All Articles
-
CVE-2026-21962: The Oracle WebLogic Flaw That Was Exploited for Seven Months Before Anyone Noticed
CISA added a maximum-severity Oracle WebLogic and HTTP Server flaw to its Known Exploited Vulnerabilities catalogue on August 24, with a three-day federal remediation deadline -- but Oracle patched the bug back in January, and a China-linked threat actor has reportedly been exploiting it against government infrastructure since then. For CISOs, the real story is not the CVE. It is why a patched, unauthenticated, CVSS 10 vulnerability sat unremediated for seven months.
incident-report -
The Annual Cyber Insurance Renewal Is Dying: What Continuous Underwriting Means for CISOs
Carriers are moving away from once-a-year, point-in-time underwriting toward continuous monitoring of a policyholder's security posture. For CISOs, that turns cyber insurance from an annual paperwork cycle into a year-round governance obligation — with real budget and reporting consequences.
briefing -
IBM's 2026 Breach Report: AI Governance Gaps Are Now a Quantified Board Risk
IBM and Ponemon's 21st annual Cost of a Data Breach Report puts the global average at $4.99 million, with AI-enabled breaches running $1 million higher. The data gives boards a hard number for the AI governance gap they've been debating in the abstract.
risk-analysis -
Medusa Ransomware Passes 500 Critical Infrastructure Victims: What the New Federal Advisory Means for Your Board
CISA, the FBI, and HHS jointly updated their Medusa ransomware advisory on August 18-19, reporting the group has now hit over 500 critical infrastructure organizations since 2021, up from 300 in March 2025. This briefing covers what changed, why healthcare is bearing the brunt, and the governance actions CISOs should take this quarter.
incident-report -
Black Hat USA 2026: The Executive Threat Briefing
Black Hat USA 2026 ran in Las Vegas this week. The themes that dominated — AI infrastructure exploitation as an independent attack discipline, nation-state credential harvesting through trusted third-party networks, and autonomous agent weaponisation — carry direct implications for enterprise risk posture. This briefing distils what security leaders need to know.
briefing -
AgentForger: When a Phishing Link Becomes a Persistent AI Insider
Zenity Labs' disclosure of AgentForger demonstrates that enterprise AI agents can be weaponised from outside the organisation via a single phishing link, creating an attacker-controlled agent that inherits authorised access to email, calendar, Slack, and Teams. OpenAI patched the specific flaw in June — but the governance problem is structural and ongoing.
risk-analysis -
LAUNDRY BEAR: What the NCSC Zero-Click Advisory Means for Your Email Security Posture
The joint NCSC advisory AA26-204A naming LAUNDRY BEAR represents a materially different email threat model than phishing: no link to click, no attachment to execute. CISOs running Zimbra need to act now; those who aren't face similar risks from analogous techniques. Here's the executive brief.
risk-analysis -
Zero Trust Is No Longer Optional: The Regulatory Mandates Making It a Compliance Requirement
Zero Trust Architecture has moved from best practice to mandatory requirement. OMB M-22-09 federal deadlines are now enforceable, CISA's updated Zero Trust Maturity Model defines the measurement framework, and DORA, CIRCIA, and the UK Cyber Security and Resilience Bill are converging on the same underlying controls. Here's what the board needs to understand about where ZTA compliance now sits.
regulatory-update