
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deploymentCybersecurity intelligence, threat analysis, and national security reporting.

Hackers are on the hunt for Rejetto HFS servers with a critical flaw that lets them forge sessions, take over accounts, and execute remote code - and it's crucial to update to version 3.2.1 ASAP to avoid falling victim. This vulnerability, known as CVE-2026-61500, was patched in July, but attackers are actively scanning for affected servers.

The FBI has scored a major win in the fight against cybercrime, arresting multiple suspects linked to the notorious ShinyHunters hack, and vowing to leave no stone unturned in bringing all responsible individuals to justice. The operation is ongoing, with the bureau working closely with law enforcement partners to crack down on the group.

A newly discovered flaw in Microsoft Exchange Server could put your mailboxes at risk, allowing authenticated attackers to elevate their privileges and gain unauthorized access across your network. Microsoft has urgently released a security update to patch this high-severity vulnerability, rated 8.8 on the CVSS scale.

Italy just slapped IQVIA with a whopping $7.8 million fine for failing to properly anonymize health data, putting nearly one million patients at risk of being reidentified. The country's Data Protection Authority found that IQVIA's lax practices left sensitive info vulnerable.

President Trump has tapped Jay Clayton, Director of National Intelligence, to lead the charge on AI policy efforts, framing it as a high-stakes race to stay ahead of emerging dangers. As the new White House AI czar, Clayton will oversee broad domestic technology and economic policy discussions.

US water systems are under siege by cyber threats from hostile nations like China, Russia, Iran, and North Korea, as well as ransomware groups, putting our critical infrastructure at risk of a nationwide public-health crisis. This summer's alarming attacks on water systems in 12 states by Iranian hackers exposed the vulnerability of our water infrastructure to foreign adversaries.

Get ready for a game-changer on the battlefield: humanoid robots are joining the fight as specialized force enablers, revolutionizing the way wars are fought. In just a few months, Ukrainian ground robots have already completed over 24,500 missions, proving their value in daily operations.

Japan's government is breathing new life into its shipbuilding industry with a fund that's sparking a wave of private investment, and now other countries are taking note. The US, which currently holds a mere 0.1% of the global shipbuilding market, may need to step up its game to stay competitive.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
In a groundbreaking feat, artificial intelligence has cracked a 200-year-old cipher written by Napoleon's nephew in 1809. This historic code, shrouded in mystery for centuries, has finally yielded its secrets to the power of AI.

A major security flaw in Bromcom's legacy single sign-on system has led to a significant data breach, exposing email addresses of users across the UK's education sector. The incident, identified on September 6, affected a legacy registration mechanism still in use despite being superseded.

A massive data breach has hit Denmark's Central Population Register, compromising sensitive personal info for a whopping 8.8 million people - that's nearly 80% of the country's population! Names, addresses, dates of birth, and more are now at risk.

Researchers have uncovered a new Spectre v2 variant, called Branch Target Reuse (BTR), which can extract sensitive data, including root password hashes, from Intel machines running Linux in just minutes. This attack leverages a clever exploit that takes advantage of a desynchronization in modern CPUs.

Debian just dropped a massive kernel security update that tackles a staggering 1,313 vulnerabilities - that's a huge patch to keep your system safe and secure! Get the details on the update and why it matters.

Dell's System Update tool has a critical flaw that could let hackers gain total control of your system - and all it takes is remote access to get started. This vulnerability, tracked as CVE-2026-86360, is a serious threat that could allow attackers to execute code with root privileges.

Malicious backdoors are sneaking into telecom systems by masquerading as regular email traffic, making them nearly undetectable. Researchers at Rapid7 uncovered an implant family called AVERAT that cleverly disguises itself as legitimate mail activity on TCP port 25 and SMTP.

South Korea's financial sector is reeling after a string of devastating data breaches at major banks, including Shinhan Bank and Kookmin Bank, which compromised the sensitive information of over 144,000 customers. The alarming incidents have triggered an emergency response from the Financial Services Commission, with officials launching urgent on-site investigations and sharing critical intelligence to contain the damage.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
Meet ClingSTUN, a sneaky Linux proxy backdoor that's exploiting known flaws in unpatched IoT devices to turn them into remotely controlled proxy nodes, allowing hackers to hijack your network. FortiGuard Labs has tracked 24 vulnerabilities so far, and it's crucial to stay ahead of this threat.

Malware operators have seized on a critical flaw in the Realtek Jungle SDK (CVE-2021-35394) to spread the Cling botnet, exploiting the vulnerability to infect devices and turn them into unwitting accomplices. By cleverly hijacking the ordinary STUN protocol, Cling creates a stealthy command-and-control channel to issue instructions and disguise its malicious activities.

Citrix is warning of targeted attacks exploiting a newly discovered zero-day flaw, CVE-2026-88779, a high-severity memory buffer issue that could disrupt services for vulnerable NetScaler ADC and NetScaler Gateway customers. The company has urged affected users to act quickly to protect themselves from potential denial-of-service attacks.

tenfold just supercharged its free Identity Governance Tool, adding game-changing features like shared-content access reviews and centralized event auditing - now smaller IT teams can enjoy robust identity governance without breaking the bank! This move helps organizations ditch manual, spreadsheet-driven practices for good.

The software landscape is evolving at a breakneck pace, with GitHub's commit count skyrocketing from 1 billion in 2025 to 2.9 billion by August 2026 - a staggering rate that hints at an explosion of credentials and identities that need to be secured. This rapid growth leaves security teams scrambling to keep up with the expanding attack surface.

A major breakthrough in the fight against cybercrime: US authorities have arrested Anibal Alexander Canelon Aguirre, the alleged mastermind behind the notorious Ploutus ATM malware that drained over $5.4 million from banks and credit unions nationwide. The suspect, also known as "Prometheus" and "The Engineer," was added to the FBI's Most Wanted list in 2026 and now faces charges of conspiracy to commit bank fraud.

Apple is cracking down on how developers access your Mac data, specifically the Full Disk Access setting, to shield you from potential security risks posed by advanced AI agents. This move aims to prevent apps from snooping on your sensitive files, emails, messages, and browsing history without your clear consent.

Get ready to see some changes in your ChatGPT experience: OpenAI is rolling out visual ads that will pop up while you're generating images, starting with a test group in the US later this month. These ads will be clearly labeled and won't affect the chatbot's responses, but will instead showcase products or services in a visually inspiring way.