2026 DBIR: Patching is Slowing, Exploits are Winning
The battle lines in cybersecurity have shifted. The latest Verizon DBIR shows attackers are exploiting vulnerabilities faster than ever, while defenders are falling further behind on patching.
Forget wrestling with cryptic Cypher queries. Rapid7's latest Surface Command update is about to unleash an army of citizen dashboard builders within your security team, turning raw asset intelligence into actionable insights in mere minutes.
The battle lines in cybersecurity have shifted. The latest Verizon DBIR shows attackers are exploiting vulnerabilities faster than ever, while defenders are falling further behind on patching.
A critical unauthenticated RCE vulnerability in the widely used KnowledgeDeliver LMS has been actively exploited. The flaw stems from a shockingly simple security oversight: shared ASP.NET machine keys.
For too long, security alerts have been a game of chance, lost in overflowing inboxes. Imperva's latest move promises to end that, pushing critical data directly to where it can be acted upon.
Everyone thought phishing-as-a-service was about stealing login credentials. Think again. A new breed of Chinese-language PhaaS is bypassing MFA and going straight for your wallet.
Phishing attacks are becoming increasingly sophisticated, even targeting encrypted messaging apps. Signal's latest update aims to put up guardrails, but how effective will they be?
The open-source software world just got a rude awakening. The Shai-Hulud malware campaign has escalated, poisoning over 600 npm packages in a breathtaking supply-chain assault.
Network analysis just got a bit cleaner. Wireshark 4.6.6 rolls out with a significant security fix and a slew of bug squashes, plus an Npcap update.
Your favorite website, perhaps even one you manage, might be a victim. A widespread attack is exploiting a critical flaw in Ghost CMS, compromising hundreds of sites and serving malware.
Microsoft's latest Windows 11 cumulative updates, KB5089549 and KB5087420, are here, not just patching vulnerabilities but subtly reshaping user interaction with new features.
Forget the dry CVE numbers. This SonicWall vulnerability means attackers are already inside networks, bypassing multi-factor authentication meant to keep them out.
Microsoft's May 2026 Patch Tuesday dropped 120 security fixes, a hefty sum with a concerning number of critical vulnerabilities. Thankfully, no zero-days were publicly exploited.
A contractor's public GitHub repository exposed highly privileged AWS GovCloud credentials and internal CISA system details. This egregious leak offers a disturbing look into government software deployment.