Articles

CanisterWorm Hijacks Namastex Labs npm Packages in Self-Spreading Supply Chain Attack
A self-replicating npm worm has hijacked packages tied to AI agent tooling company Namastex Labs, harvesting developer secrets and automatically republishing itself across every package a victim can access.

Exposure Management vs Vulnerability Management: A Complete Guide
As attack surfaces stretch across cloud, SaaS, IoT, and third-party integrations, this guide compares exposure management and vulnerability management to show how combining both delivers broader visibility and stronger prioritization.

NIST Overhauls NVD Operations, Will Stop Enriching “Lowest Priority” CVEs Amid Record Volume
Facing record CVE volume, NIST is overhauling how it runs the National Vulnerability Database, saying it will stop enriching ‘lowest priority’ CVEs so it can keep pace with the flood of new vulnerabilities.

How PTaaS Helps Organizations Maintain Continuous SOC 2 Compliance Cost-Effectively
Annual penetration tests satisfy the baseline SOC 2 standard, but this article explains why Penetration Testing as a Service offers a more cost-effective path to continuous compliance and audit readiness.

VENOM Phishing Platform Targets C-Suite Executives, Bypasses MFA to Steal Microsoft Credentials
A newly uncovered phishing-as-a-service platform called VENOM has been targeting C-suite executives’ Microsoft credentials since at least November 2025, using techniques built to bypass multi-factor authentication.

Does HIPAA Require Penetration Testing? What Security Teams Need to Know
HIPAA never explicitly requires penetration testing, but its Security Rule creates risk-management expectations that make it practically essential. This article breaks down what security teams actually need to know.

GitHub Notifications Are Being Weaponized to Deliver Malware at Scale
Attackers are exploiting GitHub’s own notification system, posting fake VS Code security alerts in the Discussions section of thousands of repositories to trick developers into downloading malware.

Dark Web Analysis vs. Dark Web Monitoring: What the Difference Means for Your Security Team
Most teams that think they have dark web coverage only have dark web alerting, and that gap is exactly where threat actors operate. This piece explains the difference between monitoring and analysis, and what real coverage requires.

Poland’s Nuclear Research Centre Repels Cyberattack, Potential Iran Attribution
Poland’s National Centre for Nuclear Research disclosed an attempted breach of its IT infrastructure, detected and blocked before any damage occurred, with early suspicion pointing to Iranian threat actors.

How to Build a DevSecOps Program, and What to Outsource
Many DevSecOps programs look complete on paper, SAST and SCA deployed, scans running on every commit, yet findings still pile up unclaimed. This article explains how to build a program that actually works, and what to outsource.

Microsoft Threat Intelligence Warns AI Has Become a Core Weapon in the Attacker’s Toolkit
From fabricated resumes and interview deepfakes to covering their tracks after a breach, Microsoft Threat Intelligence details how attackers are weaving AI into nearly every stage of an attack.

How to Measure ROI from Your Penetration Testing Program
Penetration testing ROI is one of the most underreported metrics in cybersecurity, mostly because teams measure the wrong things. This framework shows how to track real outcomes instead of activity metrics.