Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

The Real Reason Hackers Target Active Directory First

Active Directory controls access to nearly every application, file, and system in your network. That's exactly why it's the first thing attackers go after. Get privileged access to AD, and an attacker doesn't need to break into ten different systems. They just need one path in, and from there they can move freely, escalate privileges, and sit undetected for weeks. AI is making this worse. Faster reconnaissance, sharper phishing, quicker lateral movement, all pointed straight at identity infrastructure.

Orchestrating the enterprise: Extending ServiceNow with professional-grade IGA

ServiceNow is core to many modern businesses. The platform is cloud-based, AI-first and centralized. As the operational center of the enterprise, ServiceNow offers IT leaders automation opportunities that help optimize workflows, track requests and enforce processes. Naturally, managing so many actions within one ecosystem calls for advanced identity governance and administration (IGA).

Emerging Threat: (CVE-2026-54159) PrestaShop Remote Code Execution via ps_facetedsearch Object Injection

CVE-2026-54159 is a PHP object injection vulnerability in ps_facetedsearch, the layered navigation module bundled with PrestaShop, that lets an unauthenticated attacker run arbitrary code on the storefront. The vulnerability carries a CVSS v3.1 base score of 10.0 (Critical).

The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results

The JFrog Security Research team has discovered and disclosed a typosquatted NuGet package named Newtonsoftt.Json.Net. Note the double t and the.Net suffix. This package has been masquerading as the popular Newtonsoft.Json library while quietly shipping a trojanized fork. The trojan rigs Digitain, an online betting platform, and in later generations, exfiltrates rigged round results to an attacker-controlled server, utilizing the header X-Seq-ApiKey: theperfectheist2025.

Identity Security for AI

What's scarier than an engineer with prod access? An agent with the same access that never sleeps, never asks, and runs a thousand sessions while you're at lunch. Last year we solved the problem of visibility in the Identity Chain, the concept is that identities are fragmented and it’s hard to get a view from Identity Providers to Infrastructure. Within a year, two things have changed. First, teams are using LLMs & Tools to perform actions on their behalf - fully delegating work to AI Agents.

When VulnOps Meets the Vendor Blind Spot: Why Post-Mythos Modernization Needs to Include TPRM

The security world has a new focus: VulnOps. In response to Mythos, Daybreak, and the other frontier models that are sure to follow, organizations are racing to build permanent vulnerability operations functions that combine vulnerability management with more robust automation. The need for this discipline was always there. But now that AI can discover and help weaponize vulnerabilities at machine speed, the old quarterly-scan-and-patch approach is becoming less viable.

When AI Agents Run Healthcare Workflows, Business Logic Becomes the New Attack Surface

Healthcare has moved well past pilot projects. AI agents now triage support tickets, draft clinical documentation, manage patient engagement, and coordinate care across systems that were never designed to talk to autonomous software. Autonomous systems can now analyze data, make decisions, trigger actions, and coordinate across clinical systems with minimal human oversight.