Cloud & Enterprise
Cloud and enterprise IT covers identity, access, SaaS, hybrid infrastructure and corporate attack surfaces. The analysis helps readers follow risks, incidents and architectural decisions relevant to complex environments.

Klue Supply Chain Compromised, Icarus Hacked, Data in Circulation
The Klue-Salesforce supply chain breach now spans roughly two dozen confirmed victims. The extortion group Icarus, which claimed respo…

Burnyard: Local Malware Analysis Beats Cloud on Speed, But Accuracy Remains Unverified
Ohio State University's Burnyard project challenges VirusTotal and Sophos Intelix with user-space emulation on local hardware, deliver…

Ransomware: Europe Overtakes US as Top Target With 55% Surge in Attacks
Black Kite's first Europe-focused report reveals 684 ransomware attacks in the first four months of 2026, a 55.1% year-over-year incre…

'Snoopy' Sentenced: 18 Months for the Massive DraftKings Hack
Nathan Austad, known as 'Snoopy,' received an 18-month federal prison sentence for orchestrating the November 2022 credential-stuffing…

macOS: Standard Users Disable EDR/MDM Without Admin Rights
A privilege escalation technique on macOS exploits CDHash caching and NIB injection to silently disable enterprise security tools. App…

Bajaj Auto’s Silent Ransomware: What Lies Behind the ‘Successful Mitigation’ Claim
Bajaj Auto disclosed a June 23, 2026 ransomware incident without naming the threat actor, strain, or impact. The case exposes the limi…

Path Traversal in Allegra: CVE-2026-11442 Exposes Arbitrary Files
The ZDI-26-357 vulnerability in Allegra's exportReport method allows an authenticated remote attacker to read arbitrary files via path…

TTP-Chain Validation: Proving Exploitability Without an Exploit
A Picus Security engineer proposes TTP-chain validation to test CVE exploitability without live exploits, as the disclosure-to-exploit…

LastPass Breached via Klue Supply-Chain Attack: Customer Data Stolen, Vaults Intact
LastPass confirms a supply-chain breach through market-intelligence vendor Klue: stolen OAuth tokens granted access to LastPass's Sale…

OpenAI Shifts the Remediation Paradox: From Finding Bugs to Patching Them
OpenAI releases GPT-5.5-Cyber and the Patch the Planet initiative. AI has solved vulnerability discovery, creating a larger problem: t…

Xsolis Phishing Breach Exposes 1.4 Million PHI Records
Xsolis took five months to disclose the full scope of a January 2026 phishing attack. The HHS breach tracker revealed 1,396,519 affect…

SonicWall: CVE Patched, but Risk Persists Across All 14 Audited Firewalls
A SANS audit of 14 SonicWall Gen7 firewalls shows the CVE-2024-40766 firmware patch fixed the bug, but 12 of 14 devices retained stale…