Entra ID Scored a Perfect Ten, and Identity Security Posture Management Caught It in Time

Microsoft patched CVE-2026-69836, a maximum-severity Entra ID flaw, before attackers found it: what it means for identity security posture management.
MDR Services Just Grew a Second Set of Watchful Eyes

Fortinet bought Virtue AI’s agent red-teaming tools for its MDR services stack, weeks after its founders quietly left for Meta. Here is what actually changed.
DORA compliance cleared the register, not the real test

The AFM’s own DORA compliance review found real policy and incident-reporting gaps behind a strong 94% register score, with fines expected before 2026 ends.
AI security testing and the jailbreak that went shopping for a weaker model

AI security testing must assume refusal fails: Operation ASTERIX switched models the moment Claude refused, then jailbroke the next one it tried using.
Vulnerability management solutions meet a 24-hour deadline

A China-nexus actor deploys Babuk ransomware via an unpatched VMware vCenter flaw. Vulnerability management solutions now face a 24-hour EU deadline too.
Shell Was Not Breached. Its Supplier Was.

Third party risk management just failed 40+ named companies at once. What the Cl0p and PTC Windchill campaign proves about vetting a shared vendor honestly.
A Perfect Ten, and the Word Microsoft Took Back

Vulnerability disclosure policy got a real test when Microsoft’s CVSS 10.0 Entra ID flaw was called exploited, then wasn’t. What the retraction actually proves.
CareCloud’s HIPAA breach notification grew tenfold in silence

CareCloud’s hipaa breach notification jumped from 345,000 to 3.76 million patients in five months. What the timeline really requires, and why it grew unnoticed.
Medusa Ransomware Passed 500 Victims. What Managed Detection Response Actually Buys

Medusa ransomware has hit 500+ critical infrastructure victims. Here’s what managed detection response actually covers, costs and proves before you buy it.
The gate got patched , the key still worked

Three named August 2026 breaches expose the real network perimeter security gap: patching a VPN or firewall never erases the sessions attackers already stole.