#not


Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

Sep 15, 2026 // 14:30

Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the […]

Why Patch Automation Needs Brakes, Not Just an Accelerator

Sep 14, 2026 // 17:16

Author: Gene Moody, Field CTO at Action1 Patch management has a speeding problem. The pace at which software changes is increasing, while the time available […]

Your Critical Vulnerabilities Might Not Be Your Biggest Risk

Sep 12, 2026 // 01:32

Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those […]

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

Aug 31, 2026 // 11:01

The U.S. Department of Justice (DoJ) on Friday corrected a previously issued press statement that several of its agencies were victims of attacks carried out […]

73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

Jul 29, 2026 // 14:20

Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and […]

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

Jul 24, 2026 // 14:30

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we’ve collectively discovered is that enforcing least […]

Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads

Jul 14, 2026 // 12:10

xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not […]

Webinar this week: Prevention alone is not enough against modern attacks

May 11, 2026 // 15:36

Modern cyberattacks are no longer limited to malware or isolated phishing emails. Today’s threat actors combine AI-generated phishing, business email compromise, ransomware, and SaaS abuse […]

Most “AI SOCs” Are Just Faster Triage. That’s Not Enough.

Apr 16, 2026 // 17:17

The “AI SOC” is having a moment. Vendors are promising systems that can triage alerts, investigate incidents, and respond autonomously. The demos are polished. For […]

A cyberattack targeting Stryker, a medical technology company, caused widespread device failures affecting tens of thousands of units. The incident did not involve any malicious software.

Mar 17, 2026 // 21:14

The recent cyberattack on Stryker, a large medical device company, affected only its internal Microsoft systems and remotely erased data from tens of thousands of […]