Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Reporting AI Risk to the Board: What Directors Want to See

Directors ask for AI risk reporting because oversight failure is personally actionable. Under the Caremark line of cases, a board that cannot demonstrate it monitored a material risk carries exposure of its own, and AI has moved into that category for most enterprises. The request is rarely curiosity about the technology. ‍ The framing determines what belongs in the pack.

DORA, NIS2 and the Four-Hour Clock Reshaping GRC

A GRC program that produces documents quarterly cannot file a regulatory notification in four hours. The sentence carries the whole modernization argument, and the four-hour figure is not rhetorical. Under DORA, an EU financial entity classifying an incident as major has four hours to send an initial notification, then twenty-four hours for an initial report, seventy-two for an intermediate one and a month for the final. ‍

What's New in Risk Automations: 4 Templates for Vendor and User Risk

Most vendor onboarding and app access work is waiting and follow-ups. Waiting for someone to notice a form came in, assign a tier, chase a questionnaire, or dig up the context behind a Slack request. Risk Automations workflows remove that wait and automate the follow-up. A trigger fires, and the workflow runs to a concrete outcome: a ticket created, a message sent, a risk tier assigned. To make those workflows easier to launch, Risk Automations includes an ever-expanding template library.

Emerging Threat: (CVE-2026-34265) SAP NetWeaver ABAP Memory Corruption via DIAG Protocol Parsing

CVE-2026-34265 is a memory corruption vulnerability in the Application Server ABAP component of SAP NetWeaver and the ABAP Platform. The flaw stems from logical errors in how the SAP kernel parses DIAG protocol messages, the proprietary protocol that carries traffic between the SAP GUI presentation layer and the application server. Malformed input reaching the parser leads to an out-of-bounds write, classified as CWE-787. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

Why You Can't Arrest Your Way Out of Youth Cybercrime

Sir Robert Peel defined good policing as "the absence of crime and disorder, and not the visible evidence of police action in dealing with them." Gregory Francis of the Netherlands National Police quoted this at the INTERCOP conference held at INTERPOL headquarters, and this principle framed the entire event. Young people are increasingly drawn into cybercrime through the platforms where they already spend their time — Discord, Telegram and gaming servers.

Active Directory isn't going away. Your group policy setup might be as brittle as COBOL

A Reddit thread on r/activedirectory asking whether Active Directory is going away pulled in loads of comments, and the most upvoted answer compared AD to COBOL: still running, still critical, still not going anywhere. That comparison holds up when you check whether COBOL is still used today, since it runs core banking and government systems decades after its supposed retirement. The real risk for most IT teams isn't AD disappearing.

Practical Cybersecurity for Small Water Utilities: 5 Steps to Reduce Operational Risk

SpiderLabs’ technical review of the July attacks examines the affected technologies, observed activity, and broader threat landscape. The next question is practical: what can small utilities realistically do about it? At many small water and wastewater facilities, there is often no dedicated security team to understaff. A licensed operator may be responsible for sampling, maintenance, compliance, and after-hours callouts, perhaps with limited support from municipal IT.