Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Emerging Threat: (CVE-2026-78006) The Events Calendar Remote Code Execution via PHP Object Injection

CVE-2026-78006 is a deserialization of untrusted data vulnerability (CWE-502) in The Events Calendar, a WordPress plugin published by StellarWP, that allows an attacker to achieve remote code execution on the underlying host. The flaw sits in the is_safe_widget_instance function, whose guard against unsafe object data can be bypassed.

Introducing the CyCognito MCP Server: Full Exposure Context, On Demand

Today we are happy to announce the beta release of the CyCognito MCP server, which makes your external attack surface data consumable by any AI client that speaks the Model Context Protocol, including Claude, Cursor, and ChatGPT. The server runs on CyQL, the proprietary query language behind advanced search in our platform. CyQL is designed to ask precise questions about an attack surface, using operators suited to each type of asset, issue, and relationship.

AI Agent Security Readiness: The Federal Standard You Should Get Ahead Of

Here's the uncomfortable part first: in August 2026, researchers found AI agents connected to Hugging Face running loose inside enterprise networks. No owner, no audit trail, nobody who could tell you they existed until something broke. If that sentence made your stomach drop a little, good, because it should. It's the same blind spot most security teams are sitting on right now. They just haven't had their version of the incident yet.

Good Security Rating? Your Dark Web Exposure Says Otherwise

Ask a security leader how secure their company is, and most will point to a number. A rating, maybe a grade, or a score out of some maximum that a vendor calculated for them. That number only measures half the problem. It tells you about your infrastructure: your email configuration, your encryption, what's visible on the internet. It tells you much less about whether your employees' credentials are already exposed to an attacker.

AI is learning to control machines...but can it trust them?

Anthropic’s new Model Hardware Standard (MHS) could mark an important step in the evolution of agentic AI. Currently in research preview, MHS provides a standardized way for AI agents to discover, understand and operate physical equipment. Anthropic is already demonstrating the concept with laboratory and manufacturing equipment including robotic arms, microscopes, liquid handlers and laser systems. The objective is compelling.

The Cybersecurity Visibility Gap: What You Can't See Can Still Hurt You

Most security programmes are built to watch the inside of the network, but the threats that do the most damage often start outside it: leaked credentials, impersonated domains, dark web chatter, and vulnerabilities under active discussion. This post looks at why the visibility gap exists, what the data says about it, and what closing it involves.

Best Nonprofit Workflow Management Software: 5 Platforms to Consider

Nonprofit organizations often manage far more than donations. Teams may be coordinating client services, grant applications, events, volunteers, internal approvals, reporting, and day-to-day project management at the same time. The best nonprofit workflow management software should reduce that operational friction, give staff a clearer view of responsibilities, and help information move between people without relying on scattered spreadsheets.

Can Journaling Your Crypto Trades Create Better Results?

Crypto trading can be fast-moving, emotional, and difficult to evaluate objectively. When prices shift quickly, traders may focus on wins and forget the decisions that led to losses. A trading journal offers a practical way to slow down and examine those decisions. By recording the reasoning behind each trade, along with market conditions and the eventual outcome, traders can identify patterns that may otherwise go unnoticed.

How Often Should Organizations Perform DDoS Testing?

Most security teams have a firewall policy, a patch schedule, and a penetration testing calendar. DDoS resilience is often the exception, tested once, checked off, and forgotten until an actual attack exposes the gap. That's a real problem. Distributed denial-of-service threats aren't static, and neither is your infrastructure; the right answer to how often organizations should test depends on several variables, and the baseline is probably more frequent than you'd guess.
Featured Post

Why Data Governance Has Become a Critical Defence Against Ransomware in Healthcare

Ransomware and ransomware-style attacks can have a catastrophic impact within healthcare, where disruption directly impacts safety and continuity. Today's ransomware groups increasingly operate as sophisticated criminal enterprises, sharing tools, infrastructure, and expertise through ransomware-as-a-service (RaaS) models. This lowers the barrier to entry for cybercriminals while allowing experienced threat actors to focus their efforts on identifying and exploiting high-value targets.