Hired for One Job, Judged on Another: The CISO’s Real Problem

CISOs Face Double Standard in Performance Evaluation and Business Value Contribution A double standard exists when it comes to evaluating the performance of Chief Information Security Officers (CISOs). During recruitment, potential CISOs are typically expected to possess a strong technical background, extensive security experience, and leadership skills. However, once they take on the role and … Read more

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

A Notorious Hackers’ Group Targeted ReliaQuest, but the Impact Was Minimal, According to the Company Cybersecurity firm ReliaQuest has confirmed that it was targeted by hackers affiliated with the notorious ShinyHunters group. The attackers attempted to gain unauthorized access to ReliaQuest’s systems using a sophisticated social engineering tactic. However, in a rare instance of good … Read more

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts

Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts Dutch data protection authorities have slapped a massive fine on Uber, worth nearly $1 billion, for using automated software to suspend driver accounts without human review. The ride-hailing company is accused of violating the EU’s General Data Protection Regulation (GDPR), which … Read more

Hired for One Job, Judged on Another: The CISO’s Real Problem

The Double Standard Facing CISOs: Where Technical Expertise Meets Business Acumen Chief Information Security Officers (CISOs) are often hired for their technical prowess and security experience, but when it comes time to evaluate their performance, they’re judged on a different set of criteria entirely. The disconnect between these two expectations can be particularly challenging for … Read more

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

ReliaQuest, a cybersecurity firm, has confirmed that it was targeted by hackers affiliated with the notorious ShinyHunters group. However, despite the sophistication of the attack, the company claims that its impact was limited to gaining view-only access to one employee’s Okta dashboard. The incident began when ReliaQuest noticed a widespread phishing campaign launched by ShinyHunters … Read more

The Vulnerability Gap: Why Discovery Is Outrunning Repair

As AI-powered vulnerability discovery tools continue to outpace human remediation efforts, a widening gap in cybersecurity has become an all-hands-on-deck moment for the industry. In recent months, advanced AI models have been producing vulnerability reports at an unprecedented rate, often in hours rather than weeks or months. However, the structural mismatch between rapid discovery and … Read more

ToxicPanda Banking Trojan Matures Into Enterprise Threat

ToxicPanda Banking Trojan Evolves into a Devastating Enterprise Threat A highly sophisticated version of the ToxicPanda Android banking Trojan has emerged, threatening not only individual mobile users but also enterprise resources accessed from compromised devices. The latest variant, dubbed ToxicPanda 2.0, has significantly expanded its capabilities and targeting scope, putting it firmly in the category … Read more

Tricky ‘SynkLoader’ Multitool May Herald Ransomware

A Sophisticated Malware Family Emerges, Possibly Paving the Way for Ransomware Attacks A highly advanced and multilingual malware family has been discovered, which may signal the beginning of more successful ransomware attacks in the future. Dubbed “SynkLoader,” this sophisticated threat uses a combination of conventional and novel tactics to evade detection and steal sensitive information … Read more

Foul Language: WordlistLoader Disguises Malware as Ordinary Text

A new malware loader has been discovered, using a clever trick to evade detection and deliver a growing infostealer. WordlistLoader, as it’s called, disguises malicious code by reconstructing it from ordinary English words. This allows Amatera, an increasingly prevalent infostealer, to sneak past security controls and infect victims. Researchers at Gen Threat Labs have been … Read more

Exploited Zimbra Flaw Highlights Shrinking Window to Patch

Federal Agencies Scramble to Patch Critical Zimbra Flaw as Exploitation Window Shrinks The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a three-day deadline for federal agencies to patch a critical vulnerability in the widely-used Zimbra unified communications suite. The bug, CVE-2026-73570, allows attackers to execute arbitrary commands on compromised servers, potentially granting full … Read more