Cybersecurity 101
What Is the MITRE ATT&CK Framework? A Guide for Defenders
A defender's guide to the MITRE ATT&CK framework — what it is, how tactics, techniques, and matrices are structured, and how to use it for detection and threat intel.
Cybersecurity 101
A defender's guide to the MITRE ATT&CK framework — what it is, how tactics, techniques, and matrices are structured, and how to use it for detection and threat intel.
Artificial Intelligence (AI)
Anthropic's Fable 5 launches with “cyber safeguards” baked in — a framing that would, days later, become the center of a precedent-setting US export-control action.
Supply Chain Attack
Miasma's open-sourcing turns the previous day's Microsoft-repo incident into the first instance of a much broader supply-chain threat any actor can now reproduce.
Vulnerabilities
The fifth in-the-wild Chrome zero-day of the year, in the V8 JavaScript engine, is now patched — but the attack pattern shows no sign of slowing.
Artificial Intelligence (AI)
Half a century after Brunner imagined it, researchers publish a prototype — and the defender community gets a new detection-research agenda rather than an immediate operational threat.
Vulnerabilities
An AI proxy that increasingly sits between corporate apps and model providers issues a patch — defenders should verify deployments and review proxy logs.
Vulnerabilities
A patch cycle on the backup-of-record for the enterprise — high-priority, given the ransomware-response context.
Cybersecurity 101
Cyber threat intelligence (CTI) turns raw data into decisions. This guide covers the four types, the intelligence lifecycle, IOCs vs TTPs, the frameworks that structure analysis, and the use cases that make CTI valuable to SOC, IR, and vulnerability teams.
Vulnerabilities
A use-after-free in the Linux kernel's nf_tables code — patched in February, exploited publicly in June — shows how a single misplaced character in a critical subsystem becomes the keystone of a privilege-escalation chain.
Vulnerabilities
A logic-flow weakness in Check Point's Remote Access VPN gave a Qilin ransomware affiliate and other attackers a month to operate before a patch arrived.
Supply Chain Attack
For the second time in weeks, Microsoft packages were laced with credential stealers — this time targeting users of AI coding agents, forcing the company to pull more than 70 of its own GitHub repositories.
Threat Intelligence
Mandiant's published findings on a financially motivated campaign give defenders in legal and financial services a sector advisory to act on.