Executive Summary: GitHub’s August 17 outage illustrates a difficult truth about modern cloud infrastructure: a...
Security Breaches
7 DNS Security Lessons from the CubePilot Hijacking
Executive Summary: The July 2026 DNS hijacking of drone technology company CubePilot demonstrates how control of DNS can...
Salesforce, Klue, and the OAuth Token Nobody Was Watching
Summary: A vendor called Klue lost control of a GitHub token. That single lapse ended up exposing Salesforce data of its...
6 Places Pharma Data Goes That Security Teams Can’t Always See
Executive Summary: Pharmaceutical companies are moving sensitive patient, research, clinical, and intellectual property...
The Cost of Assuming Your Cloud Is Secure
Executive Summary: The Nextcloud data exposure is a reminder that cloud security failures rarely announce themselves. A...
When One Extra Letter Costs $545,000: Defending Your Domain Against Typosquatting
Executive Summary The $545,000 Surfside Beach fraud demonstrates a growing security blind spot: attackers don’t need to...
The New Face of Identity Attacks: Why Phishing No Longer Needs Your Password
Executive Summary: The latest identity attacks reveal a fundamental shift in phishing: attackers no longer need to steal...
When One SaaS Platform Fails: The Hidden Risk of Digital Dependency
Executive Summary: The Canvas breach underscores a broader reality facing every organization: as SaaS platforms become...
The SaaS Security Problem Most Organizations Still Treat Like an IT Issue
For years, organizations approached SaaS security as an access management problem. Enable SSO. Turn on MFA. Provision users...








