PAM without Enterprise Budget: Controlling Admin Rights
Privileged accounts are the primary targets of attackers. Here’s how mid-sized businesses can implement PAM with three core principles-without buying an…
What are you looking for?
Benedikt Langer is an editor at SecurityToday. His focus areas are cloud security, zero trust and NIS2 compliance. He shapes the thematic direction and ensures editorial quality.
Privileged accounts are the primary targets of attackers. Here’s how mid-sized businesses can implement PAM with three core principles-without buying an…
A manipulated website is enough: Type-Confusion vulnerabilities in Chrome's V8 engine are hitting the browser in series.
OAuth token theft bypasses MFA because the token itself contains the authentication. A 375% surge in OAuth phishing-why SOCs must defend the session.
Microsoft Defender has two actively exploited vulnerabilities-one enabling privilege escalation-with a CISA deadline of June 3.
Phishing detection lapses after just a few months. Why the annual training fizzles out-and only continuous awareness and a reporting culture have real…
CVE-2026-32202 (CVSS 8.8) has been listed in CISA KEV since April 28, 2026: APT28 is exploiting an incomplete Windows kernel patch.
At the end of April 2026, the BKA identified the alleged leader of the REvil group and initiated an international arrest warrant request. 130 …
Trellix confirmed a source-code breach in early May 2026. The cybersecurity vendor now joins a list that includes Microsoft, Okta and LastPass – security-tool …
Two Ivanti EPMM zero-days were exploited in series at the end of April 2026 - 130 unique IP addresses actively tested the vulnerabilities within …
The CISA added eight new entries to its Known Exploited Vulnerabilities Catalog within one week at the end of April 2026. Three systems stand …
Signal verification code theft at Klöckner, Prien, Hubertz plus Graichen own goal on X. Three CISO moves for 2026.
In April 2026, the Romanian data protection authority sanctioned Renault Commercial Roumanie following a cyberattack with insufficient security measures, the Spanish AEPD imposed €950,000 …
NIS2 requires multi-factor authentication (MFA) "where appropriate," and in Germany, the BSI enforcement mandate enters its operational phase in May 2026. For security and …
Squidex SSRF CVE-2026-41172 is patched in version 7.23.0. Operations teams additionally need a 72-hour plan: Egress-Allowlist, IMDSv2-Lockdown and WAF-Profile-Review.
CVE-2026-5752 in Terrarium by Cohere AI (not Cloudflare): CVSS 9.3, Sandbox Escape with Root Code Execution. 72-Hour Response Plan for Edge and Platform Teams.
Microsoft Out-of-Band April 22: ASP.NET Core CVE-2026-40372 with CVSS 9.1. Patch in DataProtection 10.0.7. 72-hour response plan for Security-Operations.
CISA KEV Update from April 20, 2026 with eight vulnerabilities, patch deadlines on April 23 and May 4. 14-day response plan for DACH security …
Microsoft ASP.NET Core CVE-2026-40372: CVSS 9.1, Privilege Escalation. DORA, NIS2, and MaRisk compliance implications with 21-day plan for finance Dev-Shops.
CVE-2026-41172 in Squidex: SSRF in Asset Upload Affects Headless-CMS Backends. What Patch, IMDS Lockdown, and Permission Audit Can Do for Security Teams in 2026.
CVE-2026-5752 in Cohere AI Terrarium: CVSS 9.3, Root Code Execution in Sandbox Container, No Vendor Patch. Mitigation Plan and Strategic Lessons for Security Teams.
Vercel confirmed on April 20 a supply-chain breach via Context AI. Hundreds of customers affected. 48-hour plan for security teams.