News & Updates

CVE Program Gets a Lifeline—But the Real Story Is Just Starting
Last month, the cybersecurity world got a wake-up call: the backbone of global vulnerability tracking—the CVE program—almost collapsed. On April 15, MITRE revealed that its contract with CISA to run the program ...

Securing AI Agents: A New Frontier in Cybersecurity
As RSA Conference 2025 just wrapped up, one thing’s clear: AI agents are everywhere—and apparently, they need security guards too. These digital overachievers are working 24/7, managing networks, analyzing data, and getting ...

Mandiant’s M-Trends 2025: Edge Devices Are Now Prime Targets
Key Takeaways from Mandiant’s M-Trends 2025 There’s a certain irony that’s hard to ignore in Mandiant’s latest M-Trends report:The devices built to protect networks—VPNs, firewalls, routers—were at the heart of one-third of ...

Who’s Snooping on Go1 Robot Dogs?
Unitree Robotics, a China-based manufacturer, has been caught up in a major security scare. Two researchers uncovered that the company had pre-installed a backdoor in its popular Go1 robot dogs, allowing anyone ...

Deleting DNA Data From 23andMe
23andMe, the prominent consumer genetic testing company, filed for Chapter 11 bankruptcy on March 23, 2025, due to declining demand for its services and a significant data breach affecting millions of users ...

12 Hours or Else: Hong Kong’s Cybersecurity Explained
Hong Kong has officially enacted a new cybersecurity law aimed at securing critical infrastructure, a move that brings its regulatory framework closer to mainland China’s. The Protection of Critical Infrastructures (Computer Systems) ...

Chainguard “FIPS” Apache Cassandra
Chainguard modified Cassandra so organizations needing FIPS-approved encryption can finally use it—without risky workarounds or costly custom fixes. Apache Cassandr ia a powerful open-source database used by companies worldwide, but it wasn’t ...

The Cost of Compliance Theater: DoD Contractor Pays $11.2M for False Cybersecurity Certifications
Cybersecurity compliance isn’t just a box to check—it’s a commitment to protecting sensitive data. But for Health Net Federal Services (HNFS), that commitment fell short. Now, HNFS, a DoD contractor entrusted with ...

Federal Agencies Face Hurdles in Zero-Trust Implementation
The push for zero trust architecture is intensifying, but federal agencies are encountering significant challenges in making it a reality. Speaking at CyberScoop’s Zero Trust Summit, Department of Energy Chief Information Security ...

Security Flaw Found in Patient Monitors: No Fix Yet
In a concerning development for healthcare cybersecurity, the FDA and CISA have issued urgent advisories about two critical patient monitors found to have severe security vulnerabilities: the Contec CMS8000 and Epsimed MN-120 ...