Tag: Vulnerability
-

What Actual Data Minimization Looks Like
Data minimization has been a GDPR requirement since 2018. Most organisations have done almost nothing about it. Here is what it actually looks like when you do.
-

Malware in the Open Source Supply Chain Is Now the Default
The malicious npm package, the typosquatted PyPI release, the compromised Docker image. The pattern has matured. The frequency has increased. The defence has not kept up.
-

Modern Phishing as a Service Is Boring (And That Is Why It Works)
Phishing in 2026 is not a clever technical exploit. Phishing in 2026 is a service industry, a well oiled business, and the most reliable way into a corporate network. Here is why it works.
-

Backups: The One Thing That Will Save You, and Why Most People Set Them Up Wrong
We have backups is often the last reassuring sentence spoken before an organization discovers the backups were incomplete, online, encrypted with everything else, or impossible to restore in time.
-

A Field Guide to Patching at Scale
Patching at scale is the unglamorous work of security. The defender who has the patching process right has solved 80 percent of the vulnerability problem. The defender who has it wrong has not. Here is what the process looks like in 2026.
-

A Field Guide to Secure Defaults in 2026
Most breaches in 2026 exploit a default that was wrong at install. The defender who fixes the defaults fixes the breach. Here is the field guide.
-

The Open Source Maintainer Burnout Crisis
Open source maintainer burnout is not a new problem, but in 2026 it is hitting a structural wall. The maintainers of the libraries that everything else depends on are the ones most likely to be working for free, on a project they started ten years ago, while a Fortune 500 company ships their work without…
-

Why Compliance Frameworks Don’t Catch the Breaches
The compliance framework has become the enterprise’s way of saying the enterprise is secure. The framework that the auditor signs off on, the board reads the summary of, the regulator accepts as evidence of due diligence. The framework that did not catch the breach the enterprise just disclosed.
-

How to Spot a Vendor That Is About to Get Acquired
The vendor the enterprise relies on just got acquired. The product roadmap is now the acquirer’s product roadmap, the support contract is now the acquirer’s support contract, the data the enterprise shared with the vendor is now the acquirer’s data. The acquisition has happened before the enterprise knew it was happening.
-

Your Attack Surface Is Bigger Than You Think
The attack surface the security team has been defending is a fraction of the actual surface. The asset the security team knows about, the system the security team has patched, the application the security team has tested, the surface that the attacker does not even bother with because the attacker has found something the security…