Cybersecurity 101
What Is Privileged Access Management (PAM)?
A complete guide to privileged access management (PAM) — why privileged accounts warrant special treatment, the core PAM capabilities, and how to build a program.
Master the framework of digital identity. Learn how Identity and Access Management (IAM) secures your enterprise through robust authentication, authorization, and the principle of least privilege.
Cybersecurity 101
A complete guide to privileged access management (PAM) — why privileged accounts warrant special treatment, the core PAM capabilities, and how to build a program.
Identity & Access Management (IAM)
Roughly $200 million, by one account, for AI identity-threat detection: Okta says it has signed a deal to buy Permiso Security, though it did not disclose the price.
Vulnerabilities
From advisory to public proof-of-concept — the critical AD CS "Certighost" domain-takeover flaw (CVE-2026-54121) goes public this week, with the fix already shipped in Microsoft's July 2026 update.
Vulnerabilities
An Active Directory privilege-escalation research disclosure — defender review across AD environments this week, with Microsoft's July 2026 update the confirmed fix.
Account Takeover (ATO)
Dashlane now says the brute-force attack it disclosed on May 31 succeeded: by defeating 2FA on about 20 customer accounts, attackers downloaded copies of those users' encrypted password vaults. The vaults stay locked behind each user's master password, but affected users should rotate.
Artificial Intelligence (AI)
Attackers seized high-profile Instagram accounts by exploiting a 'confused deputy' flaw in Meta's AI support bot: they asked it to bind a new email, the bot sent the one-time code to the attacker, and the owner was locked out. Meta has pushed an emergency hotfix.
Vulnerabilities
Belgium's national cybersecurity authority warned on May 29 that CVE-2026-41089, a critical pre-auth buffer-overflow RCE in Windows Netlogon, is now being exploited against unpatched domain controllers. Microsoft patched the flaw in its May 12 Patch Tuesday release.
Password Security
Dashlane confirmed that an external party brute-forced the token check on its new-device-registration flow, and the company's automatic protections suspended targeted accounts. The lockout is the protection working — the news is what attackers went after.
Vulnerabilities
The European Commission’s flagship age-verification tool, touted as a secure solution for protecting minors online, has faced a disastrous rollout after independent researchers bypassed its core security features in under 120 seconds. Brussels, Belgium — The European Union’s ambition to set a global standard for online safety has
Data Breaches
New forensic details reveal that the massive data exfiltration at Vercel began with a single employee downloading a compromised Roblox game cheat, highlighting the catastrophic intersection of personal device use and enterprise SaaS permissions. SAN FRANCISCO, CA — The security community is processing the full scope of the breach involving Vercel
Data Breaches
The French National Agency for Secure Documents (ANTS) has confirmed a significant security incident targeting its central portal, as threat actors move to monetize a database allegedly containing millions of sensitive user records. PARIS, FRA — The French government is grappling with a severe compromise of its digital identity infrastructure. The
Policy & Government
Modeled after the U.S. CMMC framework, the new Canadian Program for Cyber Security Certification (CPCSC) introduces a mandatory verification tier to harden the nation’s defense industrial base against state-sponsored intrusion. OTTAWA, ON — The Government of Canada has officially launched the first phase of the Canadian Program for