Cloud & Enterprise
Cloud and enterprise IT covers identity, access, SaaS, hybrid infrastructure and corporate attack surfaces. The analysis helps readers follow risks, incidents and architectural decisions relevant to complex environments.

Trend Micro: CISA Adds Exploited Apex One Zero-Day to KEV Catalog with June 4 Deadline
CVE-2026-34926 affects on-premise Apex One installations. This directory traversal zero-day is under active exploitation, prompting CI…

DocketWise Data Breach: 143,480 Impacted via Third-Party Repository Exposure
Legal-tech platform DocketWise has notified 143,480 individuals of a data breach involving cloned third-party repositories. The incide…

The Oncology Institute Discloses Patient Data Breach Linked to Third-Party Vendor
The Oncology Institute (TOI) confirmed in an SEC filing that unauthorized actors accessed patient data through a third-party software…

CISA Adds Critical Langflow Vulnerability (CVE-2025-34291) to KEV Catalog Following Active Exploitation
CISA has added CVE-2025-34291, a critical origin validation flaw in the Langflow platform, to its Known Exploited Vulnerabilities cata…

Ransomware 2026: Post-Quantum Ciphers, Encryptionless Extortion, and the Rise of EDR-Killers
The 2026 ransomware landscape is defined by the adoption of post-quantum algorithms and a shift toward encryptionless extortion, with…

GitLab 19.0 Debuts Native Secrets Management and Air-Gapped AI
GitLab 19.0 integrates native secrets management, agentic merge request workflows, and self-hosted AI models, reinforcing its 'single…

30-Minute Lateral Breakouts: Why the SOC is Losing the Race Against AI-Driven Threats
Average breakout times have accelerated by 29%, with the fastest recorded exfiltration dropping from over four hours to just six minut…

PoC Zealot: Autonomous AI Executes End-to-End GCP Cloud Attack
Unit 42’s Zealot project demonstrates how multi-agent AI systems can autonomously chain SSRF, credential theft, and BigQuery exfiltrat…

Trust3 AI Launches MCP Security: A Hardened Control Plane or Just Another Promise?
Trust3 AI has announced MCP Security to protect enterprise agentic workloads, focusing on connection verification, isolated tokens, an…

AI-Driven Mobile Attacks Hit New Record: Apps Compromised Within Two Hours of Release
The Digital.ai 2026 App Security Threat Report reveals that 87% of client-facing applications are now under systematic attack, with th…

CISA Faces Congressional Scrutiny After Months-Long AWS GovCloud Credential Leak on GitHub
Senator Maggie Hassan has demanded a classified briefing from CISA following the discovery of a public GitHub repository that exposed…

AI Agents in Production: Addressing the Confused-Deputy Threat in Operational Automation
New research identifies a critical architectural gap in operational AI agents where a lack of separation between reasoning and executi…