How Orca Traced an nginx Flaw to 1.45 Million Tengine Servers All Running Vulnerable Code
TL;DR When a critical nginx vulnerability hits the headlines, security teams patch nginx. But what if the same vulnerable code...
TL;DR When a critical nginx vulnerability hits the headlines, security teams patch nginx. But what if the same vulnerable code...
Container adoption continues to outpace security maturity across most organizations. Traditional endpoint protection tools were never designed for ephemeral, highly...
Cloud applications now power critical business services, customer platforms, and software delivery pipelines. A single identity misconfiguration or exposed API...
Most cloud security teams already own too many tools. Yet misconfigured storage, excessive permissions, vulnerable workloads, and exposed Kubernetes services...
Key takeaways The NIST Cybersecurity Framework (CSF) is a voluntary, risk-based structure that helps organizations prioritize and communicate how they...
Key takeaways Open source incident response (IR) tools give security teams transparent, inspectable software for live response, case management, log...
Executive Summary A high-severity vulnerability (CVE-2026-5027, CVSS 8.8) was disclosed affecting Langflow, an open-source low-code platform widely used for building...
Executive Summary A critical vulnerability (CVE-2026-45034, CVSS 9.8) was disclosed affecting PhpSpreadsheet, the widely-used PHP library with over 312 million...
Executive Summary A critical vulnerability (CVE-2026-20253, CVSS 9.8) was disclosed alongside three additional high-severity flaws affecting Splunk Enterprise, Splunk Cloud...