being bypassed right now. Adversary-in-the-middle phishing, SIM swap, MFA fatigue, push bombing — and what actually stops them.

Blog Meta Icon
May 5, 2026
Blog Meta Icon
11 minute read

Defender vs CrowdStrike vs SentinelOne: 2026 Test

We tested Microsoft Defender, CrowdStrike Falcon, and SentinelOne against identical threats. The results were not what most CISOs expect.

Blog Meta Icon
April 30, 2026
Blog Meta Icon
3 minute read

UniFi Dream Machine Beast: Enterprise Push

Ubiquiti's Dream Machine Beast pushes UniFi into enterprise gateway territory. Technical specs, threat-model implications, and mid-market network fit.

Blog Meta Icon
March 4, 2026
Blog Meta Icon
5 min read

The Uncomfortable Truth About AI Threat Detection

AI threat detection vendors promise what their products can't deliver. Pattern matching is not detection — and most stacks are catching less than claimed.

Blog Meta Icon
March 4, 2026
Blog Meta Icon
13 min read

Frost Bank and the New Vendor-Risk Reality

The Frost Bank vendor breach: what happens when a payment processor's third-party software fails. The vendor-risk reality boards and audit committees own.

Blog Meta Icon
March 4, 2026
Blog Meta Icon
13 min read

Flat Networks Turn Incidents Into Enterprise Events

Flat networks turn small incidents into enterprise events. The segmentation framework that limits blast radius — and why mid-market still hasn't done it.

Blog Meta Icon
March 4, 2026
Blog Meta Icon
13 min read

Ransomware Trends: Q2 2026 Analysis

Q2 2026 ransomware analysis: the operator economics, targeted sectors, cryptocurrency flow, and regulatory responses now reshaping breach disclosure practice.

Blog Meta Icon
March 4, 2026
Blog Meta Icon
13 min read

Network Gear Is the Attack Surface Nobody Audits

Your network gear is becoming the attack surface nobody audits enough. Firewalls, switches, load balancers, and the CVE backlog hiding in your perimeter.

Blog Meta Icon
March 4, 2026
Blog Meta Icon
13 min read

Patch Tuesday Is a Governance Test

Patch Tuesday is not an IT task — it is a governance test. The 30-day patching SLA, board reporting, and named-officer accountability framework boards now own.

Blog Meta Icon
March 4, 2026
Blog Meta Icon
13 min read

What Is SOC 2 Compliance? An Executive Guide

SOC 2 for executives: what auditors test, what consultants charge, what boards need to know — and why Type II is what enterprise buyers require.

Blog Meta Icon
March 4, 2026
Blog Meta Icon
7 min read

When the Security Tool Becomes the Attack Surface

When the security tool becomes the attack surface: the Microsoft Defender exploit chain, the SentinelOne kernel CVE, and the pattern now common across EDR.