BLOG

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution – PATCH: NOW

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. *            Adobe Bridge is a powerful asset management tool that allows creative professionals to preview, organize, edit, and publish multiple creative assets efficiently across the Creative Cloud ecosystem. *            Adobe Format Plugins are software add-ons used … Continue reading Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution – PATCH: NOW
Tue, 28 Jul 2026 17:52:42 +0000

Large-Scale Exploitation Campaign Targeting Website Content Management Systems

This Australian Signals Directorate (ASD) Australian Cyber Security Centre (ACSC) Alert is relevant to website owners and website managers. It is being provided to assist agencies and organizations in guarding against the persistent malicious actions of cybercriminals. A large-scale exploitation campaign is targeting various vulnerabilities in content management systems (CMS) globally, including in Australia, with … Continue reading Large-Scale Exploitation Campaign Targeting Website Content Management Systems
Tue, 28 Jul 2026 17:50:56 +0000

ID.me Phishing Campaign

The NJCCIC received reports of a phishing campaign impersonating ID.me, which is a US-based digital identity network that allows users to provide proof of their legal identity online to access government services, healthcare portals, and retailer discounts. The phishing email is sent from a “.ar” top-level domain (TLD) for Argentina with a subject line of … Continue reading ID.me Phishing Campaign
Tue, 28 Jul 2026 17:49:58 +0000

Understanding Browser Push Notifications:A Gateway to Online Scams

Websites often ask for permission to send you “push notifications.” When used correctly, this feature is highly convenient. If you use a communication tool like Microsoft Teams or a news website in your browser, a small pop-up in the corner of your screen can alert you to a new message or breaking news, even if … Continue reading Understanding Browser Push Notifications:A Gateway to Online Scams
Tue, 28 Jul 2026 17:48:35 +0000

Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting

United States Federal and international partner agencies, released this Joint Cybersecurity Advisory to provide network defenders with vital tools and resources to combat the threat posed by Russian Government-sponsored activity targeting poorly configured and vulnerable devices across critical sectors. Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising … Continue reading Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Tue, 28 Jul 2026 17:47:17 +0000

Trusted Technologies Create Pathways Into Critical Infrastructure Networks

Critical infrastructure organizations are increasingly dependent on third-party vendors for a variety of remote services, including security and operational technologies that support essential functions. Yet the privileged access that providers rely on can also create opportunities for threat actors to infiltrate these sensitive networks. Recent incidents involving Itron and Fortinet illustrate how trusted relationships can … Continue reading Trusted Technologies Create Pathways Into Critical Infrastructure Networks
Tue, 28 Jul 2026 17:46:27 +0000

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

Move to phishing-resistant authentication before SMS and voice retire We are notifying all Microsoft Entra ID tenants of an important change to authentication security: The AI era demands stronger, phishing-resistant authentication. Passkeys are becoming the default authentication experience in Microsoft Entra, and Microsoft-provided SMS and voice authentication will retire on February 1, 2027. For more … Continue reading Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
Tue, 28 Jul 2026 17:44:05 +0000

Isolating Vital Operational Technology and Enabling Systems During Crisis

The Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation (FBI) and international partners, published Joint Guidance CI Fortify – Advice for isolating vital systems. This guidance, aligned with CISA’s CI Fortify initiative, is designed to help critical infrastructure … Continue reading Isolating Vital Operational Technology and Enabling Systems During Crisis
Tue, 28 Jul 2026 17:36:29 +0000

Building Assurance Through HIPAA Security Conference

The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the National Institute of Standards and Technology (NIST) Information Technology Laboratory (ITL) are excited to announce their 2026 Conference, “Safeguarding Health Information: Building Assurance Through HIPAA Security 2026”. DATES: September 2 – 3, 2026 LOCATION: NIST Gaithersburg Campus, 100 Bureau Drive, … Continue reading Building Assurance Through HIPAA Security Conference
Tue, 28 Jul 2026 13:29:02 +0000

Register Today! NIST Workshop | Securing AI Data Center: Architecture, Security Posture, and Emerging Standards

Securing AI Data Center: Architecture, Security Posture, and Emerging Standards Workshop Remember to register for the Secure AI Data Center Workshop before Tuesday, July 21, 2026. The agenda is now available. Data centers are the computing infrastructure that powers the training and inference of artificial intelligence (AI), and they have become a critical element of … Continue reading Register Today! NIST Workshop | Securing AI Data Center: Architecture, Security Posture, and Emerging Standards
Tue, 28 Jul 2026 12:35:11 +0000