Cloud & Enterprise
Cloud and enterprise IT covers identity, access, SaaS, hybrid infrastructure and corporate attack surfaces. The analysis helps readers follow risks, incidents and architectural decisions relevant to complex environments.

Public Exploit for CVE-2026-84115 Puts Cleo Harmony at Immediate Risk
A public exploit for the authentication-bypass vulnerability CVE-2026-84115 in Cleo Harmony has been released. Versions 5.8.1.0 throug…

JFrog Artifactory Authentication Bug Exposes Supply Chain, Zeroes Defenses
CVE-2026-82329 hits JFrog Artifactory with a CVSS 9.8: an authentication bypass granting admin privileges. WatchTowr confirms in-the-w…

Spring Ring: The Teams Vishing Campaign That Jumps From Chat to Domain in Minutes
From January to April 2026, the Spring Ring campaign impersonated IT help desk staff on Microsoft Teams to trick employees into runnin…

KEV Beats CVSS: The Framework CISOs Use When Scores Lie
On August 31, 2026, vulnerability prioritization gained an official decision framework: CISA BOD 26-04 mandates four scoring variables…

AI AppSec: Scanners Agree on Just 5%, Triage Costs $128,000
Contrast Security's AppSec Overflow 2026 report reveals three AI scanners testing the same codebase agree on only 5% of findings, whil…
Beacon CRM Breached, Robert Burns Trust Warns Donors: The Risk
A cyberattack on Beacon CRM, a SaaS provider for the non-profit sector, exposed contact data for over 1,000 organizations. The Robert…

CareCloud Breach Exposes 3.75 Million Patient Records: The B2B Model Hides the Victims
CareCloud confirmed in March that an unauthorized actor accessed an AWS environment for six days, compromising 3,756,469 individuals.…

McKesson in ShinyHunters' Crosshairs: 284 Million Records and a $55 Million Ransom
McKesson disclosed a security incident involving unauthorized access to third-party applications. The ShinyHunters group claims to hav…

Hasbro Employee Data Breach Exposes 436 Workers in Massachusetts
Hasbro disclosed a data breach exposing personal and financial employee data, confirming 436 affected individuals in Massachusetts. Th…

Cisco Challenges National Labels on AI Models: Nearly 900 Fingerprinted
Cisco and VAIL research reveals 'provenance entanglement' — upstream weights, biases, and behaviors cross borders without appearing in…

AI Honeypot: Real Attacks on LiteLLM and MCP Servers Reveal Three Patterns
Wiz Threat Research deployed AI/ML honeypots for 90 days and documented sustained, service-specific attacks. Three distinct patterns t…

VCS Blind Spot: Wiz CIRT Publishes DFIR Matrix for GitHub and GitLab
The Wiz CIRT DFIR poster maps VCS audit logs to MITRE ATT&CK but exposes critical gaps: 88% of customers use SaaS with 7-day retention…