Patching everything is over: the risk method, explained
In June 2026 CISA issued directive BOD 26-04, changing how US federal agencies decide what to fix first. The rule is no longer "update everything…
Topic · Enterprise
Frameworks and practices to secure an organisation, without leaving it to chance.
In June 2026 CISA issued directive BOD 26-04, changing how US federal agencies decide what to fix first. The rule is no longer "update everything…
Multi-factor authentication is the most-cited defense against credential theft, but "MFA" is not a uniform category. SMS and push notificati…
SimpleHelp is remote-support software: whoever controls it controls the computers it manages. CVE-2026-48558 (CVSS 10.0) is an authentication bypass i…
FortiSandbox is the box where suspicious files are detonated safely. Two unauthenticated OS command injection flaws — one in the WEB UI, one in an API…
Two zero-days in SonicWall SMA1000 remote-access appliances, chained and exploited before disclosure. The first is an unauthenticated SSRF with a maxi…
CVSS 9.8, pre-auth, RCE. The flaw isn't in Splunk proper but in an internal PostgreSQL component that accepts whatever credential you hand it. A …
Enterprise security isn't improvised: it's structured on recognised frameworks. The NIST Cybersecurity Framework 2.0 organises the work around six functions — Govern, Identify, Protect, Detect, Respond, Recover — and is designed for organisations of any size. ISO/IEC 27001 is the international standard for information security management systems, certifiable by a third party.
The Zero Trust model starts from a simple principle: don't implicitly trust any request, inside or outside the perimeter, and always verify. CISA publishes a maturity model that helps move from the idea to a concrete, staged path, without impractical upheavals.
Frameworks aside, the evidence is consistent: asset inventory, timely patch management, multi-factor authentication everywhere, verified backups, least privilege. These are ordinary measures that stop the majority of real attacks — the ones that fill our dossiers.