Amazon Web Services EMEA Sarl (AWS) has been designated as a critical third party (CTP) to the UK financial sector by HM Treasury. The CTP regime came into force on January 1, 2025, and establishes a framework through which the Bank of England, PRA, and FCA (collectively the UK regulators) can set requirements on and
CISA has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms), both related to unrestricted file uploads. These vulnerabilities represent significant risks to federal systems. The Binding Operational Directive (BOD) 26-04 outlines requirements for federal agencies to manage high-risk vulnerabilities effectively. While it primarily applies to Federal Civilian Executive Branch agencies, CISA urges all organizations to adopt similar strategies for vulnerability management. Organizations can suggest additional vulnerabilities for inclusion in the KEV Catalog through CISA’s nomination process.
You can now connect your agents to the AWS MCP Server using the same credentials and sign-in methods that you already use for connecting to the AWS Management Console or AWS Command Line Interface (AWS CLI) through a familiar browser-based experience powered by industry-standard OAuth. This new sign-in path supports AWS Identity and Access Management
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For
With Wimbledon’s help, Hazel argues against the popular myth that “Attackers only need to be right once, but defenders need to be right 100% of the time.”
The Cloud Controls Matrix (CCM) is a key security framework developed by the Cloud Security Alliance (CSA) for cloud computing. It aligns with CSA best practices, helping assess and enhance the security posture of cloud services. The CCM offers guidance on which controls should be implemented by different participants within the cloud supply chain, benefiting both cloud service customers (CSCs) and cloud service providers (CSPs). It contains 197 controls organized into 17 domains.
The article reflects on a discussion with a CISO from a major retail company about a significant security incident that occurred six months prior. Despite no stolen credentials, malware, or firewall breaches, the critical reconciliation process failed, attracting regulatory attention. The root cause was an AI-powered automation agent that had been properly granted access, highlighting the complexities and potential risks of relying on AI in security processes.
Today, we’re excited to announce that Boost is moving out of beta and into public preview. After months of building, breaking, and rebuilding inside JFrog’s own R&D organization, Boost is ready for the world. If you are currently running into token limits, unpredictable costs, or runaway usage from AI agents, Boost was built for you.
In Q2 2026, Sonatype Research recorded 1.8 million malicious packages, with npm accounting for 96.6% of this figure. The quarter illustrated a troubling theme where trusted software distribution channels were exploited through repository abuse, trojan-class malware, and compromised maintainers. Attackers not only targeted malicious packages but also high-trust developer workflows, evidencing a shift toward industrialized open-source malware. While npm dominated the count of threats, the ecosystem also saw significant malicious activity in PyPI and NuGet. The report emphasizes the importance of addressing trust and dependency relationships, revealing that once trusted accounts or packages are compromised, attackers gain legitimacy. To combat these threats, organizations should enhance security measures across the software supply chain and recognize the evolving nature of open-source malware.
A critical vulnerability has been identified in OpenPLC v3, where authenticated users can write arbitrary files to the filesystem due to improper handling of filenames in the web UI. This flaw can lead to arbitrary native code execution when a malicious file is compiled. OpenPLC v3 is affected and no longer receives security updates, prompting the recommendation to upgrade to OpenPLC v4. Users are advised to minimize network exposure and follow cybersecurity practices to mitigate risks associated with this vulnerability.
Schneider Electric has identified a vulnerability in its Easergy MiCOM Px40 Series products, specifically related to the use of hard-coded credentials, which may allow unauthorized access to device information via the SNMP protocol. Affected models include various versions of the Easergy MiCOM P14x, P24x, P341, and other series. Users are advised to upgrade firmware or implement several mitigations, such as using protected networks and firewalls, to reduce security risks. CISA provides additional cybersecurity recommendations for industrial control systems.
Explore why delegated administration in SaaS isn’t just a UI feature — it is a fundamental security and trust architecture for your enterprise customers.