Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

QR Code Attacks Surge 146% in Two Months

One particularly concerning trend in the recent evolution of phishing is the rise of QR code-based attacks. It doesn't rely on new malware or sophisticated exploits. Instead, it takes advantage of something much simpler: the trust users place in QR codes every day. Over the last few months, QR codes have become one of the most popular tactics for steering users toward malicious sites on mobile devices or in browser environments, where the visibility of many security tools is very limited.

SQL injection isn't dead

Oops! A SQL injection bug just forced an emergency WordPress core patch last week. On July 17, WordPress shipped an emergency release to fix an unauthenticated remote code execution flaw in the core, reachable via a SQL injection that an anonymous attacker can exploit on a stock install. WordPress.org even turned on forced auto-updates because of how severe it is. Searchlight Cyber, who reported it, estimates over 500 million sites run WordPress.

How to design a risk register: A guide for GRC practitioners

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

You can't govern what you can't see: Detecting shadow AI on your network

AI adoption inside the enterprise didn't ask for permission. It arrived through browser tabs, code editors, and meeting transcription bots, quietly stitching itself into daily workflows long before security teams could write policy around it. The result is a familiar story with a new villain, a sprawling, unmanaged attack surface that lives in your network traffic but nowhere in your asset inventory. We call it shadow AI, and it's the blind spot you didn't plan for or budget for.

CrowdStrike Falcon Platform Helps Meet U.S. Government Mandates for CISA BOD-26-04

On June 10, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) issued Binding Operational Directive 26-04, which transforms federal vulnerability management by shifting agencies from static CVSS-based patching to a dynamic, risk-based model. This supersedes BOD 19-02 and BOD 22-01. Agencies must now prioritize remediation using four key factors: public asset exposure, KEV catalog status, exploit automatability, and technical impact (partial vs. total control).

WP2Shell: WordPress Core SQLi + REST API Chain to Pre-Auth RCE

A newly disclosed WordPress exploit chain, nicknamed “WP2Shell,” lets unauthenticated attackers achieve remote code execution (RCE) on any WordPress Core installation, no plugins required. Disclosed on July 17, 2026, the chain combines two vulnerabilities: CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API batch-route confusion).

Data Discovery vs. Data Classification

Most DLP rollouts stall in the same place. The classifier flags a file as "confidential," but nobody, including the DLP solution itself, can say why, where it came from, or whether that label still matches what's inside the file six months later. Data discovery and data classification get bundled together in nearly every vendor pitch, but they solve different problems, and the gap between them is where false positives, stale labels, and missed exfiltration events live.

The Missing Layer in Network Security: Continuous Assurance

Some of the most serious network security weaknesses develop gradually through routine operational changes. Firewall rules are adjusted to support business needs, exceptions remain in place longer than planned, and controls are modified during troubleshooting. Over time, those decisions can push the live environment away from the security posture the organization believes it has.

Protecting the Corporate Nervous System: Why Network Security Assurance Is Becoming a Security Imperative

Modern enterprises depend on a complex network of interconnected systems, applications, identities, and security controls. This infrastructure has become the nervous system of the business, enabling critical operations, supporting applications, and enforcing the boundaries that protect sensitive data. When these systems function correctly, they become invisible.