Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Unauthenticated RCE in WordPress core (wp2shell)

SQL injections are still among us. On July 17, WordPress released an emergency security update. Version 7.0.2 fixes an unauthenticated remote code execution flaw in WordPress core that an anonymous attacker can trigger against a stock install with no plugins involved. If your site runs an affected version, update today. WordPress.org has turned on forced auto-updates for affected sites because of how severe this is. We are tracking this vulnerability in Aikido Intel.

Keeping the lights on: Why recovery readiness matters for power and energy operations

Power and energy organizations are a prime target of cyberattacks. They face cyberthreats that can disrupt generation, transmission and distribution. And as they introduce more connected digital technologies alongside legacy and connectivity-restricted OT systems, their cyberattack surface becomes more complex. That is why cyber resilience has become a critical operational requirement for the power and energy sector. The U.S.

The Agentic Attack Surface Is Growing Faster Than Your API Inventory. Here's How to Catch Up

Ask any security leader how many APIs their organization runs, and you’ll usually get a confident number. Ask them how many of those APIs are actually being called by an AI agent, a copilot, or an automated workflow right now, and the confidence tends to disappear. That gap is the problem. APIs have always outpaced the inventories built to track them; new services ship every sprint, integrations get added without a ticket, and old endpoints get deprecated without ever being switched off.

Building Customer Trust Through Strong Security and Compliance Practices

A software company had everything going for it. Its product solved a real problem, customer reviews were positive, and new demos were converting into paying clients. Then, during the procurement process with a large enterprise customer, the conversation changed. Instead of discussing features or pricing, the prospect sent a security questionnaire that stretched over dozens of pages. They wanted documentation, evidence of internal controls, and proof that customer data was being handled responsibly.

The Role of Mechanical Insulation in Sustainable Building Design

Sustainable building design has become more than just a trend. Across commercial, industrial, and institutional projects, owners are looking for practical ways to reduce energy use, lower operating costs, and create healthier environments for occupants. While technologies like solar panels, smart lighting, and automated HVAC controls often receive the most attention, one of the most effective solutions is also one of the least visible: mechanical insulation.

TeamPCP Profile: Why Developer Tools Are Becoming the Attack Path

TeamPCP is a financially motivated ransomware group tied to software supply chain compromise, credential theft, extortion, and abuse of developer infrastructure. The group is also tracked through aliases including ShellForce, PCPcat, TeamPCP, DeadCatx3, Altered Spider, and PersyPCP. The group has also claimed ownership of CipherForce, which it describes as its private locker.

Trust, Verify, Protect: Modernizing Email Security for the Cloud

Picture this: Your company just fell victim to a massive data breach. The culprit wasn't a sophisticated malware strain, a zero-day exploit, or a compromised firewall. It was a perfectly legitimate-looking login from a VP’s account, originating from an unrecognized IP address, requesting an urgent wire transfer via a spotless, text-only email. In the modern threat landscape, attackers have realized something crucial: Why break in when you can just log in?