The AI Malware Panic Was Loud. The Numbers Were Quiet .

New ai malware analysis from Unit 42 checked 405 samples and found only 12, three percent, ever reached a real network, cutting through the AI security hype.
The Rust Supply Chain Attack That Got Outfoxed in 90 Minutes

A rust supply chain attack briefly poisoned three trusted crates so cargo build ran malware automatically. The honest, fully sourced timeline is here.
SOC 2 Type 2 Certification Just Became Berry Street’s Sharpest Sales Pitch

SOC 2 Type 2 certification unlocked Berry Street’s payer and enterprise deals. See what a no-exceptions audit actually proves, and what trips up smaller teams.
The MDR Service Provider That Got Vished

ReliaQuest, an mdr service provider built on threat detection, saw its own staff get vished this month. Here is what buyers should demand from any vendor.
The Pentagon paused CMMC over a labelling problem

The Pentagon suspended CMMC Phase 2 after industry blamed unclear cui marking requirements for the worst of its total cost, and what changed because of it.
AI Supply Chain Security Just Met Its Phantom Raven Problem

AI supply chain security just met Phantom Raven: 126 npm packages exploited names AI tools hallucinate. See how the attack worked and how to close the gap.
Known Exploited Vulnerabilities and the brutal mid-market ransomware truth

Black Kite studied 13,336 ransomware incidents: mid-market firms took 73% of hits, most carrying known exploited vulnerabilities. Here’s what actually helps.
Alice’s $140 Million Round and the Real Price of DSPM for AI

Alice’s $140m round shows dspm for ai and model security are now a funded category, backed by Apax Digital, Samsung and SentinelOne, not a pitch deck slide.
NIS2 Compliance Meets the Court of Justice, and Ireland Picks Up the Bill

Ireland missed its NIS2 compliance deadline and now faces a €2.8m EU penalty plus daily fines. What the Commission’s CJEU referral means for your business.
LG Uplus Just Ran South Korea’s First Global Vulnerability Disclosure Program

LG Uplus just launched a global vulnerability disclosure program with HackerOne, the first Korean telecom to do it, and the numbers behind it are worth reading.