BLOG

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution – PATCH: NOW

Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user, an attacker could then install … Continue reading Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution – PATCH: NOW
Tue, 11 Aug 2026 21:47:19 +0000

Critical Patches Issued for Microsoft Products, August 11, 2026 – PATCH NOW

Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; … Continue reading Critical Patches Issued for Microsoft Products, August 11, 2026 – PATCH NOW
Tue, 11 Aug 2026 21:44:55 +0000

Passkeys by default and retirement of Microsoft-provided SMS and voice authentication

Move to phishing-resistant authentication before SMS and voice retire We are notifying all Microsoft Entra ID tenants of an important change to authentication security: The AI era demands stronger, phishing-resistant authentication. Passkeys are becoming the default authentication experience in Microsoft Entra, and Microsoft-provided SMS and voice authentication will retire on February 1, 2027. For more … Continue reading Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
Mon, 10 Aug 2026 18:19:06 +0000

You Really Don’t Want This Delivery

The NJCCIC observed a phishing campaign impersonating UPS delivery notifications. These messages use subject lines such as “Parcel Arrival Notification,” “Your Package Is Ready for Pickup,” and “Your Parcel Has Arrived” and are purported to be from the following sender(s): “UPS Parcel Services” <contact[@]shipfasts[.]com> “UPS Delivery Support” <contact[@]learnstax[.]com> Messages include an Adobe PDF attachment that … Continue reading You Really Don’t Want This Delivery
Mon, 10 Aug 2026 18:17:19 +0000

Beware of Threat Actors Targeting IT Help Desk Staff

Information technology (IT) help desk staff are heavily targeted because they often possess privileged administrative rights and provide an entry point for account recovery, such as resetting passwords and bypassing multi-factor authentication (MFA). To identify high-value targets, threat actors perform reconnaissance on corporate websites, networking platforms such as LinkedIn, or social media websites. They pose … Continue reading Beware of Threat Actors Targeting IT Help Desk Staff
Mon, 10 Aug 2026 18:16:09 +0000

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution – PATCH NOW

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install … Continue reading Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution – PATCH NOW
Mon, 10 Aug 2026 18:14:51 +0000

New Standards Will Protect Encryption From Quantum Computers

From our bank accounts to smartphones, all our sensitive data and devices are protected with a technology known as cryptography. Present-day cryptography essentially uses a very challenging set of math problems that are nearly impossible for current computers to solve. These math problems act as a “lock” to keep hackers or spies away from the … Continue reading New Standards Will Protect Encryption From Quantum Computers
Mon, 10 Aug 2026 18:11:18 +0000

Announcing Final NIST Transit CSF Community Profile + Upcoming Webinar

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the final NIST Interagency Report 8576, Transit Cybersecurity Framework Community Profile, to help U.S. transit agencies strengthen their cybersecurity practices while supporting safe and resilient transit services. Additionally, the NCCoE is hosting a virtual event on September 1, 2026 to discuss the Profile. Register today to reserve your … Continue reading Announcing Final NIST Transit CSF Community Profile + Upcoming Webinar
Mon, 10 Aug 2026 18:09:15 +0000

Upcoming Webinar: Foundational Cybersecurity for Small Businesses

Date: August 20, 2026 Time: 2:00 p.m.- 3:00 p.m. EDT Description: The small business community is a large portion of the U.S. and global economy and is also largely under-resourced when it comes to building strong cyber defenses. The efficient use, or prioritization, of limited resources is critical. Speakers from the Cybersecurity and Infrastructure Security … Continue reading Upcoming Webinar: Foundational Cybersecurity for Small Businesses
Mon, 10 Aug 2026 18:08:24 +0000

CISA, FBI, and Partners Release Joint Cybersecurity Advisory on Gunra Ransomware

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI), in collaboration with U.S. government and international partners, released a joint Cybersecurity Advisory, #Stopransomware: Gunra Ransomware, part of an ongoing series detailing ransomware variants and threat actors. This joint advisory provides technical details on Gunra activity, along with detection and mitigation … Continue reading CISA, FBI, and Partners Release Joint Cybersecurity Advisory on Gunra Ransomware
Mon, 10 Aug 2026 18:07:41 +0000