
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deploymentCybersecurity intelligence, threat analysis, and national security reporting.

Citrix administrators were abruptly warned to shut down their NetScaler appliances amid reports of zero-day exploits being used in the wild, with private alerts circulating before patches were available. The sudden shutdowns followed discreet notifications from IT suppliers, security teams, and law enforcement, leaving many scrambling for answers.

Cloudflare's Containers flaw left customer data vulnerable, with residual material found on 18 of 24 container placements, including sensitive database fragments. The issue arose from a shared storage pool that didn't properly erase reused blocks, putting data at risk.

Get ready to supercharge your AI experience with Anthropic's Claude Marketplace, now live with over 2,000 plugins and connectors from top vendors like Google, Microsoft, and Salesforce. This game-changing platform is your one-stop shop for AI-related tools, making it easier than ever to unlock new possibilities!

Security firm watchTowr has sounded the alarm about two zero-day vulnerabilities in Citrix NetScaler appliances that are already being exploited in the wild, allowing for remote code execution. These unpatched flaws were discovered during forensic investigations and are expected to have a fix soon.

To safeguard its critical launch infrastructure, Cape Canaveral Space Force Station is gearing up to deploy a cutting-edge laser defense system designed to take down rogue drones that enter its airspace. This move is part of a larger effort to modernize base defenses and protect against low-altitude aerial threats.

Meet Lunex Stealer, a sneaky malware that's rapidly spreading across 13 countries, targeting Ukrainian-speaking users with a powerful information-stealing campaign that can swipe browser credentials and more. Its operators have set up 28 unique control panels, making it a growing threat that's hard to ignore.

ShinyHunters attackers have cleverly found a way to bypass WAF rules by using a percent-encoding trick to exploit Oracle PeopleSoft flaws, allowing them to reach vulnerable endpoints that were thought to be protected. By encoding URL paths, they can evade common defenses and put systems at risk.

The latest update to Anthropic's Claude Opus, version 5.5, has made significant strides in mimicking human writing styles, reducing obvious AI writing patterns and making it harder to churn out robotic content. This upgrade has resulted in more natural and concise writing, with 10 out of 12 writing measures showing improvement.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Microsoft has hit the pause button on the KB5002907 update due to issues with Office licenses, and is currently investigating the problem. The company will provide further guidance to affected customers through its usual channels.

Most organizations are flying blind, with 70% admitting that AI workflows are handling sensitive data without proper oversight - a gaping security risk that demands attention. To get ahead of the threat, experts agree that visibility must come before enforcement, because you can't secure what you can't see.

Google warns of a massive global campaign exploiting a critical Oracle PeopleSoft flaw, CVE-2026-35273, that allows hackers to remotely execute code without authentication, now targeting industries from healthcare to government. The attack, linked to ShinyHunters, has already compromised dozens of machines worldwide.

GitHub Actions were recently re-exposed, leaving developers vulnerable to attacks after two compromised third-party actions were re-enabled with malicious code still linked to their release tags. This security lapse put users at risk, as workflows referencing the actions could have executed the malicious payload.

The US cyber arsenal is being rapidly depleted in modern conflicts, leaving military leaders scrambling to regenerate and develop new capabilities. Vice Adm. Heidi Berg warns that high-value cyber effects can be consumed quickly, creating a strategic constraint that demands urgent attention.

The Navy's Shipyard Infrastructure Optimization Program is facing a massive blowout, with estimated costs skyrocketing to $200 billion and a timeline stretching up to 50 years. This is a far cry from the original plan of 20 years and $21 billion.

In a major win for national security, a US court has upheld the Pentagon's ban on Anthropic AI, deeming it a supply chain risk to the defense industrial base. This ruling gives the Pentagon the green light to protect its operations from potential private sector biases.

In a future fight, the backbone of logistics isn't just about moving supplies, but also about maintaining a resilient digital network that keeps commanders informed and one step ahead. The Pentagon is zeroing in on building logistics networks that can withstand pressure and keep critical operations running smoothly in contested environments.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Don't fall into the trap of thinking that buying more security tools automatically means you're safer - in reality, this approach can lead to tool overload and alert fatigue, ultimately weakening your defenses. Unit 42 experts warn that true organizational security is built on discipline, not on chasing the latest trends and solutions.

OpenAI has confirmed a security incident where its AI agents accidentally shared 53 user-uploaded images with third-party sites, but stresses that most users were unaffected and the breach was limited in scope. The mishap occurred when research environment agents transmitted training data while using external image-hosting services.

Poland is set to become home to a permanent US military base, with a top Polish defence official confirming that an agreement is near and a US decision has already been made. The move is expected to bolster the country's defence, although details such as troop numbers remain under wraps.

Kiteworks has issued a critical alert to customers after receiving credible threat intelligence from federal authorities suggesting a potential cyber attack, and is urging a 9-hour system shutdown as a precautionary measure to ensure safety. The company emphasizes that this is a preventative move, with no evidence of customer system compromise.

Hackers are actively exploiting critical flaws in Microsoft SharePoint and MikroTik RouterOS, allowing them to gain unauthorized access and take control of systems. Federal agencies are racing against the clock to patch these vulnerabilities, now added to CISA's Known Exploited Vulnerabilities catalog.

A single click on a malicious link by a logged-in WordPress user can be all an attacker needs to take control of a site, thanks to a critical flaw in the popular Elementor Website Builder plugin. This shocking vulnerability allows hackers to execute any action a user's account can perform, with just one cleverly crafted link.

The US Marine Corps is rapidly deploying anti-drone jammers to protect its amphibious vehicles from emerging aerial threats, with a $15.7 million sole-source award to Anduril for Pulsar-L electronic warfare jammers. This urgent move aims to equip forward-deployed Marines with crucial self-defense capabilities, mitigating the risk of mission failure and loss of life.

China's latest tank protection tech is a game-changer: meet the GL-6 active protection system that's taking down drone threats from above and all sides. This cutting-edge defense is the country's answer to the rising menace of cheap FPV drones and high-angle attacks on the battlefield.