vendor
20 articles
CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (FIXED)
Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when cha...
A broken DNSSEC rollover took down .al. Now 1.1.1.1 tells you when validation is bypassed
When a failed DNSSEC key rollover took down the .al TLD, we deployed a Negative Trust Anchor to restore resolution.
Rapid7 and Mindshare Partner to Accelerate Cyber Resilience Across the Middle East
Gopan Sivasankaran is Regional Director, Middle East & Africa, at Rapid7 From AI adoption and cloud-first strategies to smart cities and critical infrastruct...
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
Defending SaaS-based applications against ShinyHunters OAuth abuse
Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (v...
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare.
Why cloud security is mission-critical for federal civilian and defense agencies
Beyond IT compliance, cloud security is now the backbone of civilian agency resilience, national defense, and warfighter safety, as cloud environments become...
Hackers find a new trick to collect Microsoft Entra user data without raising red flags
New compliance guidance available: HITRUST i1 on AWS
We are pleased to announce the publication of a new AWS compliance implementation guidance: HITRUST i1 Compliance on AWS: Customer Implementation Guidance wi...
Introducing Precursor: detecting agentic behavior with continuous client-side signals
Precursor, our new continuous behavioral validation engine for bot management, offers visibility into how humans and bots actually interact across the full u...
Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit
More AI, more software, more bugs! AI, it's all you hear about nowadays and everyone's got an opinion on it.
AWS designated as a critical third party to the UK financial sector
Amazon Web Services EMEA Sarl (AWS) has been designated as a critical third party (CTP) to the UK financial sector by HM Treasury.
Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative
Microsoft’s latest Secure Future Initiative report outlines progress on secure foundations, AI-powered defense, and future-ready cybersecurity. The post Secu...
Improving Smart Tiered Cache for Public Cloud Regions
Smart Tiered Cache allows for precise upper tier selection for origins hosted on AWS, GCP, Azure, and Oracle Cloud with customer-provided cloud region hints.
Introducing OAuth Support for AWS MCP Server
You can now connect your agents to the AWS MCP Server using the same credentials and sign-in methods that you already use for connecting to the AWS Managemen...
How to Meet a 3-Day Remediation SLA & Comply with CISA BOD 26-04
Key Takeaways CISA BOD 26–04 mandates remediation of the publicly exposed, highest-risk, known-exploited vulnerabilities within 3 days. The directive applies...
Wordfence Intelligence Weekly WordPress Vulnerability Report (June 29, 2026 to July 5, 2026)
Last week, there were disclosed in and that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPres...
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
GigaWiper, also tracked as BLUERABBIT, is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational pla...
Why we cannot wait for better post-quantum signature algorithms
NIST is advancing nine new post-quantum signature algorithms as potential candidates for future standardization. We take a closer look at all of them, and ar...